AVP, Cyber Application Security Architect
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cyber application security architect securing SaaS, cloud infrastructure, and software development lifecycles. Driving secure-by-design reviews, DevSecOps, threat modeling, and AI/ML security guidance.
Responsibilities:
- Serve as the security architecture authority within the architecture organization
- Partner with product architects, principal engineers, cloud partners, and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure
- Coach and support developers in writing secure code and using secure patterns, frameworks, and libraries
- Provide architecture, implementation, and operational guidance and promote secure-by-default approaches
- Triage SAST, SCA, DAST, container, and IaC scanning findings; validate and resolve false positives; and help prioritize true risk
- Tune security tools, reduce noise, and improve signal quality through rules, suppressions, baselines, and exception processes
- Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry
- Conduct Secure by Design reviews for new applications and material changes
- Lead threat modeling workshops, identify abuse cases and attack paths, and document mitigations and residual risk
- Review authentication/authorization, data flows, secrets handling, logging/monitoring, and resiliency controls
- Provide recommendations and track follow-through with engineering teams
- Translate FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, and SOX requirements into measurable security architecture controls
- Advise on CI/CD pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns
- Advise on third-party dependency security, supply chain controls, SCA governance, and patch/vulnerability management
- Integrate security controls into developer workflows with automation and self-service
- Provide security architecture guidance for AI/ML and GenAI-enabled applications
- Help implement data protection, access control, monitoring, and abuse-prevention controls for AI/ML features
- Act as a trusted partner to product, engineering, and leadership
- Create and maintain secure coding guidance, reference architectures, and reusable patterns
- Contribute to incident root cause analysis and preventative design improvements
Requirements:
- 8+ years related IT experience
- 5+ years' experience in security application tools
- 6+ years' experience in application security reviews of new architecture
- 5+ years of experience with public and hybrid cloud environments (AWS, Azure and GCP)
- Strong software development background with the ability to read, understand, and advise on production code and design decisions
- Demonstrated expertise in threat modeling and secure architecture review for modern web and API-based applications
- Expertise securing CI/CD and SDLC processes, including pipeline security, secrets management, artifact integrity, build/release controls, and automation
- Experience with application security tooling and processes, including SAST/SCA/DAST and related scanning in pipelines
- Working knowledge of AI/ML security risks and mitigations for applications using ML models or GenAI components
- Strong collaborative and consulting skills; ability to influence without authority, communicate clearly, and deliver pragmatic, developer-friendly recommendations
- Bachelor's Degree

















