Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc

Maryland Heights (MO)

On-site

USD 140,000 - 190,000

Full time

20 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Saransh Inc. seeks a Senior Application Security Architect to lead Secure-by-Design initiatives across enterprise apps, embedding security early in SDLC.

You will conduct threat modeling, security architecture reviews, secure design assessments, and establish guardrails aligned with OWASP ASVS and NIST SSDF, collaborating with developers, enterprise architects, DevOps, and business stakeholders. The architect will work closely with teams to ensure security risks are identified and mitigated

Qualifications

  • 10+ years of cybersecurity experience
  • 5+ years leading security architecture reviews and threat modeling engagements
  • Experience in regulated industries such as Financial Services, Banking, Insurance, or Healthcare
  • Demonstrated expertise implementing Secure SDLC and DevSecOps programs at enterprise scale

Responsibilities

  • Define and implement Secure-by-Design principles across application development programs.
  • Develop security reference architectures, reusable security patterns, and architecture standards.
  • Embed security requirements into solution design and development processes.
  • Threat modeling workshops using STRIDE, Attack Trees, or similar methodologies.
  • Identify trust boundaries, attack surfaces, abuse cases, and potential design weaknesses.
  • Provide risk-based mitigation recommendations and architectural guidance.
  • Perform application, API, microservices, cloud-native, and AI-enabled app security reviews.
  • Validate architecture compliance against OWASP ASVS, OWASP Top 10, NIST SSDF, and standards.
  • Review data flows, authentication, authorization, encryption, secrets management, and logging controls.
  • Integrate security requirements into Agile and CI/CD workflows.
  • Collaborate with development teams to implement security-by-default controls.
  • Support adoption of SAST, DAST, SCA, API Security, Container Security, and Secure Coding practices.
  • Provide secure coding guidance and architectural consultation.
  • Conduct architecture review sessions, threat modeling training, and security awareness workshops.
  • Act as a trusted advisor to engineering and product teams.
  • Partner with Enterprise Architects, Product Teams, Security Leadership, and Development Managers.
  • Define security acceptance criteria and architecture review processes.
  • Present security findings, risks, and remediation strategies to senior leadership.

Skills

Application Security Architecture
Secure-by-Design Methodologies
Threat Modeling (STRIDE, Attack Trees,
PASTA
OWASP ASVS, OWASP Top 10
Secure SDLC / DevSecOps
Security Architecture Reviews
Secure Coding Practices
API Security
Cloud Security (AWS, Azure, GCP)

Tools

Microsoft Threat Modeling Tool

Job description

Role: Sr. Application Security (AppSec) Architect

Location: Maryland Heights, MO

W2 Position

What are the top 3 skills required for this role?


  • Application Security Architecture

  • Secure-by-Design Methodologies

  • Threat Modeling (STRIDE, Attack Trees, PASTA)

  • OWASP ASVS, OWASP Top 10

  • Secure SDLC / DevSecOps

  • Security Architecture Reviews

  • Secure Coding Practices

  • API Security

  • Cloud Security (AWS, Azure, GCP)


Name


  • Application Security

  • Sec Practices - OWASP Top 10

  • Microsoft Threat Modeling Tool

  • SDLC Concepts


Job Description/ Responsibilities

The Senior Application Security Architect will lead Secure-by-Design initiatives across enterprise applications by embedding security early in the software development lifecycle (SDLC). The role is responsible for conducting threat modeling, security architecture reviews, secure design assessments, and establishing security guardrails aligned with OWASP ASVS, NIST SSDF, and industry best practices. The architect will work closely with developers, enterprise architects, DevOps teams, and business stakeholders to ensure security risks are identified and mitigated before applications reach production.


Key Responsibilities

Secure-by-Design Leadership


  • Define and implement Secure-by-Design principles across application development programs.

  • Develop security reference architectures, reusable security patterns, and architecture standards.

  • Embed security requirements into solution design and development processes.


Threat Modeling & Risk Analysis


  • Conduct threat modeling workshops using STRIDE, Attack Trees, or similar methodologies.

  • Identify trust boundaries, attack surfaces, abuse cases, and potential design weaknesses.

  • Provide risk-based mitigation recommendations and architectural guidance.


Security Architecture Reviews


  • Perform application, API, microservices, cloud-native, and AI-enabled application security reviews.

  • Validate architecture compliance against OWASP ASVS, OWASP Top 10, NIST SSDF, and organizational standards.

  • Review data flows, authentication, authorization, encryption, secrets management, and logging controls.


Secure SDLC & DevSecOps


  • Integrate security requirements into Agile and CI/CD workflows.

  • Collaborate with development teams to implement security-by-default controls.

  • Support adoption of SAST, DAST, SCA, API Security, Container Security, and Secure Coding practices.


Developer Enablement


  • Provide secure coding guidance and architectural consultation.

  • Conduct architecture review sessions, threat modeling training, and security awareness workshops.

  • Act as a trusted advisor to engineering and product teams.


Governance & Stakeholder Management


  • Partner with Enterprise Architects, Product Teams, Security Leadership, and Development Managers.

  • Define security acceptance criteria and architecture review processes.

  • Present security findings, risks, and remediation strategies to senior leadership.



  • 10+ years of cybersecurity, application security, or security architecture experience.

  • 5+ years leading security architecture reviews and threat modeling engagements.

  • Experience working in regulated industries such as Financial Services, Banking, Insurance, or Healthcare.

  • Demonstrated expertise implementing Secure SDLC and DevSecOps programs at enterprise scale.


Preferred Certifications


  • CISSP

  • CSSLP

  • CCSP

  • SABSA

  • AWS/Azure/GCP Security Certifications

  • GIAC GWEB / GSEC

  • Certified Secure Software Lifecycle Professional (CSSLP)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Security Architect with Java exp at Austin, TX urgent
Security Architect with Java exp at Austin, TX urgent

Tech Mirrors • Austin (TX)

On-site
USD 83,000 - 103,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Architect
Application Security Architect

My3Tech • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Sr. Application Security Architect - .NET / Secure SDLC
Sr. Application Security Architect - .NET / Secure SDLC

Ts-California • Milpitas (CA)

On-site
USD 180,000 - 200,000
Health, Dental, Vision insurance
401K with company match
Tuition assistance
+2