Job Summary :
We are seeking a skilled and experienced Application Security Architect who has good experience in application design and development as well as equal experience in application security.
Someone who can understand code, review architecture from the security perspective.
Explain the team about the vulnerability in the code, deployment and guide them in potential fix for the same.
Key Responsibilities : Secure Architectures :
- Develop and maintain secure application design patterns and architectures for web, mobile, and cloud-native by Design :
- Collaborate with development, DevOps, and product teams to integrate security principles and controls into the SDLC Modeling :
- Conduct threat modeling and risk assessments on new and existing Standards & Policies :
- Define and enforce secure coding guidelines, architecture standards, and application security & Architecture Reviews :
- Perform security reviews of application architecture and source code; provide actionable & Automation :
- Evaluate and integrate AppSec tools (e.g., SAST, DAST, SCA, IAST, RASP) into CI / CD Response :
- Assist in application-related security incident response, root cause analysis, and remediation & Awareness :
- Mentor developers and engineers on secure coding and design principles; develop security training & Risk :
- Ensure applications meet regulatory, compliance, and internal risk management requirements (e.g., GDPR, SOC 2, : :
- Bachelors degree in computer science, Cybersecurity, or a related field.
- 12+ years of experience in application security, software development, or architecture.
- Deep understanding of modern application development (e.g., microservices, APIs, cloud-
native apps).
Strong knowledge of security vulnerabilities and defenses (e.g., OWASP Top 10, CWE, CVE).Hands-on experience with security tools (e.g., Veracode, Fortify, SonarQube, Checkmarx, Burp Suite).Experience with public cloud platforms (AWS, Azure, GCP) and their native security services.Familiarity with SDLC, CI / CD pipelines, and DevSecOps :Security certifications such as CSSLP, CISSP, OSWE, or GIAC GWAPT / GSSP.Experience with Kubernetes, containers, and infrastructure-as-code (e.g., Terraform, Knowledge of secure mobile application Competencies :Strategic and tactical thinking in security architecture.Strong communication and interpersonal skills.Ability to influence stakeholders and drive security initiatives.Analytical mindset and strong problem-solving skills.(ref : hirist.tech)