Get more replies from employers
Send a job-specific resume in minutes.
Recru is seeking an Enterprise Application Security Architect to lead security strategy and governance across the organization, embedding secure development practices from code to deployment.
You will review designs, drive Secure SDLC, and partner with engineering to ensure robust protections across applications, APIs, and cloud environments. Strong leadership, OWASP, threat modeling, and DevSecOps expertise are essential.
Enterprise Application Security Architect responsible for leading application security strategy and governance across the organization. This role drives secure software development practices, reviews designs, and embeds security into the development lifecycle from code to deployment.
Lead enterprise application security architecture and governance
Review and approve application, API, cloud, and integration designs
Conduct threat modeling and security architecture reviews
Establish and govern Secure SDLC and DevSecOps practices
Drive GitHub and source code security standards, including CodeQL, secret scanning, dependency management, and branch protections
Review source code vulnerabilities and provide remediation guidance
Define standards for SAST, DAST, SCA, API security, container security, and CI/CD security
Partner with engineering teams to embed security throughout the development lifecycle
Support cloud security initiatives across Azure, AWS, and SaaS platforms
Ensure compliance with frameworks such as NIST, ISO 27001, SOC 2, and related security standards
8+ years in Application Security, Security Architecture, Software Engineering, or DevSecOps
Strong background in application security architecture and secure software development
Hands‑on experience reviewing code repositories and application security findings
Deep knowledge of OWASP, threat modeling, API security, secure coding, and DevSecOps
Experience with GitHub Enterprise, GitHub Advanced Security, Azure DevOps, CI/CD pipelines, and cloud security
Strong understanding of Zero Trust, IAM, Entra ID, and modern application security practices
Former software engineer, application architect, or DevSecOps leader who moved into security architecture
CISSP
CSSLP
CCSP
TOGAF
Azure Security
AWS Security
GWEB
GWAPT
DevSecOps certifications