Job Summary:
We are seeking a highly skilled Senior Application Security Architect to join our team and play a pivotal role in safeguarding our critical applications. As a security expert, you will be responsible for designing, implementing, and maintaining robust security measures to protect our applications and data from threats.
Responsibilities:
- Conduct comprehensive security assessments and risk analyses of applications, identifying vulnerabilities and recommending mitigation strategies.
- Develop and implement security architectures, standards, and guidelines for application development and deployment using modern tech stacks and cloud environments.
- Provide technical leadership and guidance to development teams on security best practices and coding standards for technologies such as Java, Python, .NET, React, Angular, and Node.js.
- Review and approve application designs and code for security compliance, ensuring adherence to industry standards like OWASP Top 10.
- Conduct security testing and penetration testing using tools like Burp Suite, Metasploit, and Nessus.
- Develop and maintain security incident response plans and procedures.
- Stay up-to-date with emerging security threats and trends, including cloud-specific vulnerabilities and best practices.
- Collaborate with other security teams, such as infrastructure and network security, to ensure a comprehensive security posture.
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in application security architecture and design.
- Strong understanding of security principles, frameworks, and standards (e.g., OWASP, NIST, PCI-DSS).
- Experience with security testing methodologies (e.g., penetration testing, vulnerability scanning).
- Knowledge of common security threats and vulnerabilities, including those specific to cloud environments (e.g., misconfigurations, data breaches).
- Proficiency in programming languages and scripting (e.g., Python, Java, JavaScript).
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills.
- Ability to work independently and as part of a team.
Preferred Qualifications:
- Certifications such as CISSP, CISM, or CSSLP.
- Experience with cloud platforms like AWS, Azure, or GCP, including security best practices and services.
- Knowledge of DevOps practices and tools, such as CI/CD pipelines and infrastructure as code.