Architect, Information Security - DevSecOps/Application Security in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Architect, Information Security – DevSecOps/Application Security based in the United States.
This role is an opportunity to shape application security architecture and governance across a large, complex technology environment.
You will help development and engineering teams build security into applications from design through deployment.
The position combines hands-on security expertise with architecture, risk management, and cross-functional collaboration.
You will champion a shift-left DevSecOps approach by embedding effective security controls throughout the SDLC.
The role also focuses on secure design patterns, software supply chain risk, cloud-native applications, APIs, and CI/CD security.
You will act as a trusted security advisor and subject matter expert, helping teams turn technical risks into practical business decisions.
This is a high-impact opportunity to strengthen security maturity while enabling teams to deliver software securely and at scale.
- Partner with application, development, solution architecture, DevOps, and security teams to assess and manage application security risks across design, development, testing, and deployment.
- Conduct and support threat modeling, secure design assessments, and architecture reviews for applications, APIs, and cloud-native environments.
- Define, document, and promote secure architecture patterns, guardrails, reusable controls, and security requirements aligned with organizational AppSec standards.
- Guide teams in integrating and effectively using application security testing technologies, including SAST, DAST, and SCA, within CI/CD pipelines.
- Support the implementation and enforcement of security requirements, standards, and control gates throughout the software development lifecycle.
- Identify application and software supply chain security gaps and collaborate with engineering teams to develop practical, prioritized risk mitigation strategies.
- Track vulnerabilities, security exceptions, and risk acceptances in accordance with established governance and risk management processes.
- Collaborate with Security Champions and development teams to increase application security awareness, adoption, and overall maturity.
- Contribute to AppSec education, training, awareness, and enablement programs that strengthen secure development practices.
- Serve as a subject matter expert on application security, secure software development, and DevSecOps practices, providing guidance across technology initiatives.
- 3+ years of professional experience in application security, software security, DevSecOps, or a closely related discipline.
- Strong knowledge of secure SDLC methodologies, threat modeling, secure architecture, and secure-by-design principles.
- Hands-on familiarity with application security testing tools and methodologies, including SAST, DAST, and software composition analysis (SCA).
- Solid understanding of the OWASP Top 10, API security vulnerabilities, application security risks, and secure coding practices.
- Familiarity with CI/CD pipelines, DevOps practices, and common development and deployment tooling.
- Ability to assess technical security issues and clearly translate risks, potential business impact, and remediation options for both technical and non-technical stakeholders.
- Strong analytical, problem-solving, communication, and collaboration skills, with the ability to influence development teams and security stakeholders.
- Experience working within governance frameworks and translating security standards into practical engineering controls is highly valuable.
- Preferred certifications include CISSP, CISM, CCSP, or an equivalent information security credential.
- Experience implementing or aligning application security programs with frameworks such as OWASP SAMM or NIST SSDF is preferred.
- Experience leading AppSec or DevSecOps transformation initiatives, security maturity programs, or enterprise-wide security improvements is an advantage.
- Competitive annual compensation range of $72,370.82–$156,803.45, with actual compensation varying based on geographic location, experience, education, and skill level.
- Comprehensive benefits and compensation package.
- Full-time opportunity with a U.S.-based position.
- Opportunity to influence application security architecture, governance, and DevSecOps practices across a complex technology environment.
- Exposure to modern application security, cloud-native technologies, APIs, CI/CD, software supply chain security, and secure development practices.
- Opportunity to collaborate with engineering, architecture, DevOps, and cybersecurity professionals while contributing to enterprise-wide security maturity.
- Equal opportunity workplace committed to fair consideration of qualified candidates.