
AVP, Cyber Application Security Architect
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in New Jersey.
• Act as the security architecture authority within the architecture organization.
• Collaborate with product architects, principal engineers, cloud partners, and business leaders to integrate secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure.
• Mentor and assist developers in writing secure code and employing secure patterns, frameworks, and libraries.
• Offer architectural, implementation, and operational guidance while advocating for secure-by-default methodologies.
• Analyze SAST, SCA, DAST, container, and IaC scanning results; confirm and address false positives; and assist in prioritizing genuine risks.
• Optimize security tools to minimize noise and enhance signal quality through rules, suppressions, baselines, and exception processes.
• Promote the adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry.
• Perform Secure by Design assessments for new applications and significant modifications.
• Facilitate threat modeling workshops, pinpoint abuse cases and attack vectors, and document mitigations alongside residual risks.
• Evaluate authentication/authorization processes, data flows, secrets management, logging/monitoring, and resiliency measures.
• Provide suggestions and monitor implementation with engineering teams.
• Convert FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, and SOX requirements into actionable security architecture controls.
• Counsel on CI/CD pipeline hardening, least privilege access, artifact integrity, signing, provenance, and secure deployment strategies.
• Advise on third-party dependency security, supply chain controls, SCA governance, and patch/vulnerability management.
• Embed security controls into developer workflows through automation and self-service solutions.
• Provide security architecture counsel for AI/ML and GenAI-enabled applications.
• Assist in implementing data protection, access control, monitoring, and abuse-prevention measures for AI/ML functionalities.
• Serve as a trusted partner to product, engineering, and leadership teams.
• Develop and maintain secure coding guidelines, reference architectures, and reusable patterns.
• Contribute to incident root cause analysis and proactive design enhancements.
• Over 8 years of relevant IT experience.
• More than 5 years of experience with security application tools.
• At least 6 years of experience in conducting application security reviews of new architectures.
• Over 5 years of experience working in public and hybrid cloud environments (AWS, Azure, and GCP).
• Strong background in software development with the ability to read, comprehend, and provide guidance on production code and design choices.
• Proven expertise in threat modeling and secure architecture reviews for modern web and API-based applications.
• Proficient in securing CI/CD and SDLC processes, including pipeline security, secrets management, artifact integrity, build/release controls, and automation.
• Familiarity with application security tools and processes, including SAST/SCA/DAST and related scanning in pipelines.
• Working knowledge of AI/ML security risks and mitigations for applications utilizing ML models or GenAI components.
• Strong collaborative and consulting abilities; capability to influence without authority, communicate effectively, and deliver practical, developer-friendly recommendations.
• Bachelor's Degree.
• Comprehensive health coverage.
• Retirement savings plan with company match.
• Opportunities for professional development and training.
• Flexible work environment and remote work options.
• Employee wellness programs and initiatives.
Reli Group
Second Nature
ASRC Federal
Kyndryl
Get handpicked remote jobs straight to your inbox weekly.