Application Security (AppSec) Architect

New York, Inc.
Maryland Heights, MO, United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration DevOps Key Management
+14 more
Open Web Application Security Systems Development Life Cycle Sherwood Applied Business Security Architecture Secure Coding Software Engineering Data Streaming Data Logging Google Cloud Enterprise Software Applications Software Security Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

The Senior Application Security Architect will lead Secure-by-Design initiatives across enterprise applications by embedding security early in the software development lifecycle (SDLC). The role is responsible for conducting threat modeling, security architecture reviews, secure design assessments, and establishing security guardrails aligned with OWASP ASVS, NIST SSDF, and industry best practices. The architect will work closely with developers, enterprise architects, DevOps teams, and business stakeholders to ensure security risks are identified and mitigated before applications reach production., Secure-by-Design Leadership

  • Define and implement Secure-by-Design principles across application development programs.
  • Develop security reference architectures, reusable security patterns, and architecture standards.
  • Embed security requirements into solution design and development processes.

Threat Modeling & Risk Analysis

  • Conduct threat modeling workshops using STRIDE, Attack Trees, or similar methodologies.
  • Identify trust boundaries, attack surfaces, abuse cases, and potential design weaknesses.
  • Provide risk-based mitigation recommendations and architectural guidance.

Security Architecture Reviews

  • Perform application, API, microservices, cloud-native, and AI-enabled application security reviews.
  • Validate architecture compliance against OWASP ASVS, OWASP Top 10, NIST SSDF, and organizational standards.
  • Review data flows, authentication, authorization, encryption, secrets management, and logging controls.

Secure SDLC & DevSecOps

  • Integrate security requirements into Agile and CI/CD workflows.
  • Collaborate with development teams to implement security-by-default controls.
  • Support adoption of SAST, DAST, SCA, API Security, Container Security, and Secure Coding practices.

Developer Enablement

  • Provide secure coding guidance and architectural consultation.
  • Conduct architecture review sessions, threat modeling training, and security awareness workshops.
  • Act as a trusted advisor to engineering and product teams.

Governance & Stakeholder Management

  • Partner with Enterprise Architects, Product Teams, Security Leadership, and Development Managers.
  • Define security acceptance criteria and architecture review processes.
  • Present security findings, risks, and remediation strategies to senior leadership.

Requirements

  • Secure-by-Design Methodologies
  • Threat Modeling (STRIDE, Attack Trees, PASTA)
  • OWASP ASVS, OWASP Top 10
  • Secure SDLC / DevSecOps
  • Security Architecture Reviews
  • Secure Coding Practices
  • API Security
  • Cloud Security (AWS, Azure, Google Cloud Platform), * 10+ years of cybersecurity, application security, or security architecture experience.
  • 5+ years leading security architecture reviews and threat modeling engagements.
  • Experience working in regulated industries such as Financial Services, Banking, Insurance, or Healthcare.
  • Demonstrated expertise implementing Secure SDLC and DevSecOps programs at enterprise scale.
  • Preferred Certifications

  • CISSP
  • CSSLP
  • CCSP
  • SABSA
  • AWS/Azure/Google Cloud Platform Security Certifications
  • GIAC GWEB / GSEC
  • Certified Secure Software Lifecycle Professional (CSSLP)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all