> Markdown version of [/jobs/ext/2105511-application-security-architect](https://www.wearedevelopers.com/jobs/ext/2105511-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - **Company:** Fynbosys Inc - **Location:** New York, United States - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Integration, Information Leak Prevention, Identity and Access Management, OAuth, OpenID, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, JSON Web Token, Policy as Code, Google Cloud, Large Language Models, Software Security, Kubernetes, Virtual Agents, Terraform, Docker, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/494de4e2-0ad6-4d0a-b5cc-29f1548f6cbf ## About the Role * 12+ years of experience in Application Security / Security Architecture. * Strong knowledge of OWASP, Threat Modeling, Secure SDLC, API Security, SAST/DAST/SCA. * Experience with AWS/Google Cloud Platform, Kubernetes, Docker, CI/CD, Terraform. * Strong understanding of OAuth2, OIDC, JWT, IAM, RBAC/ABAC. * Experience with GenAI/LLM, RAG, Agentic AI, or AI Security. * Knowledge of LangChain/LangGraph, vector databases, and AI security controls is a plus. * Strong communication and stakeholder management skills. ## Description * Design and implement application security architecture across applications, APIs, and microservices. * Perform threat modeling, security reviews, and vulnerability assessments. * Embed security into the SDLC and CI/CD pipelines using SAST, DAST, SCA, and other security tools. * Ensure secure coding practices aligned with OWASP Top 10 and API Security. * Secure cloud-native applications across AWS/Google Cloud Platform, Kubernetes, and containers. * Define security controls for GenAI, LLM, RAG, and Agentic AI applications. * Address AI security risks such as prompt injection, data leakage, insecure outputs, and excessive agency. * Implement IAM, authentication, authorization, encryption, Policy-as-Code, and Identity-as-Code. * Partner with engineering and security teams to drive security-by-design. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)