> Markdown version of [/jobs/ext/608397-savp-cyber-application-security-architecture](https://www.wearedevelopers.com/jobs/ext/608397-savp-cyber-application-security-architecture). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAVP, Cyber Application Security Architecture - **Company:** EXL SERVICE - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - $195,100.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Corona (Software Development Kit), Key Management, Machine Learning, Systems Development Life Cycle, Role-Based Access Control, Secure Coding, Security Information and Event Management, Software Engineering, Data Streaming, Software Vulnerability Management, Data Logging, Google Cloud, Spring Cloud, Istio, Software Security, HybridCloud, Information Technology, Production Code, Api Design, Api Gateway, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9b4e6cdc1833ddae ## About the Role Do you have experience in Web Application Security Testing?, * Qualifications: 8+ years related IT experience; 5+ years' experience in security application tools * 6+ years' experience in application security reviews of new architecture; 5 + years of experience with public and hybrid cloud (AWS, Azure and GCP) environments. * Strong software development background with the ability to read, understand, and advise on production code and design decisions. * Demonstrated expertise in threat modeling and secure architecture review for modern web and API-based applications. * Expertise securing CI/CD and SDLC processes (pipeline security, secrets management, artifact integrity, build/release controls, and automation). * Experience with application security tooling and processes, including managing findings and resolving false positives (SAST/SCA/DAST and related scanning in pipelines). * Working knowledge of AI/ML security risks and mitigations for applications that use ML models or GenAI components. * Strong collaborative and consulting skills ability to influence without authority, communicate clearly, and deliver pragmatic, developer-friendly recommendations. ## Description Job Description: The Sr. AVP - Cyber focused on Application Security Architect with software development, platform, cybersecurity, and cloud engineering teams to embed security throughout the modern software development lifecycle (SDLC). This role focuses on secure-by-design practices, DevSecOps strategy, roadmap and enablement, and risk-based vulnerability management across internally developed, third-party, SaaS, and cloud-native applications. The AppSec Architect serves as the strategic owner of the Application Security Roadmap, defines target-state AppSec maturity aligned to business growth, and prioritizes AppSec investments and tooling rationalization. The role serves as a trusted advisor to development teams and the key contributor to the organization's overall Secure Software Development Program. You will also perform Secure by Design reviews for new applications and material changes to existing applications to ensure solutions are secure, scalable, and compliant with company standards. Responsibilities: Principle Duties Developer enablement & secure coding support * Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure. * Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. * Provide timely consulting on "how to do it right" (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. * Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. * Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. * Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection. Secure by Design reviews * Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. * Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. * Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. * Provide clear, actionable recommendations and track follow-through with engineering teams. * Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives-shifting from audit-driven to architecture-driven alignment. CI/CD and SDLC security * Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. * Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. * Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. AI/ML security guidance * Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. * Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. Collaboration & communication * Act as a trusted partner to product, engineering, and leadership-translating security requirements into developer-friendly guidance. * Create and maintain secure coding guidance, reference architectures, and reusable patterns. * Support incident learnings by contributing to root cause analysis and preventative design improvements. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)