A complete application in a minute — tailored resume and cover letter, ready to send.
State Street Corporation in Austin, TX is seeking a Senior Application Security Architect to design, review, and govern security architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems.
You will partner with software engineering, cloud and cybersecurity teams to embed secure-by-design principles across the software and AI development lifecycles, and lead threat modeling, security reviews, and DevSecOps practices.
We are looking for a Senior Application Security Architect. You will be responsible for designing, reviewing, and governing security architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems. You will partner with software engineering, data science, cloud engineering, cybersecurity, and business teams to ensure security is embedded throughout the software and AI development lifecycles.
The team you will be joining is part of the Security Architecture organization, a function that is critical to protecting the firm's applications, AI capabilities, data, and digital platforms. As applications increasingly leverage AI and machine learning technologies, this role is responsible for ensuring secure‑by‑design principles are applied consistently across traditional applications, cloud-native services, APIs, and AI‑powered solutions.
Deep expertise in application security, secure software development, and modern application architectures.
Strong understanding of AI/ML security risks, Large Language Models (LLMs), agentic AI systems, prompt injection, model misuse, and AI supply chain security.
Experience securing cloud‑native applications, APIs, microservices, containers, Kubernetes, and AI-enabled platforms.
Strong analytical, problem‑solving, and risk assessment skills with the ability to evaluate both traditional and AI‑specific security threats.
Strong communication and stakeholder management skills with the ability to collaborate across architecture, engineering, cybersecurity, cloud, and data science teams.
Degree in Computer Science, Cybersecurity, Information Technology, Engineering, Data Science, or a related discipline.
14years or more of experience in application security, software engineering, security architecture, AI security, or related technology disciplines with at least 8years of hands‑on cybersecurity experience preferred.
Demonstrated experience designing and securing enterprise‑scale applications across cloud, SaaS, hybrid, and on‑premises environments.
Deep expertise in secure software development lifecycle (SSDLC), OWASP Top10, API security, secure coding practices, and application security testing methodologies.
Strong understanding of AI/ML architectures, LLMs, Retrieval‑Augmented Generation (RAG), agentic systems, model security, prompt security, and responsible AI principles.
Experience with cloud‑native technologies, containers, Kubernetes, CI/CD pipelines, DevSecOps practices, and Infrastructure as Code (IaC).
Experience conducting threat modeling, architecture reviews, penetration test remediation, and risk assessments for applications and AI‑enabled solutions.
Familiarity with SAST, DAST, IAST, software composition analysis (SCA), API security testing, model validation, and AI security assessment techniques.
Professional certifications such as CISSP, CSSLP, CCSP, TOGAF, SABSA, AWS Security Specialty, Azure Security Engineer, AI Security, or equivalent certifications are highly desirable.
Experience within financial services or other highly regulated industries is preferred.
Additional Requirements Experience supporting enterprise application modernization, cloud transformation, DevSecOps, and AI adoption initiatives. Ability to work effectively with application development, AI engineering, cloud engineering, architecture, and cybersecurity teams in a global environment. Limited travel may be required based on business needs.
Hybrid: Expected to work in accordance with State Street's hybrid work model.
Shift: Standard business hours with flexibility to support global stakeholders across multiple time zones.
$120,000 - $202,500 Annual. The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work‑life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
We consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Job Application Disclosure: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.