Senior Application Security Architect

Automatic Data Processing, Inc.
Alpharetta, GA, United States
1 day ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration Data Governance Data Security Identity and Access Management Key Management
+24 more
OAuth OpenID Open Web Application Security Systems Development Life Cycle Cloud Services Zero Trust Network Access Secure Coding Security Software Automated Data Processing (ADP) Data Logging Google Cloud Cloud Platform System Large Language Models Software Security Generative AI Information Technology Enterprise Integration Virtual Agents CIS Benchmarks Oracle Cloud Infrastructure Devsecops Serverless Computing Vulnerability Analysis Microservices

Job description

We are seeking a highly skilled and experienced Senior Application Security Architect to join our team. In this role, you will be part of the Product Security organization within ADP’s Global Security Organization (GSO) , which plays a strategic role in enabling secure development and supporting the delivery of trusted products, solutions, and services across the entire ADP ecosystem.

As a Senior Application Security Architect, you will partner closely with product, engineering, and cloud architecture teams to design and guide the implementation of secure application architectures. You will leverage your deep expertise in application security architecture, Cloud security, and AI/GenAI security , to influence design decisions, reduce risk, and champion secure-by-design principles across the organization.

This role is instrumental in helping teams build secure applications, integrate third-party and SaaS solutions responsibly, and elevate ADP’s overall security posture through thought leadership, architectural oversight, and proactive engagement throughout the SDLC., * Partner with global product and engineering teams to design, review, and evolve secure application architectures across multi-country environments.

  • Conduct in-depth security architecture reviews and provide clear, actionable security requirements, design guidance, and validation throughout the entire solution lifecycle.
  • Advise on GenAI, LLM, and AI/ML application security , including data protection, model security, prompt injection mitigation, dependency controls, secure model integration, and risk evaluation of AI-driven components.
  • Perform security assessments of Cloud Services (AWS, Azure, GCP, OCI) to confirm required security requirements to enable Cloud services at ADP.
  • Influence technical leaders -solution architects, security champions, engineering managers, and developers-to adopt secure-by-design principles and continuously improve security maturity.
  • Support Threat Modeling activities , leveraging tools such as IriusRisk to help teams create architecture diagrams, identify security risks, define countermeasures, and validate threat coverage.
  • Develop and maintain secure architecture patterns, reference architectures, and application security standards , ensuring alignment with industry frameworks (e.g., NIST, OWASP, CIS).
  • Embed security across the SDLC , educating product teams on integrating secure coding practices, secure API design, CI/CD security controls, and automated security testing.
  • Support secure integration of third-party platforms, SaaS solutions, and cloud-native services , ensuring vendor risk and architecture risks are understood and mitigated.
  • Partner with Cloud Architecture teams to ensure consistent application of cloud security controls across AWS, Azure, and hybrid environments.
  • Communicate complex security concepts to both technical and non-technical stakeholders, enabling informed decision-making at all levels.

Requirements

  • You’ll have a bachelor’s degree in computer science, Information Security, Engineering, or a related field (or equivalent experience)., * 8+ years of experience in Application Security, Security Architecture, or related technical security roles.
  • Deep expertise in Application Security practices , including secure coding, API security, microservices, cloud application security, DevSecOps, and security scanning tools.
  • Strong understanding of GenAI / LLM / Agentic AI security , including data governance, retrieval-augmented generation (RAG), model threats, prompt injection risks, and secure integration patterns.
  • Strong knowledge of cloud platform (such as AWS, Azure, OCI, and/or GCP) security capabilities and controls.
  • Strong knowledge of security frameworks and standards (e.g., OWASP ASVS, SAMM, NIST 800-53, NIST CSF, ISO 27001, CIS Controls ).
  • Hands-on experience with Threat Modeling methodologies, tools (e.g., IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool), and risk assessment techniques.
  • Knowledge of identity and access management , OAuth2/OIDC, JWT security, secrets management, key management, and zero-trust design principles.
  • Experience with CI/CD pipeline security and infrastructure-as-code security.
  • Strong understanding of data security , encryption, privacy-by-design, and secure logging and monitoring practices.
  • Excellent communication, collaboration, and stakeholder engagement skills, with the ability to influence and drive security adoption.
  • Relevant security certifications are a plus: CISSP, CISM, CCSP, CSSLP, CEH, SANS/GIAC certifications , or cloud security certifications such as Google Professional Cloud Security Engineer .

About the company

Do you have a passion for going on the offensive to safeguard critical information? As ADP’s Global Security Organization (GSO), we know that our clients rely on us for human capital management solutions, but beyond that, they entrust us with one of their most valuable assets – their employee data.

We are honored by this trust and are laser focused on securing data at every step in the information lifecycle, ensuring integrity, confidentiality and compliance with industry and government regulations at all times.

From the cloud to the data center and across every emerging device, you’ll join a team of experts in the GSO who are always staying one step ahead in this ever-changing world of data by continually evolving our strategies and technologies to protect ADP and our clients., A little about ADP: We are a comprehensive global provider of cloud-based human capital management (HCM) solutions that unite HR, payroll, talent, time, tax and benefits administration and a leader in business outsourcing services, analytics, and compliance expertise. We believe our people make all the difference in cultivating a down-to-earth culture that embraces our core values, welcomes ideas, encourages innovation, and values belonging. We’ve received recognition for our work by many esteemed organizations, learn more at ADP Awards and Recognition (https://www.adp.com/about-adp/awards-and-recognition.aspx) ., Ethics at ADP: ADP has a long, proud history of conducting business with the highest ethical standards and full compliance with all applicable laws. We also expect our people to uphold our values with the highest level of integrity and behave in a manner that fosters an honest and respectful workplace. Click https://jobs.adp.com/life-at-adp/ to learn more about ADP’s culture and our full set of values.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all