Senior Application Security Architect

Jobtailor

Cary (NC)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Senior Security Engineer to elevate secure software development across our multi‑tier environments. You will influence architecture, promote Secure by Default deployment, and work with R&D and cloud hosting teams to maintain robust security postures.

You will mentor Security Champions, perform threat modeling, code reviews, and remediation guidance, while ensuring compliance with global regulations and product roadmaps.

Qualifications

  • 8+ years in secure software development or secure architecture.
  • Experience applying secure design, threat modeling and code reviews.
  • Knowledge of MITRE ATT&CK, OWASP Top 10, CVSS and CWE.

Responsibilities

  • Collaborate across R&D and cloud teams to improve security posture of multi‑tier solutions.
  • Plan evolutionary secure architectures and align third‑party tech with security goals.
  • Assess and harden products across SDLC with risk-based remediation guidance.
  • Partner with Product Management to align security with business objectives and regulations.
  • Identify and mentor Security Champions within product teams.
  • Develop secure engineering documentation and training aligned with PSO standards.

Skills

Secure Software Development
Secure System Architecture
Security Certifications (CISSP, CISM,

Education

Bachelor's degree in CS/EE or related

Tools

Job description

  • Collaborate across R&D and cloud hosting teams to strategically improve the security posture of business-critical multi-tier solutions in legacy, hybrid cloud, and public cloud environments. Includes tactical refactoring, environment promotion, and Secure by Default deployment and configuration to maintain security consistency if not parity between all environments.
  • Collaborate in the planning of evolutionary paths for secure architectures and systems incorporating and aligning dependent third-party architectures as well as the adoption of new technologies while maintaining a robust and consistent security posture. Includes employing specific security compensating controls, defense in depth, and security posture aspects in support of Secure by Design, Secure by Default (deployment and configuration), and Zero Trust Architectural principles.
  • Work with development teams providing security assessment and hardening of products spanning the SDLC and development pipelines left/early-shifted wherever possible. Includes performing periodic secure design, threat modeling, code reviews, or direct verification to identify and triage issues assessing the security risk and recommending remediation steps for vulnerabilities and weaknesses.
  • Collaborate with Product Management stakeholders to ensure security implementations are consistent with business objectives, customer requirements, and applicable global regulations.
  • Identify, train, and partner with Security Champions in place with product R&D teams. Help champions assess and gauge risk to identify security gaps or seams in the products and integrated solutions.
  • Create and maintain secure engineering documentation, guidance, or training collateral supporting with PSO standards, policies, and procedures.
  • Collaborate with other teams within security to identify new tools and processes to integrate into the Secure SDLC.
  • Recommend and promote software security policies, standards, and procedures that can improve the global SAS security posture.
  • Mentor and coach within the Product Security Office and other Security Architects aligned with your security breadth and building depth via subject matter expertise.
  • Ensure all applicable security policies and processes are followed to support the organization's secure software development goals.
Requirements
  • 8+ years of secure software development, secure system architecture and design, or related experience.
  • 4+ years of experience in developing or adopting software security best practices.
  • Bachelor's degree with major study in Computer Science, Electrical Engineering, or related.
  • Possess relevant security certifications such as from SANS, GIAC, or ISACA CEH, for CCSP, CSSLP, CISM, or CISSP.
  • Knowledge of current Global Enterprise security risks and attacker TTPs as published by MITRE.
  • Experience with programming languages such as C/C++, Java, Python, JavaScript, PHP, Golang, etc. allowing you to review code or logic and be confident in giving prescriptive guidance to R&D and hosting/ops in security patterns and best practices.
  • Expertise in securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE and SANS-25.
  • Experience with security best practices for modern R&D such as micro-services and containers, Agentic AI, hyper-scale cloud hosting and operations, etc.
  • Equivalent combination of related education, training and experience may be considered in place of the above qualifications.
Core Competencies

Demonstrates expertise in secure software development and system architecture, with a strong focus on implementing security best practices across the software development lifecycle. Proficient in mentoring teams and collaborating with stakeholders to align security initiatives with business objectives and regulatory requirements.

Highest-signal resume keywords
  • Secure Software Development
  • Secure System Architecture
  • Security Certifications (CISSP, CISM, CSSLP)
  • Programming Languages (C/C++, Java, Python, JavaScript, PHP, Golang)
  • OWASP Top 10 Familiarity
ATS Optimization Keywords
Hard Skills
  • Secure Software Development
  • Secure System Architecture
  • Security Best Practices
  • Threat Modeling
  • Code Review
  • Security Risk Assessment
  • Secure SDLC
  • Micro-Services Security
  • Container Security
  • Security Posture Management
Soft Skills
  • Collaboration
  • Mentoring
  • Training
  • Communication
  • Problem-Solving
Certifications & Qualifications
  • CISSP
  • CISM
  • CSSLP
  • CEH
  • SANS
  • GIAC
Industry Keywords
  • Global Enterprise Security Risks
  • MITRE ATT&CK
  • OWASP Top 10
  • CVSS
  • CWE
  • SANS-25
Tools & Technologies
  • Cloud Hosting
  • Secure by Design
  • Secure by Default
  • Zero Trust Architecture
  • Security Compensating Controls
  • Defense in Depth
  • Agentic AI
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Product Security
Staff Software Engineer, Product Security

Jobtailor • California (MO)

On-site
USD 180,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 200,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • United States

On-site
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

Jobtailor • San Francisco (CA)

On-site
USD 140,000 - 180,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Senior Lead Info Security Architect
Senior Lead Info Security Architect

Jobtailor • Illinois

On-site
USD 150,000 - 230,000
Senior Manager, Information Security
Senior Manager, Information Security

Jobtailor • North Carolina

On-site
USD 140,000 - 180,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Kentucky

On-site
USD 180,000 - 240,000
Director, Chief Information Security Architect
Director, Chief Information Security Architect

Jobtailor • Oklahoma City (OK)

On-site
USD 140,000 - 190,000