Principal Advisor Cyber Security Architecture (AppSec)
Core
Own and shape Application Security architecture, standards, and services across Rio Tinto, leading Secure SDLC and managing the Snyk application security capability.
Role type
Principal Advisor Cyber Security Architecture (AppSec)
Builds
Enterprise Application Security strategy, standards, reference architectures, service roadmap, and secure software development practices.
Domain
Mining and materials industry, Application Security, DevSecOps, Cloud-native security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application Security architecture, Secure SDLC, DevSecOps, threat modelling, vulnerability management, security-by-design, Snyk platform ownership, enterprise security standards creation
Preferred skills
CI/CD security, API security, secrets management, container security, software supply chain security, cloud-native and AI-enabled software development security, OWASP/NIST/ISO 27001 frameworks
Technologies
Snyk, GitHub, Azure DevOps, Artifactory
Responsibilities
Own enterprise Application Security strategy and roadmap; Lead Secure SDLC and DevSecOps practices; Embed security requirements into engineering standards and CI/CD pipelines; Support Application Security tooling and services; Guide teams in vulnerability identification and remediation; Define reusable security patterns for applications, APIs, and cloud-native workloads; Review solution designs for higher-risk initiatives; Mentor other architects and build relationships across teams
Seniority
Principal, strategy & mentorship