Lead Application Security Architect

Arrive

City Of London

On-site

GBP 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Arrive seeks an Application Security Architect to orchestrate and elevate its global SSDLC, ensuring secure design, build and deployment of software across the company.

You will unify standards, partner with Platform Security, and lead threat modeling, security tooling, and secure-by-design initiatives, including AI/ML security collaboration.

The role demands strong leadership, hands-on AppSec expertise, and a passion for transforming urban mobility through secure software.

Qualifications

  • Extensive hands-on AppSec experience and SSDLC mastery.
  • Experience designing and rolling out security standards and patterns in a complex engineering environment.
  • Proven ability to influence engineering teams without direct authority.

Responsibilities

  • Lead global SSDLC definition from threat modeling to secure release in collaboration with Engineering and IT.
  • Develop and maintain global security standards, baselines, and guidelines for secure coding, vulnerability management, and secure architecture.
  • Drive secure tooling strategy (SAST, DAST, IAST, SCA) and define standards for M&A integrations.
  • Lead security architecture reviews and threat modeling sessions for new applications and high-risk features.
  • Mentor security engineers and champion security best practices across the organization.

Skills

SSDLC mastery
Secure coding
OWASP Top 10
Security standards
CI/CD security
Cloud-native security
Threat modeling
Mentoring

Education

Bachelor's degree in a relevant field

Tools

Snyk
Checkmarx
Veracode

Job description

We've signed up to an ambitious journey. Join us! As Arrive, we guide customers and communities towards brighter futures and more livable cities, it isn't a challenge just anyone could take on. Luckily, we have something to help us make it happen. Our people and our values. We Arrive Curious, Focused and Together. Just as our entire brand is inspired by the North Star, the shining light leading travelers to their destinations since time began, our values guide us. They help us be at our best. For our customers. For the cities and communities we serve. For ourselves. As a global team, we are transforming urban mobility. Let's grow better, together.

Role Summary

The Application Security Architect is a senior, influential role responsible for orchestrating and leading Arrive's global application security strategy. As a core member of the Global Security Architecture & Engineering team, you will act as the central driver for how we securely design, build, and deploy software across the company.

Your primary focus is to unite our efforts by creating, standardizing, and scaling our Secure Software Development Lifecycle (SSDLC) globally. This involves building upon the expertise and best practices that already exist within our teams and forging a powerful partnership with the Platform Security team in Engineering. You will lead by unifying-setting global standards that empower our developers and security engineers and ensuring the security of our next generation of products and platforms.

Your Mission

To elevate and unify our application security program at Arrive. Your mission is to be a force-multiplier for our engineering teams, fostering a secure development culture that is built on a foundation of clear global standards, strong partnerships, and modern security practices. You will ensure that security is a shared goal and a collective achievement.

