JobMatch
← Back to jobs

AVP, Cyber Application Security Architect

EXL

RemoteUnited StatesdirectorFull Time
Posted
today
Source
Himalayas
Field
Engineering, Security

Skills

CommunicationLeadershipSecurityAzureCI/CDAWSGCPMachine LearningAI

Description

Principle Duties Developer enablement & secure coding support - Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure. - Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. - Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. - Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. - Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. - Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection. Secure by Design reviews - Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. - Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. - Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. - Provide clear, actionable recommendations and track follow-through with engineering teams. - Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment. CI/CD and SDLC security - Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. - Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. - Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. AI/ML security guidance - Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. - Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. Collaboration & communication - Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance. - Create and maintain secure coding guidance, reference architectures, and reusable patterns. - Support incident learnings by contributing to root cause analysis and preventative design improvements. Originally posted on Himalayas

JobMatch aggregates public listings. Always apply through the original posting.