Enterprise Application Security Architect

Recru

Spring (TX)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Recru is seeking an Enterprise Application Security Architect to lead security strategy and governance across the organization, embedding secure development practices from code to deployment.

You will review designs, drive Secure SDLC, and partner with engineering to ensure robust protections across applications, APIs, and cloud environments. Strong leadership, OWASP, threat modeling, and DevSecOps expertise are essential.

Qualifications

  • 8+ years in Application Security, Security Architecture, Software Engineering, or DevSecOps.
  • Strong background in application security architecture and secure software development.
  • Hands-on experience reviewing code repositories and application security findings.
  • Deep knowledge of OWASP, threat modeling, API security, secure coding, and DevSecOps.

Responsibilities

  • Lead enterprise application security architecture and governance
  • Review and approve application, API, cloud, and integration designs
  • Conduct threat modeling and security architecture reviews
  • Establish and govern Secure SDLC and DevSecOps practices
  • Drive GitHub and source code security standards, including CodeQL, secret scanning, dependency management, and branch protections
  • Review source code vulnerabilities and provide remediation guidance
  • Define standards for SAST, DAST, SCA, API security, container security, and CI/CD security
  • Partner with engineering teams to embed security throughout the development lifecycle
  • Support cloud security initiatives across Azure, AWS, and SaaS platforms
  • Ensure compliance with frameworks such as NIST, ISO 27001, SOC 2, and related security standards

Skills

Threat modeling
DevSecOps
CI/CD pipelines
GitHub Advanced Security
Cloud security
Zero Trust
IAM / Entra ID

Tools

GitHub Enterprise
Azure DevOps

Job description

Enterprise Application Security Architect responsible for leading application security strategy and governance across the organization. This role drives secure software development practices, reviews designs, and embeds security into the development lifecycle from code to deployment.

Key Responsibilities:
  • Lead enterprise application security architecture and governance

  • Review and approve application, API, cloud, and integration designs

  • Conduct threat modeling and security architecture reviews

  • Establish and govern Secure SDLC and DevSecOps practices

  • Drive GitHub and source code security standards, including CodeQL, secret scanning, dependency management, and branch protections

  • Review source code vulnerabilities and provide remediation guidance

  • Define standards for SAST, DAST, SCA, API security, container security, and CI/CD security

  • Partner with engineering teams to embed security throughout the development lifecycle

  • Support cloud security initiatives across Azure, AWS, and SaaS platforms

  • Ensure compliance with frameworks such as NIST, ISO 27001, SOC 2, and related security standards

Qualifications:
  • 8+ years in Application Security, Security Architecture, Software Engineering, or DevSecOps

  • Strong background in application security architecture and secure software development

  • Hands‑on experience reviewing code repositories and application security findings

  • Deep knowledge of OWASP, threat modeling, API security, secure coding, and DevSecOps

  • Experience with GitHub Enterprise, GitHub Advanced Security, Azure DevOps, CI/CD pipelines, and cloud security

  • Strong understanding of Zero Trust, IAM, Entra ID, and modern application security practices

  • Former software engineer, application architect, or DevSecOps leader who moved into security architecture

Preferred Skills:
  • CISSP

  • CSSLP

  • CCSP

  • TOGAF

  • Azure Security

  • AWS Security

  • GWEB

  • GWAPT

  • DevSecOps certifications

You have 8+ years of application security leadership experience. Proficient with GitHub Advanced Security, CI/CD, and cloud platforms. Certified CISSP or CSSLP with OWASP and threat modeling expertise
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Application Security (AppSec) Engineer/Architect
Application Security (AppSec) Engineer/Architect

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Strategic App Security Architect for DevSecOps & Cloud
Strategic App Security Architect for DevSecOps & Cloud

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Manager Application Security
Manager Application Security

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Security Architect
Security Architect

SQA Solution • United States

On-site
USD 140,000 - 200,000
IT Application Security Architect
IT Application Security Architect

Jobtailor • Connecticut

On-site
USD 110,000 - 170,000