
Application Security Architect
- Shelton, CT
- Permanent
- Full-time
- Application Security Assessments: Conduct and ensure the completeness, quality and consistency of software application security assessments. Ensure that SAST, DAST and other application security tools achieve secure outcomes. You are responsible for the validation of penetration testing or other business logic threats, and remediation guidance.
- Education & Collaboration: Educate and inform technical and non-technical teams on secure coding, threat modeling utilizing frameworks like STRIDE, and other security awareness focuses across a range of developer skill levels.
- Team Guidance & Training: As senior technical lead, you will provide supervision, technical guidance, and mentorship to members of the security team, including engineers and analysts. They may also be responsible for leading security awareness training programs for the wider organization to foster a security-conscious culture.
- Communication & Reporting: Effective communication is crucial. You will regularly convey vital information regarding application security posture, emerging threats, strategic needs, project priorities, identified risks, and architectural decisions to diverse audiences, including upper management, business stakeholders, and technical implementation teams. This includes meticulous documentation of architectures, policies, standards, and procedures.
- Bachelor's in Computer Science or related field required.
- 8 or more years in Information Security, with a focus on application security, enterprise security and design.
- Proven ability to develop and implement comprehensive security strategies.
- Extensive experience in application security and secure coding techniques and strategies.
- Significant experience in AI software development and GenAI SDLC transformation strategies.
- Deep understanding of software development threat modeling and threat assessments.
- Experienced in validation of penetration testing reports and ensuring remediation.
- Proficient in various programming languages (C#, Python, JavaScript, etc.).
- Proficient in DevOps, CI/CD and system orchestration and automation technologies.
- Cloud Security: Strong knowledge of major cloud platforms (Amazon Web Services - AWS, Microsoft Azure, Google Cloud Platform - GCP) and their specific security features and services is essential. An understanding of frameworks like the NIST Cloud Computing Reference Architecture is preferred.
- Excellent communication and interpersonal skills, with the ability to effectively communicate with technical and non-technical stakeholders.
- Strong leadership and management skills, with the ability to motivate and inspire a team.
- Strong analytical and problem-solving skills.
- Indirectly influence -Ability to use negotiation and persuasion to build consensus and gain cooperation.
- Proactively identifies problems/risks for all domain in a project and communicates these issues early to help course-correct.
- Expert in their domain.
- Collaborates on a project level.
- Insurance Plans (Medical/Life)
- 401K
- Competitive Bonus
- Mobility Allowance
- Tuition Reimbursement
- Company Holidays
- Volunteering time
- And Many More…..