AVP, Cyber Application Security Architect
RemoteUnited StatesdirectorFull Time
- Posted
- today
- Source
- Himalayas
- Field
- Engineering, Security
Skills
CommunicationLeadershipSecurityAzureCI/CDAWSGCPMachine LearningAI
Description
Principle Duties Developer enablement & secure coding support
- Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure.
- Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries.
- Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches.
- Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk.
- Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture.
- Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection.
Secure by Design reviews
- Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early.
- Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk.
- Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures.
- Provide clear, actionable recommendations and track follow-through with engineering teams.
- Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment.
CI/CD and SDLC security
- Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns.
- Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows.
- Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service.
AI/ML security guidance
- Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns.
- Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features.
Collaboration & communication
- Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance.
- Create and maintain secure coding guidance, reference architectures, and reusable patterns.
- Support incident learnings by contributing to root cause analysis and preventative design improvements.
Originally posted on Himalayas
JobMatch aggregates public listings. Always apply through the original posting.