Senior Application Security Architect

Insight Global
Naperville, IL, United States
1 day ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Applications Architecture Business Logic Software System Penetration Testing User Authentication Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security
+57 more
Cloud Engineering Code Review Cyber Security Continuous Integration Data Integration Software Design Patterns Github Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection Systems Mobile Application Software OSI Models Python (Programming Language) Key Management Network Security Log Analysis Network Segmentation OAuth OpenID Open Web Application Security Platform as a Service (PAAS) Windows PowerShell Proprietary Software Cloud Services Secure Coding Session Management Shell Script Security Information and Event Management Single Sign-On Software Engineering Data Streaming Systems Integration TCP/IP Software Vulnerability Management Web Applications Web Application Frameworks Data Logging Google Cloud Cloud Platform System Retrieval-Augmented Generation Large Language Models Software Security Generative AI Cyber Threat Analysis Firewalls (Computer Science) Event Driven Architecture Kubernetes Information Technology Api Gateway Data Pipelines Devsecops Serverless Computing Service Stack Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Job description

A client has a unique opportunity for a Senior Application Security Architect to join their organization in a role that allows for a direct impact on conserving vital resources and protecting the people they serve.

The Senior Application Security Architect will serve as a senior technical leader within the Product Security Team and provide security architecture leadership across the client’s commercial digital product portfolio. This role reviews the full product lifecycle and technology stack, including web and mobile applications, APIs, cloud IaaS/PaaS architectures, SaaS platforms, AI-enabled capabilities, IoT-connected solutions, data integrations, third-party software, and customer-facing product components.

The Senior Application Security Architect will combine deep application and product security architecture expertise with practical hands-on engineering skills. The role will define secure design patterns and reference architectures, lead complex threat modeling and architecture reviews, perform targeted security testing and code/dependency analysis, guide remediation, mentor technical teams, and help engineering teams integrate security into their software development lifecycle.

Lead complex application and product security architecture reviews across the organization’s commercial digital products, including web/mobile applications, APIs, SaaS platforms, cloud services, containers, AI-enabled capabilities, IoT solutions, endpoints, network-connected components, and third-party software.

Own and evolve SSDLC standards, secure reference architectures, reusable design patterns, application security requirements, and product security procedures aligned to practical engineering workflows.

Lead hands-on threat modeling for complex applications, APIs, cloud architectures, data flows, identity patterns, AI/ML integrations, automation workflows, and external service integrations; document threats, controls, residual risk, and remediation decisions.

Provide architecture guidance for secure application design, including authentication and authorization, session management, API security, secrets management, encryption, tenant isolation, input/output validation, logging, resilience, and secure service-to-service communication.

Perform targeted hands-on technical validation through secure code review, dependency analysis, configuration review, security testing, proof-of-concept development, and validation of remediation effectiveness.

Conduct and guide technical security reviews using SAST, SCA, SBOM, DAST, secrets scanning, API security, container security, cloud security posture, vulnerability management, and AI security evaluation tools.

Use and help operationalize platforms such as Snyk, Wiz, GitHub Advanced Security, DAST tooling, threat modeling tools, SBOM/SCA tooling, CI/CD security tooling, native Azure/AWS security services, and SIEM/log analysis tools such as Elastic.

Influence and partner with software engineering, architecture, product, and DevSecOps leaders to embed security controls, design reviews, test gates, evidence collection, automated response workflows, and remediation tracking into CI/CD pipelines and product release processes.

Design and review identity, access, and secure communication architectures, including IAM, OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, privileged access, encryption, secure APIs, secrets management, and service-to-service communication.

Analyze application, cloud, API, container, endpoint, and security telemetry to support threat detection, anomalous behavior investigation, incident triage, containment support, product risk decisions, and prioritized remediation plans.

Translate complex architecture risks and technical findings into actionable design guidance, remediation plans, standards updates, metrics, risk inputs, and concise executive and stakeholder-ready summaries.

Support customer-facing cybersecurity discussions, questionnaires, and technical documentation related to the organization’s commercial product security, application architecture, cloud controls, and SSDLC practices.

