Application Security Architect

Veeva Systems
Oxford, UK
10 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Amazon Web Services Software System Penetration Testing Systems Engineering Microsoft Azure Cloud Computing Static Program Analysis Cyber Security Digital Signature Python (Programming Language) Key Management
+13 more
Network Security Microsoft Security Essentials Open Web Application Security Web Application Security Software Engineering Scripting Enterprise Software Applications Cloud Platform System Software Security Information Technology Veeva Static Application Security Testing Dynamic Application Security Testing

Job description

The Role

As an Application Security Architect, you are a security expert and evangelist. You provide subject matter expertise and security guidance to product engineering teams and IT to design and build secure solutions, drive the implementation of security best practices, establish security architecture standards and patterns, and perform security architecture reviews.

You will partner with other security leads to grow the security program, mentor junior security team members, measure adherence, suggest and implement changes, develop roadmaps, present to steering committees and engineering teams, and promote security awareness company wide.

What You’ll Do

  • Build strong relationships and effectively influence Veeva’s product and IT engineering
  • Translate security risks to business impact
  • Research, prioritize, coordinate, and communicate security solution recommendations
  • Provide security architecture advice in support of product application development, cloud infrastructure, and enterprise technology projects
  • Perform code analysis, application security reviews, and contribute to the application security training program
  • Stay current with security technologies and make usage recommendations
  • Maintain an expert knowledge level of Information Security and the related issues, systems, processes, products, and services.

Requirements

  • Excellent written and verbal communication
  • Ability to evangelize technical security needs to product leadership and engineers
  • Broad experience with information, system, and network security concepts and components
  • Demonstrated experience with architecture and security reviews, threat modeling applications and identifying areas of risk
  • Experience implementing strategies to support secure and compliant architectures
  • Deep understanding of the OWASP Top 10 application security risks and how to address them
  • Expert knowledge of Amazon AWS, Microsoft Azure or other cloud computing platform offerings and security related services
  • Experience with web application security scanning software and related assessment tools such as SAST/DAST/SCA
  • Working knowledge of encryption, hashing, secure random number generation, key derivation, key management, digital signatures
  • Understanding of internet-scale, distributed, multi-tenant architecture and services.
  • Knowledge of Java and the Java Ecosystem. Proficiency with Python, JavaScript and other scripting languages
  • BS in Computer Science or equivalent with 10+ years of experience

Nice to Have

  • Experience with assessing and providing recommendations for securing generative AI solutions
  • Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM).
  • Familiar with compliance regulations like; ISO, GDPR, SOC2, SOX
  • MS in Cyber Security, Information Security, MIS or equivalent
  • Industry security certifications such as CISSP or others
  • Experience in Application penetration testing, CTF competitions, CVE research and/or Bug Bounty recognition
  • Experience in Web and Mobile (Android/iOS) based application/service assessment

Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.

As an equal opportunity employer, Veeva is committed to fostering a culture of inclusion and growing a diverse workforce. Diversity makes us stronger. It comes in many forms. Gender, race, ethnicity, religion, politics, sexual orientation, age, disability and life experience shape us all into unique individuals. We value people for the individuals they are and the contributions they can bring to our teams.

If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us at .

Requirements

  • Excellent written and verbal communication
  • Ability to evangelize technical security needs to product leadership and engineers
  • Broad experience with information, system, and network security concepts and components
  • Demonstrated experience with architecture and security reviews, threat modeling applications and identifying areas of risk
  • Experience implementing strategies to support secure and compliant architectures
  • Deep understanding of the OWASP Top 10 application security risks and how to address them
  • Expert knowledge of Amazon AWS, Microsoft Azure or other cloud computing platform offerings and security related services
  • Experience with web application security scanning software and related assessment tools such as SAST/DAST/SCA
  • Working knowledge of encryption, hashing, secure random number generation, key derivation, key management, digital signatures
  • Understanding of internet-scale, distributed, multi-tenant architecture and services.
  • Knowledge of Java and the Java Ecosystem. Proficiency with Python, JavaScript and other scripting languages
  • BS in Computer Science or equivalent with 10+ years of experience, * Experience with assessing and providing recommendations for securing generative AI solutions
  • Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM).
  • Familiar with compliance regulations like; ISO, GDPR, SOC2, SOX
  • MS in Cyber Security, Information Security, MIS or equivalent
  • Industry security certifications such as CISSP or others
  • Experience in Application penetration testing, CTF competitions, CVE research and/or Bug Bounty recognition
  • Experience in Web and Mobile (Android/iOS) based application/service assessment

About the company

Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.

As an equal opportunity employer, Veeva is committed to fostering a culture of inclusion and growing a diverse workforce. Diversity makes us stronger. It comes in many forms. Gender, race, ethnicity, religion, politics, sexual orientation, age, disability and life experience shape us all into unique individuals. We value people for the individuals they are and the contributions they can bring to our teams.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all