We are seeking a seasoned Application Security Architect to lead the design and implementation of secure software development practices across our organization.
This role will collaborate with engineering, DevOps, Operations, InfoSec teams to embed security into the software development lifecycle (SDLC), define secure architecture patterns, and guide threat modeling and risk mitigation strategies—especially in modern environments .
Key Responsibilities
- Design and implement secure architecture for web, mobile, cloud-native, and AI-driven applications.
- Define and enforce secure coding standards and best practices.
- Lead threat modeling, security design reviews, and risk assessments.
- Integrate security tools into CI / CD pipelines (e.g., SAST, DAST, SCA).
- Collaborate with development teams to remediate vulnerabilities and improve security posture.
- Evaluate and recommend security technologies and frameworks.
- Develop and maintain security guidelines, policies, and reference architectures.
- Conduct training and awareness sessions for developers and architects.
- Work with compliance teams to ensure alignment with regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS).
- Support operational needs as they arise like
- Security tool onboarding and troubleshooting
- Release and deployment reviews
- Change management and patching coordination
- Incident response and forensic analysis
- Contribution to operational playbooks and runbooks
Required Skills & Qualifications
Bachelor's or master's degree in computer science, Cybersecurity, or related field.8+ years of experience in application security, software architecture, or related roles.Strong understanding of OWASP Top 10, secure coding practices, and SDLC.Experience with security tools like SonarQube, Burp Suite, Black Duck, Akto, JFrog Artifactory.Hands-on experience with container orchestration and security (Docker, Kubernetes).Familiarity with AI / ML systems and their unique security challenges.Knowledge of authentication protocols (OAuth2, SAML, OpenID Connect).Excellent communication and stakeholder management skills.Hands-on experience with penetration testing , including use of tools like Metasploit, Burp Suite, Nmap, and custom scripts.Preferred Qualifications (Optional Skills)
Certifications : CEHExperience with CyberArk or other secrets management tools.Familiarity with DevSecOps practices and automation.Experience in secure API design and third-party integration workflows.Exposure to AI governance frameworks and secure ML lifecycle management.Experience with container runtime security, image vulnerability scanning, and Kubernetes RBAC.Understanding of AI model security, data privacy in ML workflows, and adversarial defense techniques.Why QualiZeal
Award-Winning Workplace : Certified as a Great Place to Work® and recognized by ET NOW as the Best Organization for Women in 2025.Proven Engagement : Industry-recognized client and employee Net Promoter Scores (NPS).Growth-Focused Culture : Equal-opportunity employer with a strong emphasis on leadership development, training, and continuous learning.Flexible & Supportive Environment : We value empathy, recognize contributions, and support work-life balance.Transparent Leadership : Open-book management with a collaborative, inclusive approach.Rapid Growth : 850+ professionals strong and on track to reach 3000+ employees — an exciting time to join.About QualiZeal :
QualiZeal is North America's fastest-growing independent digital quality engineering services company. With a diverse portfolio of digital transformation services encompassing Quality Engineering, Digital Engineering, Advisory and Transformation, and Emerging Technology Testing, QualiZeal empowers organizations of all sizes globally to achieve quality excellence and sustainable market leadership. Trusted by 70+ global enterprises and with a headcount of 850+ elite software quality engineers, QualiZeal is pioneering AI-enabled Quality Engineering innovation. QualiZeal has consistently maintained an outstanding client Net Promoter Score (NPS) of over 75, reflecting its unwavering commitment to client satisfaction and service excellence.
Skills Required
Jfrog Artifactory, Metasploit, Oauth2, Saml, Nmap, Sdlc, Burp Suite, Docker, Sonarqube, Owasp Top 10, Penetration Testing, Kubernetes