> Markdown version of [/jobs/ext/3055394-senior-application-security-architect](https://www.wearedevelopers.com/jobs/ext/3055394-senior-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Architect - **Company:** Insight Global - **Location:** Naperville, IL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Applications Architecture, Business Logic, Software System Penetration Testing, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Data Integration, Software Design Patterns, Github, Infrastructure as a Service (IaaS), Identity and Access Management, Intrusion Detection Systems, Mobile Application Software, OSI Models, Python (Programming Language), Key Management, Network Security, Log Analysis, Network Segmentation, OAuth, OpenID, Open Web Application Security, Platform as a Service (PAAS), Windows PowerShell, Proprietary Software, Cloud Services, Secure Coding, Session Management, Shell Script, Security Information and Event Management, Single Sign-On, Software Engineering, Data Streaming, Systems Integration, TCP/IP, Software Vulnerability Management, Web Applications, Web Application Frameworks, Data Logging, Google Cloud, Cloud Platform System, Retrieval-Augmented Generation, Large Language Models, Software Security, Generative AI, Cyber Threat Analysis, Firewalls (Computer Science), Event Driven Architecture, Kubernetes, Information Technology, Api Gateway, Data Pipelines, Devsecops, Serverless Computing, Service Stack, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3402966854&tx=CT3028TYV&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Bachelor's Degree in Cybersecurity, Computer Science, Software Engineering, IT Technology, or related technology-driven field. - 10+ years of experience in cybersecurity, application security, product security, software engineering, cloud security, or related technology roles. - 5+ years of hands-on experience as an application security architect, senior application security engineer, product security architect, software architect, senior software engineer, or similar technical role supporting modern application architectures. - 4+ years of experience leading complex application security architecture reviews, threat modeling, secure design assessments, vulnerability assessments, penetration test coordination, or technical product security reviews. - Hands-on experience with SSDLC, DevSecOps, SAST, DAST, SCA, SBOM, API security, container security, secrets scanning, secure CI/CD pipeline controls, code review, and remediation workflows. - Hands-on experience with Microsoft Azure and AWS cloud security, including native cloud security services, IaaS/PaaS security patterns, cloud posture management, secure workload configuration, and cloud-native application architectures. - Strong understanding of IAM across Azure and AWS, including OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, authorization models, and privileged access patterns. - Hands-on scripting and automation experience with Python, PowerShell, or shell scripting for security testing, data/log analysis, proof-of-concept development, automation, and security tool integration. - Demonstrated experience creating secure reference architectures and design patterns for web applications, mobile applications, APIs, microservices, containers, cloud platforms, data integrations, and third-party services. - Working knowledge of common application vulnerabilities and attack techniques, including the OWASP Top 10, API security risks, authentication and authorization weaknesses, injection, insecure deserialization, server-side request forgery, supply chain risk, and business logic abuse. - Working knowledge of network security fundamentals, including TCP/IP, OSI model, firewalls, WAFs, IDS/IPS, network segmentation, web/application protocols, and secure service-to-service communication. - Knowledge of encryption, key and secrets management, secure API design, privacy/security-by-design, vulnerability management, logging/monitoring, secure coding practices, and cloud security architecture. - Demonstrated ability to independently identify, explain, prioritize, and drive remediation of complex application, cloud, identity, AI-enabled application, and product security risks with engineering and product teams. - Demonstrate strong interpersonal communications, technical leadership, influence, mentoring, analytical, problem solving, organizational, and written/verbal communication skills. - Ability to accommodate a flexible work schedule for supporting global product teams and activities. - One or more relevant security certifications preferred, such as CISSP, CSSLP, CCSP, cloud security certification, AWS/Azure security certification, GIAC application security certification, or secure software/coding certification. - Experience developing and governing SSDLC standards, secure coding standards, application security reference architectures, reusable design patterns, security requirements, risk assessment methodologies, or product security governance processes. - Experience with architecture modeling and threat modeling methods and tools, including data flow diagrams, attack trees, STRIDE, abuse cases, or equivalent techniques. - Experience securing microservices, Kubernetes, containers, serverless architectures, event-driven systems, API gateways, service meshes, mobile platforms, and modern web application frameworks. - Experience reviewing AI-enabled