AVP, Cyber Application Security Architect
# AVP, Cyber Application Security Architect **EXL** · United States · `Remote` · `Full Time` 💼 **Уровень роли:** `Director` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Himalayas (JSON API)* --- ### Top Skills & Match 🎯 **Ключевой стек роли:** `[Security-Architect]` `[Cyber-Security-Architect]` `[Application-Security-Engineer]` `[Information-Security-Analyst]` `[DevSecOps-Engineer]` `[Application-Security-Architect]` `[AVP-Cybersecurity]` `[Director-Cloud-and-Application-Security-Solutions-Architect]` `[Application-Security-Director]` --- ### About the Role Principle Duties Developer enablement & secure coding support - Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure. - Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. - Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. - Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. - Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. - Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection. Secure by Design reviews - Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. - Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. - Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. - Provide clear, actionable recommendations and track follow-through with engineering teams. - Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment. CI/CD and SDLC security - Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. - Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. - Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. AI/ML security guidance - Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. - Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. Collaboration & communication - Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance. - Create and maintain secure coding guidance, reference architectures, and reusable patterns. - Support incident learnings by contributing to root cause analysis and preventative design improvements. Originally posted on Himalayas
- Security-Architect
- Cyber-Security-Architect
- Application-Security-Engineer
- Information-Security-Analyst
- DevSecOps-Engineer
- Application-Security-Architect
- AVP-Cybersecurity
- Director-Cloud-and-Application-Security-Solutions-Architect
- Application-Security-Director
Наблюдалась 2026-10-04, впервые 2026-10-04, источник — Himalayas (JSON API).