Application Security Strategy & Standards
  • Champion and orchestrate the definition of Arrive's global Secure Software Development Lifecycle (SSDLC), from threat modeling to secure release, in close partnership with key stakeholders across Engineering and IT.
  • Develop and maintain a comprehensive set of global security standards, baselines, and guidelines for secure coding, vulnerability management, and secure architecture.
  • Create and champion the strategy for our application security tooling, including SAST, DAST, IAST, and Software Composition Analysis (SCA).
  • Define and manage the application security standards for Mergers & Acquisitions, establishing clear requirements and guiding the architectural integration of acquired technologies.
Technical Partnership & Enablement
  • Act as a lead security consultant and strategic partner for product and engineering teams, providing expert guidance on secure design patterns and vulnerability remediation.
  • Forge a dynamic partnership with the Platform Security team: co-design the security tooling roadmap, consume their platforms where they meet global standards, and introduce new architectural patterns where needed.
  • Lead security architecture reviews and threat modeling sessions for new applications and high-risk features.
  • Act as a senior mentor and advocate for security engineers and champions across the organization, helping to grow our security talent.
Emerging Threats & Innovation
  • Stay at the forefront of emerging application security threats, with a particular focus on the risks associated with AI/ML systems.
  • Collaborate with Data & AI teams to develop security principles and architectural patterns for securely integrating AI into our products.
  • Drive innovation in our security practices, continuously seeking opportunities to automate and improve the effectiveness of our AppSec program.
  • Lead the strategy for leveraging AI within the AppSec program, both to mature the SSDLC and to establish the secure-by-design principles required for our AI-first engineering landscape.
What You Bring
  • Deep AppSec Expertise: Extensive, hands‑on experience in application security, with mastery of the SSDLC, secure coding principles, and common vulnerability classes (OWASP Top 10, etc.).
  • A Builder of Standards: Proven experience creating, documenting, and rolling out security standards, patterns, and best practices in a complex engineering environment.
  • A Unifier and Partner: Exceptional ability to foster collaboration and influence engineering teams without direct authority. You build bridges, operate "together," and break down silos.
  • Strategic Thinker: Ability to see the big picture, define a long‑term strategy for application security, and translate it into an actionable plan.
  • Modern Technologist: Strong understanding of modern software development practices, including cloud‑native architectures, CI/CD pipelines, containerization, and Infrastructure as Code.
Qualifications
  • 10+ years of experience in technology, with at least 7 years in a dedicated application security or product security role.
  • Demonstrated experience designing and implementing a Secure SDLC in a cloud‑native environment (GCP, AWS).
  • Hands‑on experience with the architecture and strategy of AppSec tools (e.g., Snyk, Checkmarx, Veracode,).
  • Experience with securing microservices architectures, APIs, and modern web/mobile applications.
  • Experience with securing AI/ML systems
  • A Bachelor's degree in a relevant field or equivalent professional experience.
Why Join Arrive
  • Be the global leader and define the future of application security at a mission‑driven, transformative company.
  • Operate as a senior expert within a strategic architecture team, with a broad mandate to influence security across all of Arrive's products.
  • Work at the cutting edge of securing technology, including multi‑cloud and AI‑driven mobility solutions.
About Arrive

Arrive, including brands like EasyPark, Flowbird, RingGo, ParkMobile and Parkopedia, is a leading global mobility platform. Present in over 90 countries and 20,000 cities, the company helps people and decision‑makers make smarter decisions about urban mobility and ease the experience of travel worldwide. Arrive delivers a unique combination of the core ingredients to make cities more livable: from smart payments and optimized car parks to data‑driven traffic reduction and support for reinvestment in public transport and green space. It's about more than function, it's about saving time and simplifying the experience of travel for everyone. Travel is more than a journey, it's how you Arrive.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Group Business Solutions
Head of Group Business Solutions

Arrive • Greater London

On-site
GBP 140,000 - 180,000
Global impact
International teams
Ownership of architecture
+1
Senior Python Engineer (Data)
Senior Python Engineer (Data)

Arrive • Greater London

Hybrid
GBP 90,000 - 130,000
Head of Workplace and Facilities
Head of Workplace and Facilities

Arrive • Greater London

Hybrid
GBP 110,000 - 160,000
Staff Python Engineer (Data)
Staff Python Engineer (Data)

Arrive • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible working
Hybrid work option
25 Days holiday entitlement
+7
Business Intelligence Analyst (Hybrid, London, UK)
Business Intelligence Analyst (Hybrid, London, UK)

Parking Network BV • Greater London

Hybrid
GBP 45,000 - 65,000
Payments Product Manager - Card Issuing
Payments Product Manager - Card Issuing

Arrive • Greater London

On-site
GBP 90,000 - 150,000
Vertical Lead (London, UK)
Vertical Lead (London, UK)

Parking Network BV • Greater London

Hybrid
GBP 85,000 - 110,000
Senior Backend Engineer - Revenue (Hybrid, London, UK)
Senior Backend Engineer - Revenue (Hybrid, London, UK)

Parking Network BV • Greater London

Hybrid
GBP 75,000 - 110,000
Senior Analytics Engineer (Hybrid, London, UK)
Senior Analytics Engineer (Hybrid, London, UK)

Parking Network BV • Greater London

Hybrid
GBP 90,000 - 120,000
Partner Success Representative (Basingstoke, UK)
Partner Success Representative (Basingstoke, UK)

Parking Network BV • Basingstoke

Hybrid
GBP 22,000 - 32,000