Information Security Architect at Concora Credit Inc.
Beaverton, OR
—
Jul 12, 2026
Beaverton, OR
Jul 21, 2026
What this job asks for AI summary
A hands-on security architecture role responsible for designing and maintaining secure patterns across infrastructure, identity, data, and application development in a financial services environment. The position involves conducting security assessments, leading application security reviews, evaluating vendor and partner security designs, and collaborating with cross-functional teams to embed security practices at every stage of the technology lifecycle. Suits an experienced security practitioner with a background in regulatory frameworks and enterprise-scale environments.
Senior level · 5+ years · National · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The job title is 'Information Security Architect' — a hands-on technical role with architecture, engineering, and some operational duties — making 15-1212 (Information Security Analysts) the closest available SOC code. 15-1299 (Computer Occupations, All Other) is noted as a runner-up since 'Security Architect' sits between analyst and architect occupations not fully captured by either code.
No work location or metro area is specified in the posting. The mention of 'onsite fitness equipment at both locations' suggests a physical office exists, but no city or state is named.
The degree requirement states 'Bachelor's degree, applicable certification, or equivalent experience,' which explicitly accepts equivalent experience in lieu of a degree — treated as no hard degree gate.
Regulatory frameworks (PCI, GLBA, HIPAA, SOX) are listed as a required category; no single framework is singled out as the sole gate, so the skill is captured at the category level.
'Security architecture' and 'application security' are broad capabilities listed under the Requirements section; no specific named tooling is mandated for these areas.
Infrastructure-as-code and policy-as-code are explicitly called out in the Requirements section as goals for translating security standards, making them hard gates.
Cloud security, IAM, SSO, MFA, and identity protocols (SAML, OAuth, OIDC, FIDO) all appear under the Preferred section and are marked accordingly.
CISSP and CISM are listed as 'strongly preferred' under the Preferred section — not a hard gate despite the strong language, as they sit in the optional block.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): security architecture.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.