Application Security Architect with SAS focusing on secure software development and compliance. Partnering with teams to enhance security posture across technologies and cloud environments.
Responsibilities
Work in active partnership with development teams in identifying and building solutions to secure code and the implementation of application vulnerability scanning and penetration testing contributing documentation, developer guidance and training, and repositories with examples of best practices in secure architecture, design, design, and operational patterns and practices.
Perform risk based prioritized and periodic reviews of application architecture to identify security gaps and generally help improve the security posture of business-critical multi-tier applications in legacy, hybrid cloud, and public cloud environments.
Work cross organizationally with engineering (security champions, architects, and developers) and operations to assist in the identification, risk assessment, and remediation of security issues, and Product Management to ensure security implementations are consistent business objectives and customer requirements ensuring alignment to SAS security standards, policies, and procedures and other global regulatory requirements.
Assist in the creation of dashboards and on-demand reporting of a product division’s security posture and make recommendations for improvements aligning to Secure by Default and Zero Trust principles.
Identify, train, and partner with divisional Security Champions in place with product architecture and engineering teams.
Help champions assess and gauge risk to identify security gaps or seams in the products and integrated solutions.
Collaborate with other teams within security to identify new tools and processes to integrate into the Secure SDLC.
Recommend and promote software security policies, standards, and procedures that can improve the global security posture of the company.
Ensure all applicable security policies and processes are followed to support the organization's secure software development goals.
Requirements
Bachelor's degree with major study in technical disciplines such as Electrical Engineering or Computer Science.
5+ years of secure software development, secure system architecture and design, or related experience.
Demonstrated knowledge in securing enterprise web applications and the supporting systems and services as detailed by OWASP Top 10 for Web, CVSS, CWE/CVE, etc. extending to the effective remediation of issues surfaced by relevant SAST and DAST scanners and tooling.
Demonstrated ability to provide guidance to development and hosting/operational teams on the effective remediation of issues surfaced by relevant SAST and DAST scanners and tooling, reported by customers, or findings from internal/external offensive security testing or compliance audits.
An equivalent combination of related education, training and experience may be considered in place of the above qualifications.
2+ years of experience in developing or adopting software security patterns and best practices.
Demonstrated knowledge and willingness to learn security principles for Kubernetes, containers and micro-services, SaaS (public and private cloud deployments), ML, GenAI, and Agentic AI.
Experience with programming languages such as: Java, C/C++, C#, Rust, Python, JavaScript, PHP, Golang, etc.
Benefits
Comprehensive medical, prescription, dental and vision plans.
Medical plan options include: PPO with low annual deductible and copays.
HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan.
There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
An industry-leading 401k plan.
Tuition Assistance Program and programs and resources to support your development.
Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
Volunteer Time Off, parental leave and unlimited paid sick days.
Generous childcare benefits for all full-time employees.
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.
Security Officer responsible for maintaining a safe environment for clients and employees. Enforcing policies and responding to emergencies at the client's site.
Senior Security Advisor enhancing security measures to align with corporate objectives at Desjardins. Leading development of strategic initiatives and overseeing best practices in security.
Controls Professional assessing internal control frameworks at Barclays, improving control effectiveness and managing risks to ensure compliance with regulations.
Senior Information Security Engineer at Wells Fargo investigating insider threats and strengthening cybersecurity measures. Conducting advanced investigations and collaborating with cyber teams to mitigate risks.
Staff Product Manager overseeing enterprise security product strategy for Tenable. Collaborating with various teams to deliver customer - focused solutions and product features.
Information Systems Security Officer managing operational security posture for information systems at GDIT. Collaborating closely with ISSM and ISO, handling security aspects, and ensuring compliance with security standards.
Program Security Representative providing multi - discipline security support for Special Access Programs. Ensuring compliance, developing policies, and conducting security assessments in a military context.