Job Title : Application Security Risk Architect
Experience : 7 - 9
Job Description
Threat Modeling & Security Architecture Reviews (Primary Focus) :
- Lead threat modeling sessions using frameworks like STRIDE, PASTA, LINDDUN to identify risks and mitigations.
- Conduct security architecture reviews for new and existing applications (web, mobile, APIs, microservices, cloud-native).
- Analyze data flow diagrams, trust boundaries, and third-party integrations for attack vectors.
- Collaborate with solution architects to embed secure design principles and zero-trust models in architectures.
- Maintain a central repository of threat models and risk assessments for traceability.
Application Security & Vulnerability Management :
Perform secure design and code assessments for critical applications.Support the SAST program (Checkmarx, Fortify, SonarQube), prioritizing findings linked to design flaws.Partner with developers to guide remediation with secure design patterns and mitigation strategies.Governance, Awareness & Developer Support :
Define secure design guidelines and best practices for development teams.Provide training and mentorship on threat modeling and secure architecture principles.Create security playbooks, checklists, and documentation for architecture security reviews.Required Skills & Qualifications :
5+ years of experience in Application Security or Secure Software Architecture with a focus on Threat Modeling & Architecture Security Reviews.Strong knowledge of secure application design : authentication, authorization, data protection, API security, microservices security.Experience with threat modeling tools (Microsoft Threat Modeling Tool, IriusRisk) or manual frameworks (STRIDE).Familiarity with cloud security principles across AWS, Azure, GCP architectures.Hands-on experience with SAST tools (Checkmarx, Fortify, SonarQube) & secure coding standards (OWASP, CWE).Preferred Qualifications :
Experience integrating secure design practices into Agile and DevOps CI / CD pipelines.Knowledge of compliance & risk frameworks : OWASP ASVS, NIST 800-53, ISO 27001, PCI DSS.Relevant security certifications : CSSLP, SABSA, CISSP, AWS Security Specialty.Exposure to DAST, SCA, container security, or penetration testing methodologies(ref : hirist.tech)