| Software engineering, application security, security engineering, or related technical roles | Required | 10 |
| Experience in designing and implementing security architecture for IT systems | Required | 6 |
| Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse | Required | 6 |
| Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) | Required | 6 |
| Demonstrated experience with threat modeling and security architecture reviews | Required | 6 |
| Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads | Required | 6 |
| Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices | Required | 6 |
| Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans | Required | 10 |
| Experience in a regulated environment such as financial services, healthcare, government, or payments | Highly desired | 6 |
| Experience conducting or coordinating penetration testing and translating results into durable architectural improvements | Highly desired | 6 |
| Experience implementing DevSecOps programs and security automation at scale | Highly desired | 4 |
| Familiarity with privacy engineering, data classification, and compliance frameworks | Highly desired | 4 |
| Experience with security architectures in Esri's ArcGIS platform | Highly desired | 2 |