
Lead Application Security Architect
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Spain.
• Develop and uphold security architecture standards, policies, and frameworks for enterprise applications, platforms, and cloud-native environments.
• Create and implement secure design patterns, reference architectures, and architecture decision records focused on application security.
• Facilitate security architecture reviews for both new and existing applications utilizing frameworks like OWASP, NIST, and SANS.
• Embed zero-trust principles and defense-in-depth strategies into application architecture.
• Establish and maintain enterprise application security requirements while generating performance metrics.
• Lead threat-modeling sessions and offer actionable remediation recommendations.
• Advocate for secure coding standards and developer security enablement initiatives.
• Assess security requirements and design solutions that address enterprise risk and regulatory compliance.
• Effectively communicate architecture designs, risk evaluations, and remediation strategies to both technical and non-technical stakeholders.
• Manage security design reviews and approval workflows among security, engineering, and enterprise architecture teams.
• Contribute to the roadmap for application security strategy and suggest program improvements.
• Provide mentorship to junior security engineers, developers, and architects.
• Spearhead cross-functional security projects and facilitate secure development training and awareness initiatives.
• Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related discipline; equivalent experience will be taken into account.
• Over 7 years of experience in information security, emphasizing application security engineering, secure software development, or security architecture.
• In-depth knowledge of OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns.
• Proven experience in designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads.
• Strong expertise in DevSecOps practices and tools: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration.
• Familiarity with NIST CSF, NIST SP 800-53, ISO 27001, and principles of zero-trust architecture.
• Working knowledge of IAM, OAuth 2.0/OIDC, as well as application-layer authentication and authorization controls.
• Understanding of cryptography, data protection, encryption, and Public Key Infrastructure.
• Acquainted with STRIDE, PASTA, or similar threat-modeling methodologies.
• Capability to analyze complex application architectures and convert security requirements into actionable design solutions.
• Ability to independently lead security assessments, architecture reviews, and cross-functional security initiatives.
• Relevant certifications such as CSSLP, CISSP, AWS/Azure Security Specialty, OSCP, or equivalent are preferred.
• Knowledge of OWASP GenAI, LLM Top 10, Security Exchange, and AI Exchange is advantageous.
• Flexible remote work arrangement.
• Commitment to equal opportunities for all genders.
• Reasonable accommodations provided for individuals with disabilities.
• Mentorship and professional growth through secure development training and awareness programs.
VMD Corp
GR8 Tech
Modern Health
Accumulus Technologies
Get handpicked remote jobs straight to your inbox weekly.