Application Security Architect

The Custom Group of Companies

New York, NY

JOB DETAILS
SALARY
$160,000–$200,000 Per Year
SKILLS
Analysis Skills, Application Programming Interface (API), Applications Security, Best Practices, Communication Skills, Computer Engineering, Computer Science, Computer Security, Cross-Functional, Establish Priorities, Internet Security, Java, JavaScript, People Management, Programming Languages, Python Programming/Scripting Language, Risk Analysis, Risk Management, Secure Coding, Security Architecture, Security Attacks, Software Development Lifecycle (SDLC), Standards Development, Team Player, Threat Modeling
LOCATION
New York, NY
POSTED
30+ days ago
Responsibilities:
  • Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses.
  • Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities.
  • Drive threat modelling as a standard part of the SDLC, and develop and maintain threat models for critical applications, identifying potential security risks and proposing mitigations.
  • Drive the Security Champions program, and define and promote secure coding practices, patterns, and standards across development teams.
  • Conduct security reviews and provide guidance on security requirements for new features and projects.
  • Assist in the analysis, selection and rollout of new application security tools, processes, and standards.
  • Stay up to date with the latest security threats, vulnerabilities, and industry best practices.

Requirements:
  • Proven experience in application security with a focus on application security testing and vulnerability management.
  • Hands-on experience with Application Security tools.
  • Strong understanding of common application vulnerabilities (e.g., OWASP Top 10) and mitigation techniques.
  • Experience with threat modelling methodologies and tools.
  • Proficiency in at least one programming language (e.g., Java, Python, JavaScript).
  • Excellent communication and collaboration skills, with the ability to work effectively in cross-functional teams.
  • Strong understanding of risk management.

Professional qualifications/certifications
  • Degree in technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
  • Relevant security certifications (e.g., CISSP, CEH, CSSLP) or equivalent is preferred.

About the Company

T

The Custom Group of Companies