Skip to main content
CareerCircle Home
Log in
Join
Search for and find Sr Application Security Architect jobs and TEKsystems jobs at CareerCircle.com
TEKsystems jobs, learn more at CareerCircle.com

Sr Application Security Architect

TEKsystems

Posted Monday, July 14, 2025

Posting ID: JP-005409569

Rockville, MD
Share:
FacebookTwitterLinkedin

Description

Overview The Senior Application Security Architect is responsible for designing, implementing, and overseeing enterprise-wide application security architecture and standards. This role focuses on establishing security frameworks, conducting architecture reviews, developing security baselines, and leading strategic security initiatives that have broad impact across the organization. The position requires a blend of technical expertise, architectural thinking, and leadership to embed security throughout the software development lifecycle. Job Responsibilities: • Design and establish enterprise application security architecture frameworks and reference models aligned with business objectives and risk tolerance • Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls • Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models • Create and evolve threat modeling methodologies (STRIDE, PASTA, OCTAVE) and facilitate threat modeling sessions with development teams • Define secure coding standards and security requirements for different application types based on data classification and risk profile • Architect security solutions for authentication, authorization, encryption, and secure communication channels • Establish security guardrails for cloud-native applications, serverless architectures, and infrastructure-as-code implementations • Design and implement API security strategies including OAuth/OIDC flows, API gateways, and rate limiting • Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives • Evaluate and recommend security tools and technologies for the enterprise security tech stack • Develop security architecture roadmaps and guide implementation of security capabilities • Partner with development teams to design secure solutions that balance security requirements with business needs • Lead strategic security initiatives with enterprise-wide impact • Leverage GenAI technologies to enhance security architecture reviews and automate security analysis • Maintain documentation of security architecture decisions, patterns, and reference implementations • Develop and deliver security architecture training to raise security awareness among developers and architects • Stay current with emerging security threats, technologies, and architectural approaches • Perform security design reviews for new applications and major changes to existing applications • Architect secure data handling practices including encryption at rest and in transit Qualifications: • Bachelor's degree in Computer Science, Information Security, or related technical field required • 5+ years of experience in application security, with at least 2 years in security architecture roles • Deep knowledge of secure design principles, threat modeling methodologies, and security patterns • Experience designing security controls for cloud environments (AWS, Azure, GCP) • Proficiency in evaluating and implementing application security tools (SAST, DAST, IAST, SCA) • Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, and other proxy tools • Experience with secure software development practices and DevSecOps implementation • Strong understanding of OWASP Top 10, SANS CWE, and other security standards • Knowledge of secure authentication mechanisms (MFA, SSO, OAuth 2.0, SAML, OIDC) • Experience with secure API design and implementation of API security controls • Knowledge of regulatory requirements (PCI-DSS, GDPR, SOX, etc.) and their architectural implications • Experience with containerization, microservices, and API security • Proficiency in one or more programming languages (Java, Python, JavaScript preferred) • Experience with secure code review techniques and identifying common vulnerability patterns • Knowledge of cryptographic protocols and implementations • Experience with security requirements for modern application architectures (SPA, serverless, etc.) • Excellent communication skills with ability to translate complex security concepts to technical and non-technical audiences • Experience leading cross-functional security initiatives and influencing stakeholders • Certifications such as CSSLP, CISSP, AWS Security Specialty are highly desirable This position requires a strategic thinker who can balance security requirements with business objectives while driving the organization toward a more secure application ecosystem.

Skills

Application security, Security architecture, Aws, GenAI, Threat Modeling

Top Skills Details

Application security,Security architecture,Aws,GenAI,Threat Modeling

Experience Level

Expert Level

Compensation:$70

Contact Information

Email: zrosenblatt@teksystems.com

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
On-Site
Communication
Leadership
Security Controls
Security Requirements Analysis
Security Strategies
Certified Information Systems Security Professional
Code Review
Programming Languages
Microservices
Python (Programming Language)
Java (Programming Language)
Software Development
Business Objectives
Computer Science
Sarbanes-Oxley Act (SOX) Compliance
Authentications
Microsoft Azure
Single Sign-On (SSO)
Application Programming Interface (API)
Amazon Web Services
CI/CD
Software Development Life Cycle
JavaScript (Programming Language)
Data Security
Authorization (Computing)
Generative Artificial Intelligence
General Data Protection Regulation (GDPR)
Dynamic Application Security Testing (DAST)
Application Security
Infrastructure as Code (IaC)
Containerization
Risk Aversion
Encryption
IT Security Architecture
Security Awareness
Security Patterns
Security Assertion Markup Language (SAML)
Payment Card Industry (PCI) Data Security Standards
DevSecOps
Vulnerability Management
Security Testing
Open Web Application Security Project (OWASP)
Secure Coding
Design Elements And Principles
Communications Security
Threat Modeling
Enterprise Security
Cloud-Native Applications
Serverless Computing
API Design
OAuth
Static Application Security Testing (SAST)
Burp Suite
Security Analysis
Rate Limiting
Data Classification
Certified Secure Software Lifecycle Professional
AWS Certified Security Specialty
Security Tools
Security Solutions
Octave

Blog