Senior Application Security Architect
Lead secure application design and help development teams integrate security throughout the SDLC. Review architectures, code, and security findings, and guide teams toward practical mitigations.
Responsabilidades
- Design and review secure architectures for web, API, microservices, and AI-enabled environments.
- Conduct threat modeling and security reviews covering OWASP Top 10, API risks, business logic flaws, and data exposure.
- Review application code, architecture, and security controls; identify risks and remediation paths.
- Integrate and optimize SAST, DAST, SCA, secrets scanning, and other security controls in CI/CD pipelines.
- Help engineering teams embed security throughout the SDLC and prioritize effective mitigations.
- Explain technical vulnerabilities as business risks to product, engineering, and executive stakeholders.
Requisitos
- At least 4 years of cybersecurity experience, including application security or secure software development.
- Experience designing secure application architectures and reviewing complex application ecosystems.
- Ability to audit code in at least one programming language.
- Hands-on threat modeling experience, such as STRIDE.
- Experience with SAST, DAST, SCA, findings triage, and remediation guidance.
- Strong understanding of APIs, microservices, cloud-native applications, and AI/LLM integrations.
- Ability to communicate technical risks to engineering, product, and leadership teams.