Stay current on application security architecture, cloud security, DevSecOps, vulnerability management, secure coding, threat intelligence, AI application security, and relevant frameworks and standards including NIST, OWASP, CIS, ISO 27001, SOC 2, and applicable secure software guidance.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

Bachelor’s Degree in Cybersecurity, Computer Science, Software Engineering, IT Technology, or related technology-driven field.

  • 10+ years of experience in cybersecurity, application security, product security, software engineering, cloud security, or related technology roles.

  • 5+ years of hands-on experience as an application security architect, senior application security engineer, product security architect, software architect, senior software engineer, or similar technical role supporting modern application architectures.

  • 4+ years of experience leading complex application security architecture reviews, threat modeling, secure design assessments, vulnerability assessments, penetration test coordination, or technical product security reviews.

  • Hands-on experience with SSDLC, DevSecOps, SAST, DAST, SCA, SBOM, API security, container security, secrets scanning, secure CI/CD pipeline controls, code review, and remediation workflows.

  • Hands-on experience with Microsoft Azure and AWS cloud security, including native cloud security services, IaaS/PaaS security patterns, cloud posture management, secure workload configuration, and cloud-native application architectures.

  • Strong understanding of IAM across Azure and AWS, including OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, authorization models, and privileged access patterns.

  • Hands-on scripting and automation experience with Python, PowerShell, or shell scripting for security testing, data/log analysis, proof-of-concept development, automation, and security tool integration.

  • Demonstrated experience creating secure reference architectures and design patterns for web applications, mobile applications, APIs, microservices, containers, cloud platforms, data integrations, and third-party services.

  • Working knowledge of common application vulnerabilities and attack techniques, including the OWASP Top 10, API security risks, authentication and authorization weaknesses, injection, insecure deserialization, server-side request forgery, supply chain risk, and business logic abuse.

  • Working knowledge of network security fundamentals, including TCP/IP, OSI model, firewalls, WAFs, IDS/IPS, network segmentation, web/application protocols, and secure service-to-service communication.

  • Knowledge of encryption, key and secrets management, secure API design, privacy/security-by-design, vulnerability management, logging/monitoring, secure coding practices, and cloud security architecture.

  • Demonstrated ability to independently identify, explain, prioritize, and drive remediation of complex application, cloud, identity, AI-enabled application, and product security risks with engineering and product teams.

  • Demonstrate strong interpersonal communications, technical leadership, influence, mentoring, analytical, problem solving, organizational, and written/verbal communication skills.

  • Ability to accommodate a flexible work schedule for supporting global product teams and activities. - One or more relevant security certifications preferred, such as CISSP, CSSLP, CCSP, cloud security certification, AWS/Azure security certification, GIAC application security certification, or secure software/coding certification.

  • Experience developing and governing SSDLC standards, secure coding standards, application security reference architectures, reusable design patterns, security requirements, risk assessment methodologies, or product security governance processes.

  • Experience with architecture modeling and threat modeling methods and tools, including data flow diagrams, attack trees, STRIDE, abuse cases, or equivalent techniques.

  • Experience securing microservices, Kubernetes, containers, serverless architectures, event-driven systems, API gateways, service meshes, mobile platforms, and modern web application frameworks.

  • Experience reviewing AI-enabled application architectures, including generative AI, LLM integrations, copilots, agents, retrieval-augmented generation, AI data pipelines, prompt injection defenses, and secure AI design patterns.

  • Experience supporting incident response triage, containment, root cause analysis, and integration with automated response or security orchestration tools.

  • Experience with Google Cloud security and Google Cloud IAM.

  • Experience leading complex, cross-functional technical projects, remediation initiatives, standards adoption, security tooling implementation, architecture governance, or application security maturity improvement programs.

  • Experience working with global product, software engineering, DevSecOps, enterprise architecture, cloud architecture, legal/privacy, risk, compliance, and customer-facing teams.

  • Experience presenting architecture decisions, technical risks, and remediation recommendations to technical and non-technical stakeholders, including senior leadership.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all