Security Architect IV 4P/689

4P Consulting Inc.
Atlanta, GA, United States
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure C Sharp (Programming Language) Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Executive Information Systems Python (Programming Language)
+16 more
Open Web Application Security Fortify (Software) Secure Coding Web Application Security Software Engineering Software Vulnerability Management Enterprise Software Applications Large Language Models Sonatype Software Security Mttr Github Enterprise Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking an experienced Security Architect IV with strong expertise in Application Security, DevSecOps, cloud security architecture, vulnerability management, and secure software development . This role will help design and implement enterprise application security programs, integrate security tools into CI/CD pipelines, and support secure development practices across modern application environments., * Design and implement Application Security and DevSecOps programs.

  • Integrate security testing tools into CI/CD pipelines.
  • Support secure development practices and shift-left security.
  • Manage application vulnerabilities, remediation tracking, and security metrics.
  • Define and report KPIs such as MTTR, severity trends, and SLA compliance.
  • Build dashboards and executive-level security reports.
  • Perform security risk assessments and recommend mitigation strategies.
  • Secure APIs, microservices, cloud applications, and modern application platforms.
  • Evaluate security risks related to AI-enabled applications, LLM integrations, AI-driven APIs, and AI-generated code.
  • Partner with developers, architects, product teams, and leadership to improve application security.

Requirements

Do you have experience in Web Application Security Testing?, The ideal candidate will have hands-on experience with SAST, SCA, DAST, vulnerability management, application risk assessments, AI-enabled applications, APIs, microservices, and cloud security ., * 10+ years of information security or security architecture experience.

  • At least 5 years in application security, DevSecOps, or related roles.
  • Strong experience with SAST, SCA, DAST, CI/CD security integration, and vulnerability management.
  • Hands-on experience with tools such as GitHub Enterprise, Azure DevOps, Sonatype, Fortify, Snyk, JFrog, or similar platforms.
  • Experience with application and cloud security architecture, APIs, microservices, and secure coding practices.
  • Proficiency in one or more programming languages such as C#, Python, Java, or JavaScript.
  • Working knowledge of OWASP Top 10, NIST, ISO, and secure development standards.
  • Strong communication skills with the ability to translate technical risks into business impact.
  • Must pass Insider Threat Protection background checks., * Security certifications such as CISSP, CSSLP, CCSP, CISA, GIAC, OSCP, or similar.
  • Experience securing AI-enabled applications and AI-generated code.
  • Experience creating executive dashboards and security metrics., Application Security, DevSecOps, SAST, SCA, DAST, CI/CD, Vulnerability Management, Cloud Security, API Security, Microservices, AI Security, Secure Coding, OWASP, NIST, ISO, Risk Assessment, GitHub Enterprise, Azure DevOps, Fortify, Snyk, Sonatype, JFrog.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · WWC 2024

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

Videos

See all

Related articles

See all