> Markdown version of [/jobs/ext/1786640-application-security-devsecops-architect](https://www.wearedevelopers.com/jobs/ext/1786640-application-security-devsecops-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security & DevSecOps Architect - **Company:** Mutual Medical, Inc. - **Location:** Cleveland, OH, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software Applications, Microsoft Azure, Burp Suite, Cloud Computing Security, Databases, Continuous Integration, Data Warehousing, Software Design Patterns, Programming Tools, Enterprise Architecture Framework, Middleware, Github, IT Management, Information Systems Security Architecture Professional, Microsoft Software, OAuth, Open Source Technology, OpenID, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Engineering, SonarQube, Systems Architecture, Software Vulnerability Management, Web Applications, Cloud Collaboration, Software Security, Veracode, Gitlab, Togaf, Kubernetes, Information Technology, Checkmarx, DODAF, Devsecops, Qualys, Docker, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 18, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17631227?backUrl=%2Fcareer%2F17631227%2FApplication-Security-Devsecops-Architect-Ohio-Cleveland ## About the Role * Hands-on experience with application security tooling: + SAST (Snyk, Wiz, Checkmarx, Veracode, Semgrep, SonarQube) + DAST (Qualys, Burp Suite, OWASP ZAP, Invicti) + SCA, IaC scanning, container security tools * Strong knowledge of: + OWASP Top 10, CWE Top 25 + Threat modeling (STRIDE, PASTA, or equivalent) + API security and authentication (OAuth2, OIDC, SAML) * Experience with: + CI/CD platforms (Azure DevOps, GitHub Actions, Jenkins, GitLab) + Cloud security (AWS, Azure) + Containers and orchestration (Docker, Kubernetes) * Working knowledge of secure architecture patterns and Zero Trust principles, * Bachelor's degree in Computer Science or related field or equivalent combination of training/education and experience. * 3 years proven ability to transfer technology to end user applications/environments. * Experience in cutting edge web collaboration design patterns and best practices, * Expert in one or more technologies (Microsoft, OpenSource, Database (relational, graph, Map, document, etc.). * Basic knowledge in infrastructure and networks with focus on security. * Basic understanding of various project methodology disciplines with basic knowledge of information and systems architectures, highly proficient in website architectures. * Basic understanding of various data base platforms and data warehousing., * Bachelor's degree in Computer Science or related field or equivalent combination of training/education and experience. * 5 years proven ability to transfer technology to end user applications/environments. * 2 years of experience influencing technical direction in one of the following: application, data bases, or infrastructure., * Expert in one or more technologies (Microsoft, OpenSource, Databased (relational, graph, Map, Document). * Experience with suite of IT applications including transactional, middleware integration, workflow, web based. * Solid knowledge in infrastructure and networks with a focus on security. * Solid understanding of various project methodology disciplines with solid knowledge of information and systems architectures, highly proficient in website architectures. * Solid understanding of various data base platforms and data warehousing. * Exposure to EA Framework such as FEAC, TOGAF or DODAF., * Bachelor's degree in Computer Science or related field or equivalent combination of training/education and experience. * 7 years proven ability to transfer technology to end user applications/environments. * 3 years of experience influencing technical direction in one of the following: application, data bases, or infrastructure., * Expert in one or more technologies (Microsoft, OpenSource, Databased (relational, graph, Map, Document). * Experience with suite of IT applications including transactional, middleware integration, workflow, web based. * Advanced knowledge in infrastructure and networks with a focus on security. * Advanced understanding of various project methodology disciplines with advanced knowledge of information and systems architectures, highly proficient in wesite architectures. * Advanced understanding of various data base platforms and data warehousing. * Exposure to EA Framework such as FEAC, TOGAF or DODAF. ## Description The Application Security & DevSecOps Architect will lead the design and implementation of secure application architecture and DevSecOps practices across the enterprise, embed security throughout the software development lifecycle (SDLC) to reduce risk, improve resiliency, and enable scalable, secure software delivery and serve as the primary technical authority for application security, vulnerability management, and DevSecOps pipeline security., Assists in the development of solution options to arrive at better decisions that will reduce IT cost, improve system flows, increase agility, and remove duplicative functionality. Supports the management of risk associated with IT assets through the development and promotion of standards and polices. Expertise may be concentrated in one or more domains., * Acts as a subject matter expert (SME) to assist various IT areas to support efficiencies in overall design for implementations of new technologies and improvement of existing processes. Advises on best practices and ensures policy and procedure adherence. * Assists in the definition of the current and future state and the transitional plan. Focuses on the incremental improvements that move toward the future state looking for opportunities to streamline environments and remove redundancy. * Collaborates within teams, participates in reviews of all prospective software and hardware acquisitions. Evaluates compatibility with current architecture and supports future architecture roadmaps. Identifies architectural risks and proposes alternatives and solutions. Documents exceptions to architectural standards. * Assists in the review and revisions of new and existing IT standards and policies evaluating their importance. Assists in the development of architectural metrics and reports. * Maintains active awareness of IT industry including new developments, emerging trends, development tools and best practices. * Performs other duties as assigned., Acts in a leadership role that ensures the IT architectural strategy aligns with the overall corporate strategy and is tune with evolving business trends and technology capabilities. Assists in the development of solution options to arrive at better decisions that will reduce IT cost, improve system flows, increase agility, and remove duplicative functionality. Supports the management of risk associated with IT assets through the development and promotion of standards and polices. Expertise may be concentrated in one or more domains., * Translates overall IT roadmap into actionable processes. Supports the establishment of targeted architecture and develops standards for the organization covering all key domains (Application, Data, and Infrastructure). * Assists in the definition of the current and future state and the transitional plan. Focuses on the incremental improvements that move toward the future state looking for opportunities to streamline environments and remove redundancy. * Collaborates within teams, participates in reviews of all prospective software and hardware acquisitions. Evaluates compatibility with current architecture and supports future architecture roadmaps. Identifies architectural risks and proposes alternatives and solutions. Documents exceptions to architectural standards. * Reviews new and existing IT standards, and architectural plans modifies or creates standards and policies to support the future state. Develops architectural metrics and reports for the executive team, business and IT management. * Maintains active awareness of IT industry including new developments, emerging trends, development tools and best practices * Performs other duties as assigned., * Translates overall IT roadmap into actionable processes. Supports the establishment of targeted architecture and develops standards for the organization covering all key domains (Application, Data, and Infrastructure). * Defines the current and future state and the transitional plan. Focuses on the incremental improvements that move toward the future state looking for opportunities to streamline environments and remove redundancy. * Collaborates within teams, participates in reviews of all prospective software and hardware acquisitions. Evaluates compatibility with current architecture and supports future architecture roadmaps. Identifies architectural risks and proposes alternatives and solutions. Documents exceptions to architectural standards. * Review new and existing IT standards, and architectural plans modifies or creates standards and policies to support the future state. develops architectural metrics and reports for the executive team, business and IT management. * Maintain active awareness of IT industry including new developments, emerging trends, development tools and best practices * Performs other duties as assigned. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)