Lead Application Security Architect

Jones Lang LaSalle Incorporated

Barcelona

Presencial

EUR 90.000 - 130.000

Jornada completa

Hace 4 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Jones Lang LaSalle Incorporated is seeking a Senior Application Security Architect to design security architectures for enterprise applications and cloud-native environments. You will drive secure design patterns, threat modeling, and DevSecOps integration across development teams.

You will mentor junior engineers, collaborate with architecture and engineering peers, and contribute to the security strategy roadmap to reduce risk and enable secure digital transformation.

Formación

  • Comprehensive knowledge of application security methodologies and patterns.
  • Experience designing security architectures for cloud-native environments (AWS/Azure/GCP).
  • Proficient in DevSecOps practices and tooling (SAST/DAST/SCA).
  • Familiar with NIST, ISO 27001, and zero-trust principles.

Responsabilidades

  • Design and maintain security architectures for enterprise apps and cloud-native platforms.
  • Lead threat modeling sessions and provide remediation guidance.
  • Mentor junior engineers and coordinate with engineering and enterprise teams.

Conocimientos

OWASP Top10
SAST
DAST
SCA
CI/CD security
Zero-trust
Threat modeling
Cloud-native
IAM
OAuth 2.0
PKI
STRIDE

Educación

Bachelor's degree in CS/InfoSec
CSSLP/CISSP

Herramientas

Docker
Kubernetes
CI/CD tooling

Descripción del empleo

JLL supports the Whole You, personally and professionally.Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology to our clients. We are committed to hiring the best, most talented people in our industry; and we support them through professional growth, flexibility, and personalized benefits to manage life in and outside of work. Whether you’ve got deep experience in commercial real estate, skilled trades, and technology, or you’re looking to apply your relevant experience to a new industry, we empower you to shape a brighter way forward so you can thrive professionally and personally.Senior Application Security ArchitectOverviewAt JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. The Application Security Architect is a senior individual contributor responsible for bridging application security engineering and enterprise security architecture at JLL.This role designs and owns security architectures for application ecosystems, integrates security into the software development lifecycle (SDLC), and serves as a technical authority on secure design patterns, threat modeling, and DevSecOps practices. Operating at the Senior level, this position independently leads application security initiatives, mentors junior engineers and developers, and partners across engineering, architecture, and business teams to reduce risk and enable secure digital transformation.If you’re a strategic thinker with application security expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you.Essential Duties and Responsibilities:Security Architecture & DesignDesign and maintain security architecture standards, policies, and patterns for enterprise applications, platforms, and cloud-native environments, ensuring alignment with JLL's technology strategy and risk posture.Develop and enforce secure design patterns, reference architectures, and architecture decision records (ADRs) for application security across development teams.Lead security architecture reviews for new and existing applications, evaluating designs against frameworks such as OWASP, NIST, and SANS.Integrate zero-trust principles and defense-in-depth strategies into application architecture to reduce attack surface and support enterprise risk management goals.DevSecOps & Secure Development LifecycleDefine and maintain a standardized set of enterprise application security requirements and produce metrics to report performance against those requirements.Lead threat modeling sessions for new application features and system integrations, producing actionable remediation guidance for development teams.Champion secure coding standards and developer security enablement programs in collaboration with platform and application engineering teams.Risk, Compliance & Stakeholder EngagementAnalyze complex security requirements across multiple technology domains and design comprehensive security solutions that address enterprise risk and regulatory compliance obligations.Communicate security architecture designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders across business units.Coordinate security design reviews and approval processes, facilitating alignment between security, engineering, and enterprise architecture teams.Contribute to JLL's application security strategy roadmap, identifying emerging threats and recommending enhancements to the secure development and architecture programs.Mentorship & Team LeadershipProvide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards.Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams.Support secure development training and awareness programs to build security competency across engineering organizations.Required Knowledge, Skills, and Abilities:Technical KnowledgeComprehensive knowledge of application security methodologies, including OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns.Demonstrated experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads.Strong proficiency in DevSecOps practices and tooling: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration.Experience with enterprise security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles.Working knowledge of identity and access management (IAM), OAuth 2.0/OIDC, and application-layer authentication and authorization controls.Understanding of cryptography, data protection, encryption, and Public Key InfrastructureFamiliarity with threat modeling methodologies (STRIDE, PASTA, or equivalent) and their application to complex distributed application architectures.Knowledge of OWASP: GenAi, LLM Top 10, Security Exchange, Ai Exchange a plusSkills & AbilitiesAbility to analyze complex application architectures and translate security requirements into practical, implementable design solutions.Strong communication skills with the ability to convey technical security risks and architectural recommendations to diverse stakeholders including development teams, business leaders, and enterprise architects.Demonstrated ability to lead security assessments, architecture reviews, and cross-functional security initiatives independently.Proven capability to mentor and guide junior security professionals and developers on secure design practices and security engineering standards.Analytical and problem-solving skills applied to sophisticated security integration challenges with enterprise-wide implications.Ability to balance security rigor with development velocity, enabling secure delivery of digital applications and services.Education & ExperienceBachelor's degree in Computer Science, Information Security, Software Engineering, or a related field; equivalent experience considered.7+ years of experience in information security with a focus on application security engineering, secure software development, or security architecture.Relevant certifications preferred: CSSLP, CISSP, AWS/Azure Security Specialty, OSCP, or equivalent application security or architecture credentials.If this job description resonates with you, we encourage you to apply even if you don’t meet all of the requirements below. We’re interested in getting to know you and what you bring to the table!Personalized benefits that support personal well-being and growth:JLL recognizes the impact that the workplace can have on your wellness, so we offer a supportive culture and comprehensive benefits package that prioritizes mental, physical and emotional health.About JLL –We’re JLL—a leading professional services and investment management firm specializing in real estate. We have operations in over 80 countries and a workforce of over 102,000 individuals around the world who help real estate owners, occupiers and investors achieve their business ambitions. As a global Fortune 500 company, we also have an inherent responsibility to drive sustainability and corporate social responsibility. That’s why we’re committed to our purpose to shape the future of real estate for a better world. We’re using the most advanced technology to create rewarding opportunities, amazing spaces and sustainable real estate solutions for our clients, our people, and our communities.Our core values of teamwork, ethics and excellence are also fundamental to everything we do and we’re honored to be recognized with awards for our success by organizations both globally and locally.Creating a diverse and inclusive culture where we all feel welcomed, valued and empowered to achieve our full potential is important to who we are today and where we’re headed in the future. And we know that unique backgrounds, experiences and perspectives help us think bigger, spark innovation and succeed together.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Coordinador de Mantenimiento
Coordinador de Mantenimiento

