Application Security Architect

Alarm.com

Tysons (VA)

On-site

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alarm.com is looking for an Application Security Architect to join our growing security organization—initially as the primary owner of application security, with the opportunity to shape and potentially build the AppSec function over time. You’ll work hands‑on with engineers across the company and lead threat modeling and secure design decisions.

This role spans vulnerability management, secure SDLC integration, code reviews, AI/LLM security, and security tooling across cloud, on‑prem, and IoT

Qualifications

  • 10+ years in application security or related security roles.
  • Bachelor's degree in CS/CE or equivalent work experience.
  • Knowledge of cloud and on‑prem security practices.
  • Hands‑on with AppSec tooling (SAST/DAST/IAST/SCA).
  • Ability to influence engineering teams without formal authority.

Responsibilities

  • Vulnerability Management: triage and track findings from SAST/DAST/IAST/SCA and bug bounties.
  • Secure SDLC Integration: embed security practices across the development lifecycle.
  • Threat Modeling & Design Reviews: lead threat modeling and secure design sessions.
  • Code & Application Reviews: perform deep reviews of high‑risk code paths and APIs.
  • AI & LLM Security: ensure secure AI/LLM design and data protection.
  • Automation & Tooling: build security automation in CI/CD pipelines.
  • Developer Guidance & Training: deliver workshops and secure coding guidance.
  • Cloud Application Security: advise on app security in cloud environments.
  • IoT Device & Platform Security: guide OSS risk analysis for devices and platforms.
  • Security Policy & Compliance: translate policy into practical guidance for developers.
  • Incident Response: support incident handling and post‑incident reviews.

Skills

Security architecture
Threat modeling
AppSec tooling
CI/CD security
Cloud security
IoT security
Security leadership
Communication
Influence without authority

Education

Bachelor's degree in CS/CE or related field

Tools

SAST
DAST
IAST
SCA
WAF
GitHub Advanced Security

Job description

Do you love diving deep into complex systems? Are you passionate about helping engineering teams ship secure, high‑quality software? Do you get energy from solving practical security problems at scale and partnering closely with developers, architects, and product teams?

If so, we’d love to talk to you. Alarm.com is looking for an Application Security Architect to join our growing security organization—initially as the primary owner of application security, with the opportunity to help shape and potentially build the AppSec function over time. You’ll play a hands‑on, influential role in shaping how we build secure software across a diverse ecosystem—including mobile apps, cloud services, on‑prem systems, IoT devices, and emerging AI‑powered features. You’ll collaborate with engineers across the company, participate in design reviews, lead threat modeling, and help teams adopt secure development practices that keep our customers and partners safe.

Alarm.com offers an environment where you can meaningfully impact both technology and culture. You’ll work with smart, friendly engineers, cutting‑edge products, and a platform that spans everything from home automation to large‑scale data processing. If you enjoy a blend of deep technical work, cross‑team partnership, and practical security engineering, this could be the perfect place to grow your career.

What You'll Do
  • Vulnerability Management: Triage and track inbound findings from SAST, DAST, IAST, SCA tools, and external sources (bug bounty, penetration tests). Maintain strong awareness of vulnerability trends and exploitability. Prioritize remediation using a risk‑based approach, partnering directly with engineering teams.
  • Secure SDLC Integration: Partner with engineering and platform leadership to embed security practices throughout the development lifecycle. Influence and evolve the AppSec tooling and automation roadmap—including emerging AI‑assisted capabilities—through prototyping, evaluation, and feedback.
  • Threat Modeling & Design Reviews: Lead threat modeling and participate in feature‑team design reviews to ensure security best practices are applied across new features and architectural changes. Collaborate early with engineers, architects, and tech leads during design sessions to identify risks, guide secure design decisions, and embed security into system architecture.
  • Code & Application Reviews: Perform deep, targeted reviews of high‑risk code paths, APIs, authentication/authorization flows, and sensitive components. Coordinate with Penetration Testers, Red Teams, and Compliance teams to ensure holistic coverage.
  • AI & LLM Security: Partner with teams adopting AI and LLM‑based systems—both internal tooling and production features—to ensure secure design, model and data protection, prompt/input validation, and safe integration patterns. Assess and mitigate risks related to data leakage, model behavior, supply chain concerns, and emerging AI security threats.
  • Automation & Tooling: Build and maintain security automation integrated into CI/CD pipelines. Automate detection, validation, and developer‑friendly remediation workflows to improve signal quality and reduce friction.
  • Developer Guidance & Training: Serve as a domain expert and partner to engineering teams. Deliver workshops, provide secure coding guidance, and help teams adopt effective security controls and testing practices.
  • Cloud Application Security: Advise on application‑layer security in cloud‑native environments, including identity, secrets management, network exposure, and service‑to‑service authentication.
  • IoT Device & Platform Security: Provide security guidance for IoT devices and platform components, including OSS dependency risk analysis and security considerations for legacy or constrained devices.
  • Security Policy & Compliance: Translate policy and compliance requirements into practical guidance for developers. Contribute to policy evolution and support audit activities as needed.
  • Incident Response: Collaborate with InfoSec during security incidents and investigations. Maintain and evolve runbooks and contribute to post‑incident reviews to drive systemic improvements.
Required Skills & Experience
  • 10+ years of experience in application security, software engineering, or related technical security roles (8+ acceptable for exceptionally strong candidates).
  • Bachelor's in Computer Science, Computer Engineering, Electrical Engineering, or related field, or equivalent work experience.
  • Knowledge of application security best practices across both cloud and on‑prem environments, including cloud‑hosted Kubernetes and related cloud services.
  • Hands‑on experience with AppSec tooling and techniques (SAST, DAST, SCA, IAST, WAF, etc.).
  • Strong understanding of vulnerabilities, exploitability, and security principles (e.g., OWASP Top 10, secure design patterns).
  • Experience with CI/CD pipelines and DevSecOps practices.
  • Demonstrated ability to influence engineering teams and drive security outcomes without relying on authority.
  • Strong analytical thinking, practical problem‑solving skills, and a balanced approach to technical risk.
  • Excellent written and verbal communication skills, capable of explaining complex security issues to both technical and non‑technical audiences.
  • Experience with GitHub Advanced Security (including code scanning, secret scanning, and dependency insights) is preferred.
  • Familiarity with AI and LLM security concepts—such as model hardening, prompt/input validation, data protection, and the OWASP Top 10 for LLMs—is preferred.

Please note that sponsorship of new applicants for employment authorization, or any other immigration‑related support, is not available for this position at this time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Engineer
Application Security Engineer

Awardco, Inc. • Lindon (UT)

On-site
USD 110,000 - 140,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

ALLTECH CONSULTING SVC INC • Georgia

On-site
USD 100,000 - 130,000
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
Application Security Engineer
Application Security Engineer

Awardco • Lindon (UT)

On-site
USD 140,000 - 170,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000