Quorum Software

Quorum Software

·18 hours ago

Senior director, security architect (usa - remote)

Apply now

Location

remote, TX, United States

Commitment

Full Time

Level

Director

Required skills

AuthenticationCustomer Account FunctionalityCompute

Job Description

Senior Director, Security Architect

Location: Houston, Texas (preferred) or United States - Remote

Model of Work: Hybrid if located in Houston, TX or Remote with Travel if the work location is United States – Remote

Are you excited by challenges? Do you enjoy working in a fast-paced, international and dynamic environment? Then now is the time to join Quorum Software, a rapidly growing company and industry leader in oil & gas transformation. Quorum Software is the world's largest provider of digital technology focused solely on business workflows that empower the next evolution of energy. From emerging companies to supermajors, throughout every region of the globe, customers rely on Quorum's proven innovation and unmatched global expertise to streamline business operations and make data-driven decisions that optimize profitability and growth. Our industry-leading solutions are transforming energy companies across the entire value chain, helping visionary leaders evolve their organizations into modern energy companies.

Overview

The Security Architect is the senior technical authority for security across the software products, cloud platforms, data, and AI systems built and operated by Quorum’s Product, Innovation & Engineering (PIE) function. As a global software company serving the energy industry, the products we ship help operate and optimize critical infrastructure worldwide — which makes security a foundational requirement, a recurring subject of rigorous customer assurance, and a competitive differentiator rather than an afterthought. Operating at the intersection of engineering and security, the Security Architect defines and drives the “build-side” security mandate: secure software development, cloud infrastructure hardening on Azure, product data protection, customer-facing identity and tenant isolation, and the fast-emerging discipline of securing AI and agentic systems. The role owns architecture and implementation for everything PIE is accountable for, implements enterprise standards set by the CISO where the two intersect, and advises on adjacent corporate-security decisions — while deliberately staying out of the corporate IT security domains owned elsewhere. This is a hands-on architecture role. The Security Architect sets technical direction, produces reference architectures, threat models, and guardrails, and works shoulder-to-shoulder with engineering teams to make the secure path the default path.

Responsibilities

Application & Software Security

  • Own the secure SDLC: define and evolve security gates across design, build, and release — threat modeling, secure-by-design patterns, and paved-road guardrails that engineering teams adopt by default.
  • Drive SAST, DAST, and SCA: select, integrate, and tune application- and dependency-scanning tooling in CI/CD, keeping signal high and friction low, and set the standards for triage and remediation SLAs.
  • Govern AI-generated code: establish review, provenance, and scanning controls specifically for code produced with AI assistants, treating it as a first-class supply-chain and quality risk.
  • Secrets management: architect enterprise-grade secret storage, rotation, and detection so credentials never live in source or pipelines.
  • Partner on offensive testing: act as the technical counterpart for CISO-commissioned application pentests and red-team exercises, and own remediation of the findings within PIE.

Cloud Infrastructure Security (Azure)

  • Secure the Azure landing zone: own the security architecture of subscriptions, network topology, private endpoints, and in-cloud segmentation for product and platform workloads.
  • Policy-as-code & CSPM: codify guardrails (e.g., Azure Policy, Bicep/Terraform, Defender for Cloud) so misconfiguration is prevented at deploy time and continuously detected at runtime.
  • Implement cloud IAM/PAM: operationalize the enterprise standard for MFA, just-in-time access, and service-account hygiene across cloud workloads, in line with CISO-set requirements.

Product & Customer Data Security

  • Protect product and customer data: architect encryption (at rest and in transit), key management, and DLP controls across the product estate.
  • Data classification & governance: embed classification within DaWinci and the Data-as-a-Product model so sensitivity is known, enforced, and auditable across data products.
  • Align to enterprise policy: implement product data protection consistent with CISO enterprise data policy, and engage Legal where privacy and contractual obligations apply.

AI / ML Security & Governance

  • Secure the AI platform: own security architecture for AI Foundry workloads and the agentic layer, including MCP/A2A agent access, scoping, and authorization.
  • Defend against AI-specific threats: design controls for data leakage, prompt injection, insecure tool/agent use, and model supply-chain and vendor risk.
  • Advise enterprise AI policy: as a consulted expert, inform the CISO/Legal-owned policy on what data may reach any LLM and how AI tools are used across the company.

Product Identity & Tenant Isolation

  • Own customer-facing identity: architect authentication and authorization for the products (OAuth2/OIDC, token and session design, least-privilege authorization models).
  • Guarantee tenant isolation: ensure robust multi-tenant separation so one customer can never reach another’s data or compute — a non-negotiable for energy-sector clients.

