About the Role :
We are seeking an experienced Application Security Architect with a strong background in Information Security Assessments, AI Security Architecture, and Secure Software Development.
The ideal candidate should possess expertise in application security, cloud security, security architecture reviews, SBOM creation, and secure development practices.
Exposure to leveraging Generative AI tools for security assessments and vulnerability analysis is highly desirable.
Key Responsibilities :
- Define, develop, and drive application security initiatives across enterprise applications.
- Design, document, and maintain secure application architectures, standards, and security patterns.
- Conduct security architecture reviews for new and existing applications to identify security risks and vulnerabilities.
- Collaborate with engineering, architecture, and product teams to integrate security throughout the Software Development Lifecycle (SDLC).
- Define and enforce security requirements for applications, APIs, and cloud-native solutions.
- Develop and maintain secure coding standards and security best practices for development teams.
- Enhance application security processes, governance, and security assessment methodologies.
- Build reusable secure reference architectures and security patterns for enterprise applications.
- Perform information security assessments and provide risk-based security recommendations.
- Support secure deployment of applications across cloud environments.
- Evaluate architectural decisions from a security and risk management perspective.
- Work closely with development teams to remediate security findings and improve application resilience.
- Create and maintain Software Bill of Materials (SBOM) for applications.
- Leverage Generative AI tools (OpenAI, Claude, etc.) to assist in identifying security vulnerabilities, reviewing application architectures, and improving security assessments.
Mandatory Skills :
- 8-12 years of experience in Application Security, Information Security, or Security Architecture.
- Strong experience in AI Security Architecture.
- Hands-on experience in Information Security Assessments.
- Experience creating and managing Software Bill of Materials (SBOM).
- Strong understanding of secure application architecture and secure SDLC.
- Experience conducting application security architecture reviews.
- Strong knowledge of OWASP Top 10, NIST, and secure coding practices.
- Experience defining security controls for APIs and enterprise applications.
- Knowledge of cloud security architecture and secure cloud deployments.
- Strong understanding of risk management and security governance.
- Excellent communication and stakeholder management skills.
Good to Have
- Hands-on experience using Generative AI tools such as OpenAI (ChatGPT), Claude, or similar AI platforms for :
a. Security architecture reviews
b. Vulnerability identification
c. Threat analysis
d. Secure code review
e. Risk assessment
- Experience with DevSecOps and CI/CD security integration.
- Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, or equivalent.
- Experience with SAST, DAST, SCA, API Security, and Container Security tools.
Education : Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related technical discipline.
Ekfrazo Technologies - AI Security/Application Security Architect • Pune