Security Architect, Product Security
Humana
- Location
- Louisville, KY
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 130 approvals (FY2023)
- Posted
- Sep 1, 2026
Skills
About this role
Become a part of our caring community The Security Architect II supports Humana's Product Security program by partnering with engineering, architecture, and security teams to identify and address security risks across enterprise applications. This role analyzes security findings, provides risk-based remediation guidance, and helps drive secure development practices while building expertise in product security and security architecture. Work Style Remote Candidates must reside in or be willing to relocate to one of the following locations: Atlanta, GA, Boston, MA, Charlotte, NC, Chicago, IL, Dallas, TX, Washington, DC, Ft. Lauderdale, FL, Louisville, KY, Nashville, TN, New York, NY, or Tampa, FL. Description The Security Architect II supports Humana's Product Security program by helping identify, assess, and reduce security risk across enterprise applications and technology solutions. Working closely with software engineering, architecture, and security teams, this role serves as a security subject matter expert supporting vulnerability triage, secure software development practices, and security consultation efforts. This position is ideal for professionals with approximately 2-5 years of cybersecurity, application security, product security, or related security architecture experience who are looking to expand their expertise within a large enterprise environment. The successful candidate will have experience analyzing vulnerabilities, assessing risk, communicating remediation recommendations, and partnering with technical teams throughout the Software Development Life Cycle (SDLC).
Primary Responsibilities
Serve as a Level 2 Security SME supporting Product Security Scan & Triage activities. Analyze, investigate, and adjudicate complex vulnerability findings and security tool results. Assess security risk and provide practical, risk-based remediation guidance to engineering teams. Support secure software development lifecycle (SDLC) practices across enterprise technology initiatives. Support static application security testing (SAST), software composition analysis (SCA), secrets detection, and open-source/package security activities. Partner with development teams to review security findings and improve application security posture. Participate in security exception and risk acceptance workflows. Assist with the development and improvement of runbooks, knowledge articles, escalation criteria, and operational processes. Collaborate with cybersecurity, information security, architecture, and technology teams to address application security risks and improve security outcomes.
Required Qualifications
2-5 years of relevant cybersecurity, application security, information security, product security, or security architecture experience. Practical experience analyzing vulnerabilities and evaluating security risk. Ability to provide clear, actionable remediation guidance to technical teams. Working knowledge of: Static Application Security Testing (SAST) Software Composition Analysis (SCA) Secrets Scanning Secure SDLC practices Understanding of common application security and software security concepts. Strong critical thinking, problem-solving, and analytical skills. Demonstrated collaboration and communication skills, including the ability to work effectively with software engineers, architects, and security professionals. Bachelor's degree preferred; equivalent combination of education and relevant experience will be considered.
Preferred Qualifications
Experience with enterprise security tooling and vulnerability management workflows. Experience supporting application security, product security, cybersecurity, or information security programs. Experience with cloud security, container security, API security, DAST, or SaaS security platforms. Experience creating documentation, technical guidance, playbooks, or operational processes. Experience mentoring junior analysts or supporting team development initiatives. Security