tebra

Security Architect

Apply Now

At a Glance

Location
United States
Work Regime
remote
Experience
7+ years
Posted
2026-03-16T12:27:30-04:00

Key Requirements

Required Skills

GCPJavaScriptKubernetesPythonSQLTerraformTypeScript

Domain Knowledge

  • Automation
  • Cybersecurity
  • Education
  • Regulatory

Benefits & Perks

Health Insurance

le pay and a robust benefits package, reflecting our commitment to your over

Requirements

Experience: 7+ years of experience in Information Security with deep hands-on expertise in network Architecture.

Education & Certifications: Master’s degree in Cybersecurity required. GCP Professional Cloud Security Engineer certification is highly preferred.

GCP & AI Depth: Deep experience securing Google Cloud Platform, including specific experience with Vertex AI services and BigQuery analytics controls.

Core Security Stack: Proven ability to manage and tune Cloudflare (WAF/Zero Trust) and CrowdStrike Falcon (EDR/XDR).

Technical & Automation Fluency: Expert proficiency in Python for building custom automation APIs and Workato for orchestration. Working knowledge of HCL for Terraform code review, JavaScript/TypeScript for Cloudflare Workers, SQL for BigQuery analysis, and RegEx for custom WAF rule creation.

Kubernetes Mastery: Strong understanding of Kubernetes (GKE) security, including node pools, network policies, and securing Helm deployments.

Responsibilities

The Security Architect is a technical, hands-on senior role responsible for designing and implementing robust security architectures across Tebra’s hybrid and cloud environments. You will drive the strategy to strengthen our overall security posture, ensure compliance (SOC2, HITRUST, PCI DSS), and proactively manage risk. You will have the unique opportunity to embed security into the DNA of our platform, shifting left through DevSecOps integration and enabling engineering teams to build securely by default in GCP.

Cloudflare & Edge Defense:

Own the strategy and execution for the Cloudflare ecosystem to secure the network edge. This includes architecting WAF rules (using

RegEx

), DDoS protection, Bot Management, and writing custom edge logic using