Application Security Senior Engineer

ISTARI

United States

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A strategic cybersecurity advisory company is looking for an experienced Application Security Architect to ensure secure design principles are embedded in the client's application development process. This 12-month contractor role focuses on enhancing application resilience against threats while collaborating with development and security teams. Candidates should have around 10 years of experience in application security and relevant skills in secure SDLC governance and API security architecture. The position is ideal for those located on the US East Coast or Central region.

Qualifications

  • Approximately 10 years’ experience in Application Security.
  • Strong experience overseeing secure SDLC governance and design assurance.
  • Proven capability in application and API security architecture.
  • Experience with SAST, DAST, and CI/CD security tooling.
  • Strong risk-based reporting and executive communication.

Responsibilities

  • Provide application security architecture advisory for new application development.
  • Lead the governance of the Secure Software Development Framework.
  • Define, maintain, and govern application security blueprints and design patterns.
  • Enforce API security standards including auth, encryption, rate limiting.
  • Oversee threat modelling, reviews, and risk assessments.
  • Drive secure coding practices and developer training.
  • Manage vulnerability findings and remediation workflows in pipelines.
  • Partner with third-party AppSec providers for day-to-day work.
  • Collaborate with cloud and platform teams to ensure Zero Trust deployments.
  • Provide executive reporting on security posture and trends.

Skills

Application Security
Secure SDLC governance
API security architecture
Cloud-native security
Vulnerability management
Secure coding practices
CI/CD security tooling
Vulnerability findings management
Executive reporting
Third-party AppSec coordination

Tools

SAST
DAST
CI/CD security tooling
API gateways
Identity services

Job description

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from ISTARI

ISTARI is a strategic cybersecurity advisory company with a bold vision: to curate the defining cybersecurity ecosystem of our time - uniting enterprise, academia, government, and innovators to build collective resilience.

At the heart of this mission, ISTARI helps clients achieve lasting organisational cyber resilience by convening and applying world-class talent, expertise, and innovation through a uniquely powerful network, with ISTARI as the central orchestrator.

The Opportunity

The Application Security Architect provides strategic architecture and engineering support to embed security into the client’s application development ecosystem. This role ensures that secure design principles, controls, and governance are consistently integrated across the SDLC, enabling applications to be resilient against modern threats while supporting business agility.

This is a 12-month contractor role, operating within the Architecture & Engineering function and partnering closely with development teams, platform engineering, and security operations.

What You’ll Do
  • Provide application security architecture advisory for new application development, modernisation initiatives, and system integrations, ensuring security-by-design principles are embedded across the SDLC.
  • Lead the execution and governance of the Secure Software Development Framework in collaboration with the client’s development partners and platform teams.
  • Define, maintain, and govern application security blueprints, reference architectures, and design patterns for APIs, microservices, and cloud-native workloads.
  • Establish and enforce API security standards, including authentication, authorisation, encryption, traffic inspection, and rate limiting.
  • Oversee threat modelling, secure design reviews, and risk assessments for business-critical applications and third-party integrations.
  • Drive secure coding practices by enabling developer awareness, training, and adoption of secure frameworks and standards.
  • Oversee the SAST, DAST, and CI/CD security tooling strategy, ensuring effective integration into development pipelines and efficient management of findings and remediation workflows.
  • Act as the strategic interface for Application Security-as-a-Service, partnering with third-party engineering teams providing day-to-day AppSec execution and tooling operations.
  • Collaborate with cloud, network, and platform engineering teams to ensure applications are securely deployed within segmented, Zero Trust-aligned environments.
  • Serve as the application security authority during security incidents, providing architectural guidance for containment, remediation, and post-incident improvements.
  • Provide executive-level reporting on application security posture, including vulnerability trends, remediation progress, and residual risk.
What You’ll Bring
  • ~10 years’ experience in Application Security.
  • Strong experience in secure SDLC governance and design assurance.
  • Proven capability in application and API security architecture.
  • Hands-on experience with cloud-native and microservices security.
  • Experience overseeing security tooling and vulnerability findings management.
  • Ability to coordinate and govern third-party AppSec service providers.
  • Strong risk-based reporting and executive communication skills.
  • Deep knowledge of SAST, DAST, and CI/CD security tooling.
  • Experience with API gateways and identity services.
  • Duration: January 2026 – December 2026
  • Location Preference: US East Coast or Central
  • Work Authorisation: Not provided
Seniority level

Mid-Senior level

Employment type

Contract

Job function

Consulting

Industries

IT Services and IT Consulting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Architect, Information Security - DevSecOps/Application Security
Architect, Information Security - DevSecOps/Application Security

Jobgether • United States

On-site
USD 72,000 - 157,000
Competitive compensation
US-based role
Enterprise security exposure
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Application Security Architect & Developer
Application Security Architect & Developer

USA Tech Recruit • San Francisco (CA)

On-site
USD 230,000 - 261,000
Application Security Engineer
Application Security Engineer

Unisys • Rockville (MD)

On-site
USD 100,000 - 130,000
Security Solution Architect
Security Solution Architect

Jobgether • United States

Hybrid
USD 190,000 - 250,000
Competitive base salary
Discretionary bonuses
Equity package through RSU
+2
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

FTS, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000