Staff Application Security Architect

Rocket Homes Real Estate LLC

Seattle (WA)

On-site

USD 149,000 - 318,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Rocket Homes Real Estate LLC is seeking a Senior Application Security Architect to drive secure software patterns and SDLC integration. You will design standard security requirements, mentor teams, and mature security processes across product, engineering, and information security to bake security into every release.

You will lead threat modeling, secure design, and automated guardrails, aligning with regulatory and contractual requirements while enabling business velocity.

Qualifications

  • 10+ years in information security or secure software development, or a bachelor’s plus 5+ years in related roles.
  • Proven experience performing architectural threat modeling on complex systems using formal frameworks (STRIDE, DREAD, PASTA).
  • Ability to read, write, and audit code for security vulnerabilities with actionable remediation guidance.
  • Deep familiarity with Java ecosystem (preferred), plus .NET and/or Python.
  • Proficiency in scripting languages (PowerShell, Bash, Python) for automation.
  • Experience leveraging AI-assisted engineering tools while maintaining critical thinking to validate AI outputs.
  • Hands-on experience with secure SDLC, DevSecOps CI/CD pipelines, SAST/DAST/SCA/Secret Scanning tooling, IAM (OAuth2.0, OIDC, SAML), container security (Docker, Kubernetes), and secure coding standards.
  • Knowledge of least privilege, zero trust architectures, secure defaults, and secure input validation.

Responsibilities

  • Perform security reviews of applications throughout the SDLC, including threat modeling and code reviews.
  • Set strategic direction for AppSec initiatives, shift-left processes, and secure coding standards.
  • Collaborate with software engineering, product, architecture, and information security teams to align goals.
  • Identify opportunities to improve delivery pipelines and implement automated guardrails and remediations.
  • Collaborate with business, product owners, architecture, and information security to enable secure software patterns and business velocity.
  • Coordinate and drive initiatives for AppSec engineers to build and scale security strategies.
  • Build processes to test compliance and effectiveness of security requirements via automated guardrails and continuous testing.
  • Influence decisions on secure architecture, API design, authentication/authorization, and cloud deployment.
  • Create and evangelize application security policy sets and secure design patterns.
  • Work with development and audit teams to align architectures with upcoming compliance and regulatory requirements.
  • Mentor engineers and information security staff on threat modeling, secure design, and vulnerability remediation techniques.

Skills

Threat modeling
Secure coding principles
Code audit
Automation scripting
AI tooling
DevSecOps
Cloud security
Zero trust

Education

Bachelor’s degree in computer science or information security

Tools

SAST/DAST/SCA tooling
Docker
Kubernetes
OAuth2.0 / OIDC / SAML
CI/CD security tooling
MITRE ATT&CK
STRIDE / DREAD / PASTA Threat Modeling

Job description

As the Senior Application Security Architect, you work strategically with engineering and product teams to enable the delivery of secure application patterns and software solutions. You design standard security requirements for how applications should be built, deployed, and maintained, ensuring security is baked into the software development lifecycle from the start. You also build and mature team processes that empower development teams to own their software's security posture while mentoring internal security team members.

Responsibilities

Perform security reviews of applications throughout the SDLC, including threat modeling and source code reviews, focusing on designing secure applications from the start and ensuring secure design principles are correctly implemented.

Help set strategic direction for application security initiatives, shift-left processes, and secure coding standards across the enterprise, treating security as quality.

Build relationships and collaborate with software engineering, product, architecture, and information security teams to ensure alignment of company vision and secure coding goals.

Identify opportunities for improvement within software delivery pipelines and work with engineering leadership to implement automated security guardrails and remediations.

Collaborate with business, product owners, architecture, and information security teams to enable delivery of secure software patterns that support business velocity.

Coordinate and drive initiatives for AppSec engineers to build, execute, and scale application security strategies.

Build processes that test compliance and effectiveness of software security requirements through automated guardrails and continuous security testing.

