> Markdown version of [/jobs/ext/2636809-application-security-appsec-architect](https://www.wearedevelopers.com/jobs/ext/2636809-application-security-appsec-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security (AppSec) Architect - **Company:** New York, Inc. - **Location:** Maryland Heights, MO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Key Management, Open Web Application Security, Systems Development Life Cycle, Sherwood Applied Business Security Architecture, Secure Coding, Software Engineering, Data Streaming, Data Logging, Google Cloud, Enterprise Software Applications, Software Security, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 5, 2026 - **Apply:** https://www.dice.com/job-detail/0ca555bc-61ff-4568-8936-223f79087d83 ## About the Role * Secure-by-Design Methodologies * Threat Modeling (STRIDE, Attack Trees, PASTA) * OWASP ASVS, OWASP Top 10 * Secure SDLC / DevSecOps * Security Architecture Reviews * Secure Coding Practices * API Security * Cloud Security (AWS, Azure, Google Cloud Platform), * 10+ years of cybersecurity, application security, or security architecture experience. * 5+ years leading security architecture reviews and threat modeling engagements. * Experience working in regulated industries such as Financial Services, Banking, Insurance, or Healthcare. * Demonstrated expertise implementing Secure SDLC and DevSecOps programs at enterprise scale. * Preferred Certifications * CISSP * CSSLP * CCSP * SABSA * AWS/Azure/Google Cloud Platform Security Certifications * GIAC GWEB / GSEC * Certified Secure Software Lifecycle Professional (CSSLP) ## Description The Senior Application Security Architect will lead Secure-by-Design initiatives across enterprise applications by embedding security early in the software development lifecycle (SDLC). The role is responsible for conducting threat modeling, security architecture reviews, secure design assessments, and establishing security guardrails aligned with OWASP ASVS, NIST SSDF, and industry best practices. The architect will work closely with developers, enterprise architects, DevOps teams, and business stakeholders to ensure security risks are identified and mitigated before applications reach production., Secure-by-Design Leadership * Define and implement Secure-by-Design principles across application development programs. * Develop security reference architectures, reusable security patterns, and architecture standards. * Embed security requirements into solution design and development processes. Threat Modeling & Risk Analysis * Conduct threat modeling workshops using STRIDE, Attack Trees, or similar methodologies. * Identify trust boundaries, attack surfaces, abuse cases, and potential design weaknesses. * Provide risk-based mitigation recommendations and architectural guidance. Security Architecture Reviews * Perform application, API, microservices, cloud-native, and AI-enabled application security reviews. * Validate architecture compliance against OWASP ASVS, OWASP Top 10, NIST SSDF, and organizational standards. * Review data flows, authentication, authorization, encryption, secrets management, and logging controls. Secure SDLC & DevSecOps * Integrate security requirements into Agile and CI/CD workflows. * Collaborate with development teams to implement security-by-default controls. * Support adoption of SAST, DAST, SCA, API Security, Container Security, and Secure Coding practices. Developer Enablement * Provide secure coding guidance and architectural consultation. * Conduct architecture review sessions, threat modeling training, and security awareness workshops. * Act as a trusted advisor to engineering and product teams. Governance & Stakeholder Management * Partner with Enterprise Architects, Product Teams, Security Leadership, and Development Managers. * Define security acceptance criteria and architecture review processes. * Present security findings, risks, and remediation strategies to senior leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)