Job Description
Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.