Key Requirement: Must be highly technical and comfortable reviewing source code, security findings, and GitHub repositories. This is not a policy-only security role.
We're seeking an Enterprise Application Security Architect to lead application security strategy, architecture governance, and secure software development practices across the enterprise. This individual will partner closely with architecture, engineering, DevOps, and security teams to ensure applications are secure by design from development through deployment.
What You'll Do
- Lead enterprise application security architecture and governance
- Review and approve application, API, cloud, and integration designs
- Conduct threat modeling and security architecture reviews
- Establish and govern Secure SDLC (SSDLC) and DevSecOps practices
- Drive GitHub and source code security standards, including CodeQL, secret scanning, dependency management, and branch protections
- Review source code vulnerabilities and provide remediation guidance
- Define standards for SAST, DAST, SCA, API security, container security, and CI/CD security
- Partner with engineering teams to embed security throughout the development lifecycle
- Support cloud security initiatives across Azure, AWS, and SaaS platforms
- Ensure compliance with frameworks such as NIST, ISO 27001, SOC 2, and related security standards
Required Experience
- 8+ years in Application Security, Security Architecture, Software Engineering, or DevSecOps
- Strong background in application security architecture and secure software development
- Hands-on experience reviewing code repositories and application security findings
- Deep knowledge of OWASP, threat modeling, API security, secure coding, and DevSecOps
- Experience with GitHub Enterprise, GitHub Advanced Security, Azure DevOps, CI/CD pipelines, and cloud security
- Strong understanding of Zero Trust, IAM, Entra ID, and modern application security practices
Preferred Certifications
CISSP, CSSLP, CCSP, TOGAF, Azure Security, AWS Security, GWEB, GWAPT, or DevSecOps certifications.
Ideal Background: Former software engineer, application architect, or DevSecOps leader who moved into security architecture and still enjoys digging into code.