Staff Application Security Architect
Core
Design standard security requirements for application patterns, deploy secure SDLC processes, and mentor engineering teams to own software security posture.
Role type
Staff Application Security Architect
Builds
Secure application patterns, automated security guardrails, and secure design principles for the enterprise.
Domain
Fintech / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Architectural threat modeling (STRIDE, DREAD, PASTA), secure code review and audit, DevSecOps pipeline integration, SAST/DAST/SCA tooling, Identity and access management (OAuth 2.0, OIDC, SAML), Container security (Docker, Kubernetes), OWASP Top 10 / ASVS, MITRE ATT&CK Framework, secure input validation, zero trust architectures
Preferred skills
Advanced automated threat modeling capabilities, scaling AppSec programs across large organizations, developer security champion program administration, deep Java expertise
Technologies
Java, .NET, Python, PowerShell, Bash, Docker, Kubernetes, CI/CD pipelines
Responsibilities
Perform security reviews and threat modeling throughout the SDLC, set strategic direction for shift-left security processes, collaborate with engineering and product teams to align secure coding goals, implement automated security guardrails in delivery pipelines, create and evangelize application security policy sets, mentor engineers on secure design and remediation techniques
Seniority
Staff, hands-on IC with strategic influence