As the Senior Application Security Architect, you work strategically with engineering and product teams to enable the delivery of secure application patterns and software solutions. You design standard security requirements for how applications should be built, deployed, and maintained, ensuring security is baked into the software development lifecycle from the start. You also build and mature team processes that empower development teams to own their software's security posture while mentoring internal security team members. Perform Security Reviews of applications throughout the SDLC including at the design and implementation phases through formal threat modeling and source code reviews, focusing on designing secure applications from the start and ensuring secure design principles are correctly implemented. Help to set strategic direction for application security initiatives, shift-left processes, and secure coding standards across the enterprise with a focus on treating security as quality. Build relationships and collaborate with software engineering, product, and architecture teams to ensure alignment of company vision and secure coding goals. Continually identify opportunities for improvement within software delivery pipelines and work with engineering leadership to implement automated security guardrails and remediations. Collaborate with business, product owners, architecture, and information security teams to enable the delivery of secure software patterns that support business velocity Coordinate and drive initiatives for AppSec engineers to build, execute, and scale application security strategies. Help to build processes that test the compliance and effectiveness of software security requirements through automated guardrails and continuous security testing. Influence decision-makers in the areas of secure application architecture, API design, authentication/authorization controls, and modern cloud deployment. Create and evangelize application security policy sets and secure design patterns to be used throughout the company that balance velocity and external compliance requirements. Work directly with development and audit teams to help align security architectures against upcoming compliance, regulatory (e.g., SSDF, Executive Orders on Cybersecurity), and contractual landscapes. Mentor software engineers and information security team members on threat modeling, secure code design, and modern vulnerability remediation techniques.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior