> Markdown version of [/jobs/ext/1346322-staff-application-security-architect](https://www.wearedevelopers.com/jobs/ext/1346322-staff-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Application Security Architect - **Company:** Rock Family of Companies - **Location:** Stewart, MN, United States - **Experience:** Expert - **Salary:** $149,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), .NET Framework, Artificial Intelligence, User Authentication, Bash Shell, Code Review, Cyber Security, Continuous Integration, Data Validation, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Zero Trust Network Access, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, Software Systems, Software Vulnerability Management, Scripting, Software Security, Mitre Att&ck, GWAPT, Kubernetes, Information Technology, Enterprise Integration, Build Process, Api Design, Devsecops, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 19, 2026 - **Apply:** https://www.juju.com/job/00000000ghqxpy ## About the Role + 10 years of experience in an information security, application development with a secure coding background or software engineering role with a focus on secure code & design principles, OR bachelor's degree in computer science, information security, or a related field and 5 years of experience. + Proven experience performing architectural threat modeling on complex systems and applications using formal frameworks (e.g., STRIDE, DREAD, PASTA) + Strong ability to read, write, and audit code for security vulnerabilities, with the ability to provide engineering teams with precise, actionable remediation guidance + Deep technical familiarity with **Java** ecosystem (strongly preferred), as well as **.NET** and/or **Python** + Proficiency in at least one scripting language (e.g., PowerShell, Bash, Python) for automation and custom tooling + Demonstrated aptitude for leveraging AI-assisted engineering tools to drive operational efficiency, balanced with the critical thinking required to identify, validate, and correct AI inaccuracies or hallucinations + Practical experience or working knowledge of the following: + Secure SDLC frameworks + DevSecOps pipeline integration (CI/CD) + SAST /DAST/SCA/Secret Scanning tooling + Identity and access management (OAuth 2.0, OIDC, SAML) + Container security (Docker, Kubernetes) + OWASP Top 10 / ASVS mappings + Familiarity with the MITRE ATT&CK Framework + Strong knowledge of fundamental InfoSec concepts, such as least privilege, zero trust architectures, secure input validation, layered security, secure defaults, etc. + Deep understanding of modern enterprise security risks such as software supply chain Security, securing & hardening development environments, and identifying and mitigating risk at scale. Preferred Qualifications + Master's degree in computer science, information security, or a related field + Advanced expertise in architectural threat modeling and building automated threat modeling capabilities into developer workflows + OSCP, OSWE, GWAPT, CISSP, CCSP, or other relevant security certifications + Hands-on experience scaling AppSec programs across large engineering organizations, including, integrating secure solutions across an organization's SDLC, and/or experience administering a developer security champion program + Strong technical experience with Java ## Description As the Senior Application Security Architect, you work strategically with engineering and product teams to enable the delivery of secure application patterns and software solutions. You design standard security requirements for how applications should be built, deployed, and maintained, ensuring security is baked into the software development lifecycle from the start. You also build and mature team processes that empower development teams to own their software's security posture while mentoring internal security team members. About the** **r** **ole + Perform Security Reviews of applications throughout the SDLC including at the design and implementation phases through formal threat modeling and source code reviews, focusing on designing secure applications from the start and ensuring secure design principles are correctly implemented. + Help to set strategic direction for application security initiatives, shift-left processes, and secure coding standards across the enterprise with a focus on treating security as quality. + Build relationships and collaborate with software engineering, product, and architecture teams to ensure alignment of company vision and secure coding goals. + Continually identify opportunities for improvement within software delivery pipelines and work with engineering leadership to implement automated security guardrails and remediations. + Collaborate with business, product owners, architecture, and information security teams to enable the delivery of secure software patterns that support business velocity + Coordinate and drive initiatives for AppSec engineers to build, execute, and scale application security strategies. + Help to build processes that test the compliance and effectiveness of software security requirements through automated guardrails and continuous security testing. + Influence decision-makers in the areas of secure application architecture, API design, authentication/authorization controls, and modern cloud deployment. + Create and evangelize application security policy sets and secure design patterns to be used throughout the company that balance velocity and external compliance requirements. + Work directly with development and audit teams to help align security architectures against upcoming compliance, regulatory (e.g., SSDF, Executive Orders on Cybersecurity), and contractual landscapes. + Mentor software engineers and information security team members on threat modeling, secure code design, and modern vulnerability remediation techniques. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)