Incident Response, Compliance & Assurance

  • Detect and contain product/cloud incidents: build detection, containment, and forensics capability for product and cloud security events, operating within the CISO-owned enterprise IR program.
  • Provide audit evidence: generate and maintain product- and cloud-side evidence for SOC 2, ISO 27001, and other frameworks, and respond authoritatively to customer security questionnaires.
  • Advise on vendor risk: support security review of product-embedded vendors and LLM providers as a consulted party to the CISO-owned vendor-risk process.

And other duties as assigned.

Requirements

  • Substantial experience (typically 8+ years) in security engineering or architecture, with a strong software-product and cloud-native focus.
  • Demonstrated ownership of security architecture for production SaaS/cloud products, ideally in a regulated or high-assurance context.
  • Deep hands-on Azure security expertise — landing zones, CSPM/Defender for Cloud, Azure Policy, private networking, and infrastructure-as-code (Bicep or Terraform).
  • Proven secure-SDLC / DevSecOps practice — threat modeling and SAST/DAST/SCA and secrets management embedded in CI/CD.
  • Strong grasp of cloud-native identity — OAuth2/OIDC, authorization models, and multi-tenant isolation.
  • Working command of compliance frameworks relevant to product assurance — SOC 2, ISO 27001, and customer security questionnaires.
  • Excellent communication and influence — able to align engineers, product leaders, and the CISO organization around a shared security direction.

Strongly Preferred Skills

  • Practical experience securing AI/ML and agentic systems — LLM application security, prompt-injection and data-leakage defenses, MCP/A2A or comparable agent frameworks, and model/vendor risk.
  • Background serving the energy sector or other critical-infrastructure industries, with an appreciation of their heightened assurance and resilience expectations.
  • Data-security depth — encryption and key management, DLP, and data classification within data-mesh / Data-as-a-Product architectures.
  • Relevant certifications such as CISSP, CCSP, Azure Security Engineer / Cybersecurity Architect Expert, or SABSA/TOGAF.

Additional Details

  • Background Check: The successful candidate will need to successfully complete the following clearances: Criminal History Check, Education Verification, Employment Verification, Driver’s License Verification and passport/ID validation.
  • Visa Sponsorship: Employment eligibility to work with Quorum Software in the United States is required as the company will not pursue visa sponsorship for this position. The successful candidate will be required to ensure they maintain and renew any visas or permits that grant employment eligibility where applicable.

About Quorum Software

Quorum Software connects people and information across the energy value chain. Twenty years ago, we built the first software for gas plant accountants. Pipeline operators came next, followed by land administrators, pumpers, and planners. Since 1998, Quorum has helped thousands of energy workers with business workflows that optimize profitability and growth. Our vision for the future connects the global energy ecosystem through cloud-first software, data standards, and integration. The trusted source of decision-ready data for 1,800+ companies, Quorum Software makes the essential connections that let us work better together in the connected energy workplace.

For more information, visit quorumsoftware.com.

Quorum Diversity Statement:

At Quorum, we are committed to fostering, cultivating, and preserving a culture of belonging. We want to be the place where a diverse pool of talented people join us, stay with us and do their best work. With a diverse team of employees, we grow and learn better together. The collective sum of the individual differences, life experiences, knowledge, innovation, self-expression, and talent that our employees invest in their work represents not only part of our culture, but our reputation and our achievements. We are fully focused on equity and equality and believe deeply in diversity of race, gender, sexual orientation, age, religion, ethnicity, national origin, ability, neurodiversity and all the other characteristics that make us unique.

Quorum Business Solutions and Quorum Software are Equal Opportunity Employers.

All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, ancestry, veteran status, disability, genetic information, or any other basis protected by law. Those applicants requiring reasonable accommodation to the application and/or interview process should notify a member of the Human Resources Department.

Our company uses E-Verify to confirm the employment and eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.dhs.gov/E-Verify.

Recruitment Scam Alert:

Quorum Software does not charge fees, request payments, conduct interviews via messaging apps, or request the installation of software at any stage of the recruitment process. All legitimate recruitment activities are conducted exclusively through our official careers website (www.quorumsoftware.com/careers) and email addresses ending in @quorumsoftware.com. Any communication that does not originate from these official channels should be considered unauthorized and may be reported to [email protected].

Ready to join the team?

Apply now

Similar Jobs: