Lead Application Security Architect

JLL

Barcelona

Presencial

EUR 110.000 - 140.000

Jornada completa

14 días+
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Descripción de la vacante

JLL is seeking a Senior Application Security Architect to bridge security engineering and enterprise architecture. You will own security architectures for application ecosystems, drive SDLC security, and serve as a technical authority on secure patterns, threat modeling, and DevSecOps practices.

In this senior role, you will mentor engineers and collaborate across engineering, architecture, and business teams to reduce risk.

Formación

  • Bachelor's degree or equivalent in a relevant field and 7+ years in information security with focus on application security or security architecture.
  • Expert understanding of secure design patterns and security architecture for cloud-native platforms.
  • Proven ability to lead security assessments, architecture reviews, and cross-functional initiatives.

Responsabilidades

  • Design and maintain security architecture standards for enterprise applications and cloud-native environments.
  • Lead threat modeling sessions and provide actionable remediation guidance to development teams.
  • Champion secure coding practices and DevSecOps integration across engineering teams.
  • Communicate security designs and risk assessments to technical and non-technical stakeholders.

Conocimientos

OWASP Top 10
DevSecOps
Cloud-native security
Threat modeling
Zero-trust
SAST
Architectural design

Educación

Bachelor's degree in CS / InfoSec / SWE

Herramientas

AWS
Azure
GCP
Kubernetes
CI/CD tools

Descripción del empleo

Senior Application Security Architect

At JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. The Application Security Architect is a senior individual contributor responsible for bridging application security engineering and enterprise security architecture at JLL. This role designs and owns security architectures for application ecosystems, integrates security into the software development lifecycle (SDLC), and serves as a technical authority on secure design patterns, threat modeling, and DevSecOps practices. Operating at the Senior level, this position independently leads application security initiatives, mentors junior engineers and developers, and partners across engineering, architecture, and business teams to reduce risk and enable secure digital transformation. If you’re a strategic thinker with application security expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you.

Essential Duties and Responsibilities:
Security Architecture & Design
  • Design and maintain security architecture standards, policies, and patterns for enterprise applications, platforms, and cloud-native environments, ensuring alignment with JLL's technology strategy and risk posture.
  • Develop and enforce secure design patterns, reference architectures, and architecture decision records (ADRs) for application security across development teams.
  • Lead security architecture reviews for new and existing applications, evaluating designs against frameworks such as OWASP, NIST, and SANS.
  • Integrate zero-trust principles and defense-in-depth strategies into application architecture to reduce attack surface and support enterprise risk management goals.
DevSecOps & Secure Development Lifecycle
  • Define and maintain a standardized set of enterprise application security requirements and produce metrics to report performance against those requirements.
  • Lead threat modeling sessions for new application features and system integrations, producing actionable remediation guidance for development teams.
  • Champion secure coding standards and developer security enablement programs in collaboration with platform and application engineering teams.
Risk, Compliance & Stakeholder Engagement
  • Analyze complex security requirements across multiple technology domains and design comprehensive security solutions that address enterprise risk and regulatory compliance obligations.
  • Communicate security architecture designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders across business units.
  • Coordinate security design reviews and approval processes, facilitating alignment between security, engineering, and enterprise architecture teams.
  • Contribute to JLL's application security strategy roadmap, identifying emerging threats and recommending enhancements to the secure development and architecture programs.
Mentorship & Team Leadership
  • Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards.
  • Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams.
  • Support secure development training and awareness programs to build security competency across engineering organizations.
Required Knowledge, Skills, and Abilities:
Technical Knowledge
  • Comprehensive knowledge of application security methodologies, including OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns.
  • Demonstrated experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads.
  • Strong proficiency in DevSecOps practices and tooling: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration.
  • Experience with enterprise security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles.
  • Working knowledge of identity and access management (IAM), OAuth 2.0/OIDC, and application-layer authentication and authorization controls.
  • Understanding of cryptography, data protection, encryption, and Public Key Infrastructure
  • Familiarity with threat modeling methodologies (STRIDE, PASTA, or equivalent) and their application to complex distributed application architectures.
  • Knowledge of OWASP: GenAi, LLM Top 10, Security Exchange, Ai Exchange a plus
Skills & Abilities
  • Ability to analyze complex application architectures and translate security requirements into practical, implementable design solutions.
  • Strong communication skills with the ability to convey technical security risks and architectural recommendations to diverse stakeholders including development teams, business leaders, and enterprise architects.
  • Demonstrated ability to lead security assessments, architecture reviews, and cross-functional security initiatives independently.
  • Proven capability to mentor and guide junior security professionals and developers on secure design practices and security engineering standards.
  • Analytical and problem-solving skills applied to sophisticated security integration challenges with enterprise-wide implications.
  • Ability to balance security rigor with development velocity, enabling secure delivery of digital applications and services.
Education & Experience
  • Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field; equivalent experience considered.
  • 7+ years of experience in information security with a focus on application security engineering, secure software development, or security architecture.
  • Relevant certifications preferred: CSSLP, CISSP, AWS/Azure Security Specialty, OSCP, or equivalent application security or architecture credentials.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Lead Application Security Architect at JLL
Lead Application Security Architect at JLL

JLL • Barcelona

Presencial
EUR 110.000 - 150.000
Personalized benefits
Lead Application Security Architect
Lead Application Security Architect

Jones Lang LaSalle Incorporated • Barcelona

Presencial
EUR 90.000 - 130.000
Senior Application Security Architect DevSecOps Cloud
Senior Application Security Architect DevSecOps Cloud

JLL • Barcelona

Presencial
EUR 110.000 - 140.000
Senior Application Security Architect: Lead Secure SDLC & Cloud
Senior Application Security Architect: Lead Secure SDLC & Cloud

JLL • Barcelona

Presencial
EUR 110.000 - 150.000
Personalized benefits
Senior App Security Architect – Cloud & DevSecOps Leader
Senior App Security Architect – Cloud & DevSecOps Leader

Jones Lang LaSalle Incorporated • Barcelona

Presencial
EUR 90.000 - 130.000
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Associate Security Architect
Associate Security Architect

Swiss Re - Schweizerische Rückversicherungs-Gesellschaft • Madrid

Híbrido
EUR 41.000 - 68.000
Information Security Engineer
Information Security Engineer

Comoro Ltd • Barcelona

Presencial
EUR 70.000 - 90.000
Security Program Director
Security Program Director

Business Insights • Bellprat

Presencial
EUR 140.000 - 180.000
Associate Security Architect
Associate Security Architect

Swiss Re • Madrid

Híbrido
EUR 42.000 - 70.000
Hybrid work arrangement
Performance-based bonus