Influence decision makers in secure application architecture, API design, authentication/authorization controls, and modern cloud deployment.

Create and evangelize application security policy sets and secure design patterns to balance velocity and external compliance requirements.

Work directly with development and audit teams to align security architectures against upcoming compliance, regulatory (e.g., SSDF, Executive Orders on Cybersecurity), and contractual landscapes.

Mentor software engineers and information security team members on threat modeling, secure code design, and modern vulnerability remediation techniques.

Minimum Qualifications
  • 10 years of experience in information security, application development with a secure coding background or software engineering role with a focus on secure code & design principles, OR bachelor’s degree in computer science, information security, or a related field and 5 years of experience.
  • Proven experience performing architectural threat modeling on complex systems and applications using formal frameworks (e.g., STRIDE, DREAD, PASTA).
  • Strong ability to read, write, and audit code for security vulnerabilities, with the ability to provide engineering teams with precise, actionable remediation guidance.
  • Deep technical familiarity with Java ecosystem (strongly preferred), as well as .NET and/or Python.
  • Proficiency in at least one scripting language (e.g., PowerShell, Bash, Python) for automation and custom tooling.
  • Demonstrated aptitude for leveraging AI‑assisted engineering tools to drive operational efficiency, balanced with critical thinking to identify, validate, and correct AI inaccuracies or hallucinations.
  • Practical experience or working knowledge of secure SDLC frameworks, DevSecOps pipeline integration (CI/CD), SAST/DAST/SCA/Secret Scanning tooling, identity and access management (OAuth2.0, OIDC, SAML), container security (Docker, Kubernetes), OWASPTop10 / ASVS mappings, MITREATTACK Framework, and fundamental InfoSec concepts such as least privilege, zero trust architectures, secure input validation, layered security, secure defaults.
  • Deep understanding of modern enterprise security risks such as software supply chain security, securing and hardening development environments, and identifying and mitigating risk at scale.
Preferred Qualifications
  • Master’s degree in computer science, information security, or a related field.
  • Advanced expertise in architectural threat modeling and building automated threat modeling capabilities into developer workflows.
  • OSCP, OSWE, GWAPT, CISSP, CCSP, or other relevant security certifications.
  • Hands‑on experience scaling AppSec programs across large engineering organizations, including integrating secure solutions across an organization’s SDLC and administering a developer security champion program.
  • Strong technical experience with Java.
On‑Call Expectations

This role may include participation in an on‑call rotation to support production systems and ensure service reliability. Responsibilities may include coverage during nights and weekends. Frequency and scheduling will be determined by team needs and communicated accordingly.

Benefits and Compensation

Compensation ranges from $149,000 to $318,000 annually, with potential annual bonuses, incentives, and other employment‑related benefits including medical, dental, vision, 401(k) retirement plan, and paid‑time off.

Eligible team members receive health benefits, a 401(k) plan, and paid time off, among other perks.

Equal Employment Opportunity

Decisions related to employment are not based on race, color, religion, national origin, sex, physical or mental disability, sexual orientation, gender identity or expression, age, military or veteran status or any other characteristic protected by state and federal law. The company provides reasonable accommodations to qualified individuals with disabilities in accordance with applicable state and federal laws. Applicants requiring reasonable accommodations should contact the Human Resources team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Architect, Information Security - DevSecOps/Application Security
Architect, Information Security - DevSecOps/Application Security

Jobgether • United States

On-site
USD 72,000 - 157,000
Competitive compensation
US-based role
Enterprise security exposure
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Application Security Engineer - Plano, TX
Application Security Engineer - Plano, TX

Motion Recruitment Partners LLC • Plano (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Senior/Lead AppSec Engineer
Senior/Lead AppSec Engineer

AgileEngine, LLC • Brazil (IN)

On-site
USD 120,000 - 160,000
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment Partners LLC • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2