application architectures, including generative AI, LLM integrations, copilots, agents, retrieval-augmented generation, AI data pipelines, prompt injection defenses, and secure AI design patterns. - Experience supporting incident response triage, containment, root cause analysis, and integration with automated response or security orchestration tools. - Experience with Google Cloud security and Google Cloud IAM. - Experience leading complex, cross-functional technical projects, remediation initiatives, standards adoption, security tooling implementation, architecture governance, or application security maturity improvement programs. - Experience working with global product, software engineering, DevSecOps, enterprise architecture, cloud architecture, legal/privacy, risk, compliance, and customer-facing teams. - Experience presenting architecture decisions, technical risks, and remediation recommendations to technical and non-technical stakeholders, including senior leadership. ## Description A client has a unique opportunity for a Senior Application Security Architect to join their organization in a role that allows for a direct impact on conserving vital resources and protecting the people they serve. The Senior Application Security Architect will serve as a senior technical leader within the Product Security Team and provide security architecture leadership across the client's commercial digital product portfolio. This role reviews the full product lifecycle and technology stack, including web and mobile applications, APIs, cloud IaaS/PaaS architectures, SaaS platforms, AI-enabled capabilities, IoT-connected solutions, data integrations, third-party software, and customer-facing product components. The Senior Application Security Architect will combine deep application and product security architecture expertise with practical hands-on engineering skills. The role will define secure design patterns and reference architectures, lead complex threat modeling and architecture reviews, perform targeted security testing and code/dependency analysis, guide remediation, mentor technical teams, and help engineering teams integrate security into their software development lifecycle. Lead complex application and product security architecture reviews across the organization's commercial digital products, including web/mobile applications, APIs, SaaS platforms, cloud services, containers, AI-enabled capabilities, IoT solutions, endpoints, network-connected components, and third-party software. Own and evolve SSDLC standards, secure reference architectures, reusable design patterns, application security requirements, and product security procedures aligned to practical engineering workflows. Lead hands-on threat modeling for complex applications, APIs, cloud architectures, data flows, identity patterns, AI/ML integrations, automation workflows, and external service integrations; document threats, controls, residual risk, and remediation decisions. Provide architecture guidance for secure application design, including authentication and authorization, session management, API security, secrets management, encryption, tenant isolation, input/output validation, logging, resilience, and secure service-to-service communication. Perform targeted hands-on technical validation through secure code review, dependency analysis, configuration review, security testing, proof-of-concept development, and validation of remediation effectiveness. Conduct and guide technical security reviews using SAST, SCA, SBOM, DAST, secrets scanning, API security, container security, cloud security posture, vulnerability management, and AI security evaluation tools. Use and help operationalize platforms such as Snyk, Wiz, GitHub Advanced Security, DAST tooling, threat modeling tools, SBOM/SCA tooling, CI/CD security tooling, native Azure/AWS security services, and SIEM/log analysis tools such as Elastic. Influence and partner with software engineering, architecture, product, and DevSecOps leaders to embed security controls, design reviews, test gates, evidence collection, automated response workflows, and remediation tracking into CI/CD pipelines and product release processes. Design and review identity, access, and secure communication architectures, including IAM, OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, privileged access, encryption, secure APIs, secrets management, and service-to-service communication. Analyze application, cloud, API, container, endpoint, and security telemetry to support threat detection, anomalous behavior investigation, incident triage, containment support, product risk decisions, and prioritized remediation plans. Translate complex architecture risks and technical findings into actionable design guidance, remediation plans, standards updates, metrics, risk inputs, and concise executive and stakeholder-ready summaries. Support customer-facing cybersecurity discussions, questionnaires, and technical documentation related to the organization's commercial product security, application architecture, cloud controls, and SSDLC practices. Stay current on application security architecture, cloud security, DevSecOps, vulnerability management, secure coding, threat intelligence, AI application security, and relevant frameworks and standards including NIST, OWASP, CIS, ISO 27001, SOC 2, and applicable secure software guidance. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)