Engineering & Delivery

Security / Architecture Reviewer

Review system boundaries, data flows, identity, and delivery controls so Wilkes & Liberty can ship secure designs with explicit risks, evidence, and operator-owned decisions.
Location
United States — remote
Work schedule
Full-time
Engagement
Contract (1099)
Appointment term
Ongoing
Seniority
Senior
Department
Engineering & Delivery
Remote policy
Remote
Hiring status
Open
Applications close
October 31, 2026
Eligible work jurisdictions
United States
Work eligibility
Authorized to work in the U.S.; no sponsorship available
Clearance requirement
Not required
Clearance level
No clearance required
Expected travel
0%
Veteran friendly
Yes

The role

Wilkes & Liberty needs an independent Security / Architecture Reviewer who can challenge a design early and verify the implemented result later. This is a technical assurance role, not a ceremonial sign-off and not a substitute for Compliance / GRC. You will help teams make trust boundaries, failure behavior, risk decisions, and acceptance evidence explicit before a system reaches a client operator.

What you will own

  • Model system boundaries, principals, data flows, attack surfaces, abuse cases, deployment dependencies, and the consequences of failure.
  • Review architecture, code, configuration, and delivery plans across web applications, APIs, identity, infrastructure, data, and AI-enabled workflows.
  • Test whether authentication, authorization, tenant isolation, secrets handling, file intake, outbound access, audit evidence, and recovery behavior are least-privilege and fail closed where the risk requires it.
  • Turn material risks into clear engineering requirements and acceptance evidence. Separate confirmed defects, unsupported claims, and accepted residual risk.
  • Review proposed mitigations, verify closure against the exact changed state, and document decisions and exceptions without overstating assurance.
  • Support secure handoff and incident readiness with architecture records, threat models, review notes, and operator-facing procedures.
  • Work with the Compliance / GRC Specialist on applicable obligations while keeping technical security findings distinct from control narratives or certification claims.

What you bring

  • You can reason across application, API, identity, infrastructure, and data boundaries and explain where final authority and enforcement must live.
  • You can perform threat modeling, code and configuration review, and focused security testing, then turn the result into changes an engineering team can implement.
  • You understand authentication and authorization, secrets and key handling, logging and evidence, software supply-chain risk, secure deployment, and failure-mode design.
  • You can challenge a design without blocking by reflex: you explain the risk, viable options, evidence needed, and who must own the decision.
  • You distinguish a technical control from a policy statement, and a reviewed design from a certified system.
  • You write precise findings that identify the affected boundary and state, not vague security advice.

Helpful experience

  • Drupal or other content platforms, Next.js/Node services, GraphQL or JSON:API, containers, and infrastructure as code.
  • OAuth/OIDC, workload identity, zero-trust patterns, network and data-boundary design, and secure software delivery.
  • AI agents, tool authorization, retrieval systems, or other workflows where untrusted input can trigger privileged action.
  • Federal, regulated, or high-assurance delivery, including work that must map engineering evidence to contractual requirements without claiming certification.

Equal opportunity and accommodations. Wilkes & Liberty considers qualified candidates without regard to protected characteristics. Reasonable accommodations are available during the application process.

Apply