
Application & Platform Security Architect
Posted Jun 27

Posted Jun 27
This is a fully remote position, open to applicants in Florida.
• Establish reusable security architecture patterns and guardrails to facilitate consistent and secure implementations across high-risk business applications.
• Propel secure-by-design initiatives by incorporating security considerations from the onset of the software architecture lifecycle and guiding enterprise architecture direction.
• Represent security architecture in design authority boards and technical review councils, promoting risk-based security controls.
• Collaborate with in-business IT customers, including application architects and engineers, to assess application software and infrastructure designs for the purpose of defining and designing application controls that align with enterprise standards.
• Develop application-specific security control architectures and create design artifacts to ensure secure implementation of business-critical systems.
• Create reusable implementation guidance and design patterns based on past engagements to scale services effectively.
• Partner with information security leadership to formulate strategies and plans that enforce security requirements and address identified risks in infrastructure and applications.
• Serve as a security architecture liaison to IT delivery and engineering teams, integrating security principles into technical delivery and architecture review discussions.
• Support security considerations in business and IT initiatives by aiding in the architecture, design, implementation, deployment, and operational transition of innovative and secure technology solutions.
• Research, assess, design, test, recommend, and plan the implementation of new or updated information security technologies.
• Build collaborative working relationships with Information Technology functions to ensure solutions are aligned with security architecture and business strategy.
• Act in an advisory capacity for application development or acquisition projects to evaluate security requirements and controls, ensuring that security measures are executed as intended.
• Complete remediation actions and initiate steps to ensure compliance and security gaps are effectively addressed.
• Investigate and evaluate new information security threats and suggest remedial measures.
• Promote an information security culture through education, skill enhancement, and the execution of effective information security processes and practices.
• Comprehend and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety, GxP compliance, data security, and the software development lifecycle.
• Cultivate and leverage relationships with affiliates, subsidiaries, vendors, and industry peers in alignment with AbbVie Values, Vendor Management Office, and Purchasing to advance the organization's mission, vision, and goals.
• Design security architecture for applications, ensuring all components comply with best practices and regulatory standards.
• Collaborate closely with software development, DevOps, and operations teams to integrate security within the software development lifecycle (SDLC).
• Lead initiatives to identify potential threats through application threat modeling and recommend design modifications to mitigate risks.
• Bachelor’s degree with 9 years of experience OR Master’s degree with 8 years of experience OR PhD with 4 years of experience in information security and/or related areas (IT Audit, Risk Management, or Security Architecture).
• Must exhibit exceptional capability in assessing and communicating information security concepts and practices to both business and IT stakeholders.
• Requires comprehensive knowledge of the systems development life cycle, client area functions and systems, and technological alternatives for systems applications program development.
• Strong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices.
• Expertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect).
• Knowledge of cryptographic practices, encryption protocols, and PKI management.
• Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP).
• Familiarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus).
• Understanding of DevSecOps practices, including securing CI/CD pipelines.
• Paid time off (vacation, holidays, sick leave).
• Medical, dental, and vision insurance.
• 401(k) available for eligible employees.
• Participation in long-term incentive programs.
Hyperativa
Affirm
Allstate
GitLab
Get handpicked remote jobs straight to your inbox weekly.