Jones Lang LaSalle Incorporated • Barcelona

Presencial
EUR 42.000 - 64.000
Total rewards program
Sustainability initiatives
Recepcionist
Recepcionist

Jones Lang LaSalle Incorporated • Barcelona

Presencial
EUR 23.000 - 29.000
Técnico/a de Operaciones
Técnico/a de Operaciones

Jones Lang LaSalle Incorporated • Benidorm

Presencial
EUR 20.000 - 28.000
Senior Data Quality and Governance Analyst (EMEA based)
Senior Data Quality and Governance Analyst (EMEA based)

Jones Lang LaSalle Incorporated • Madrid

Presencial
EUR 60.000 - 80.000
Personalized benefits
Professional growth opportunities
Jefe/a equipo de Construcción
Jefe/a equipo de Construcción

Jones Lang LaSalle Incorporated • Benidorm

Presencial
EUR 45.000 - 65.000
Salario competitivo
Beneficios sociales
Senior App Security Architect – Cloud & DevSecOps Leader
Senior App Security Architect – Cloud & DevSecOps Leader

Jones Lang LaSalle Incorporated • Barcelona

Presencial
EUR 90.000 - 130.000
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Madrid

A distancia
EUR 70.000 - 90.000
Growth without limits
Competitive compensation
Flexibility: remote work
+3
Senior Security Engineer – Identity & Access
Senior Security Engineer – Identity & Access

Dlocal • Madrid

Presencial
EUR 90.000 - 130.000
Flexible schedules
Fintech industry environment
Referral bonus program
+2
Consultant Corporate, Capital Markets
Consultant Corporate, Capital Markets

JLL • Madrid

Presencial
EUR 70.000 - 100.000
Associate Security Architect
Associate Security Architect

Crossell • Madrid

Híbrido
EUR 42.000 - 70.000
Performance-based bonus