Stand out for this role — generate a tailored resume and cover letter in about a minute.
Insight Global seeks a Senior Application Security Architect to lead security architecture across our client’s digital products. You will review full lifecycles, guide secure design, and drive remediation across web, mobile, APIs, and cloud platforms.
The role combines hands‑on engineering with strategic architectural leadership and mentorship for engineering teams. You will influence SSDLC standards, perform threat modeling, and validate security through code reviews, testing, and security
A client has a unique opportunity for a Senior Application Security Architect to join their organization in a role that allows for a direct impact on conserving vital resources and protecting the people they serve.
The Senior Application Security Architect will serve as a senior technical leader within the Product Security Team and provide security architecture leadership across the client’s commercial digital product portfolio. This role reviews the full product lifecycle and technology stack, including web and mobile applications, APIs, cloud IaaS/PaaS architectures, SaaS platforms, AI-enabled capabilities, IoT-connected solutions, data integrations, third-party software, and customer-facing product components.
The Senior Application Security Architect will combine deep application and product security architecture expertise with practical hands‑on engineering skills. The role will define secure design patterns and reference architectures, lead complex threat modeling and architecture reviews, perform targeted security testing and code/dependency analysis, guide remediation, mentor technical teams, and help engineering teams integrate security into their software development lifecycle.
Lead complex application and product security architecture reviews across the organization’s commercial digital products, including web/mobile applications, APIs, SaaS platforms, cloud services, containers, AI-enabled capabilities, IoT solutions, endpoints, network‑connected components, and third‑party software.Own and evolve SSDLC standards, secure reference architectures, reusable design patterns, application security requirements, and product security procedures aligned to practical engineering workflows.Lead hands‑on threat modeling for complex applications, APIs, cloud architectures, data flows, identity patterns, AI/ML integrations, automation workflows, and external service integrations; document threats, controls, residual risk, and remediation decisions.Provide architecture guidance for secure application design, including authentication and authorization, session management, API security, secrets management, encryption, tenant isolation, input/output validation, logging, resilience, and secure service‑to‑service communication.Perform targeted hands‑on technical validation through secure code review, dependency analysis, configuration review, security testing, proof‑of‑concept development, and validation of remediation effectiveness.Conduct and guide technical security reviews using SAST, SCA, SBOM, DAST, secrets scanning, API security, container security, cloud security posture, vulnerability management, and AI security evaluation tools.Use and help operationalize platforms such as Snyk, Wiz, GitHub Advanced Security, DAST tooling, threat modeling tools, SBOM/SCA tooling, CI/CD security tooling, native Azure/AWS security services, and SIEM/log analysis tools such as Elastic.Influence and partner with software engineering, architecture, product, and DevSecOps leaders to embed security controls, design reviews, test gates, evidence collection, automated response workflows, and remediation tracking into CI/CD pipelines and product release processes.Design and review identity, access, and secure communication architectures, including IAM, OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, privileged access, encryption, secure APIs, secrets management, and service‑to‑service communication.Analyze application, cloud, API, container, endpoint, and security telemetry to support threat detection, anomalous behavior investigation, incident triage, containment support, product risk decisions, and prioritized remediation plans.Translate complex architecture risks and technical findings into actionable design guidance, remediation plans, standards updates, metrics, risk inputs, and concise executive and stakeholder‑ready summaries.Support customer‑facing cybersecurity discussions, questionnaires, and technical documentation related to the organization’s commercial product security, application architecture, cloud controls, and SSDLC practices.Stay current on application security architecture, cloud security, DevSecOps, vulnerability management, secure coding, threat intelligence, AI application security, and relevant frameworks and standards including NIST, OWASP, CIS, ISO 27001, SOC 2, and applicable secure software guidance.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.