Lead Application Security Architect
Core
Senior individual contributor bridging application security engineering and enterprise security architecture to design secure ecosystems and integrate security into the SDLC.
Role type
Senior IC Application Security Architect
Builds
Secure application ecosystems, cloud-native environments, and microservices architectures for JLL's real estate clients.
Domain
Real Estate / Application Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Application security methodologies (OWASP, SANS/CWE), Cloud-native security (AWS/Azure/GCP), DevSecOps tooling (SAST/DAST/SCA), Threat modeling (STRIDE/PASTA), Zero-trust architecture, IAM/OAuth/OIDC, Cryptography
Preferred skills
LLM/AI security knowledge (OWASP GenAi), Mentoring junior engineers, Cross-functional leadership
Technologies
AWS, Azure, GCP, SAST, DAST, SCA, CI/CD pipelines, OAuth 2.0, OIDC, NIST CSF, ISO 27001
Responsibilities
Design and maintain security architecture standards and patterns for enterprise applications; Lead security architecture reviews and threat modeling sessions; Champion secure coding standards and developer enablement programs; Communicate risk assessments to technical and non-technical stakeholders; Mentor junior security professionals on secure design practices.
Seniority
Senior, hands-on IC with mentorship responsibilities
