Apolis logo

Sr. Application Security (AppSec) Architect

Apolis

  • Maryland Heights, MO
  • 8 days ago
  • $60–$68 Per Hour

Highlights

This role focuses on threat modeling, security architecture reviews, secure design assessments, Secure SDLC, DevSecOps, API security, and cloud security while collaborating with enterprise architects, developers, DevOps teams, and business stakeholders. The ideal candidate will lead Secure-by-Design initiatives across enterprise applications by embedding security throughout the Software Development Lifecycle (SDLC).

Numbers & Facts

LocationMaryland Heights, MO
IndustryComputer/IT Services
Salary$60–$68 Per Hour
Company Size500 to 999 employees
Websitehttps://www.apolisrises.com/

Description

Job Title:Sr. Application Security (AppSec) Architect

Location:Onsite Maryland Heights, MO

Tax Term (W2, C2C):W2

Job Type (Permanent/Contract):Contract

Duration:Long Term

Description:

We are seeking an experienced Sr. Application Security (AppSec) Architect with 10+ years of experience in Cybersecurity, Application Security, or Security Architecture. The ideal candidate will lead Secure-by-Design initiatives across enterprise applications by embedding security throughout the Software Development Lifecycle (SDLC). This role focuses on threat modeling, security architecture reviews, secure design assessments, Secure SDLC, DevSecOps, API security, and cloud security while collaborating with enterprise architects, developers, DevOps teams, and business stakeholders.


Role and Responsibilities:

Secure-by-Design Leadership

  • Define and implement Secure-by-Design principles across application development programs.
  • Develop security reference architectures, reusable security patterns, and architecture standards.
  • Embed security requirements into solution design and development processes.

Threat Modeling & Risk Analysis

  • Conduct threat modeling workshops using STRIDE, Attack Trees, or similar methodologies.
  • Identify trust boundaries, attack surfaces, abuse cases, and potential design weaknesses.
  • Provide risk-based mitigation recommendations and architectural guidance.

Security Architecture Reviews

  • Perform application, API, microservices, cloud-native, and AI-enabled application security reviews.
  • Validate architecture compliance against OWASP ASVS, OWASP Top 10, NIST SSDF, and organizational standards.
  • Review data flows, authentication, authorization, encryption, secrets management, and logging controls.

Secure SDLC & DevSecOps

  • Integrate security requirements into Agile and CI/CD workflows.
  • Collaborate with development teams to implement security-by-default controls.
  • Support adoption of SAST, DAST, SCA, API Security, Container Security, and Secure Coding practices.

Developer Enablement

  • Provide secure coding guidance and architectural consultation.
  • Conduct architecture review sessions, threat modeling training, and security awareness workshops.
  • Act as a trusted advisor to engineering and product teams.

Governance & Stakeholder Management

  • Partner with Enterprise Architects, Product Teams, Security Leadership, and Development Managers.
  • Define security acceptance criteria and architecture review processes.
  • Present security findings, risks, and remediation strategies to senior leadership.

Required Skills:

  • Application Security Architecture
  • Secure-by-Design Methodologies
  • Threat Modeling
  • STRIDE
  • Attack Trees
  • PASTA
  • OWASP ASVS
  • OWASP Top 10
  • NIST SSDF
  • Secure SDLC
  • DevSecOps
  • Security Architecture Reviews
  • Secure Coding Practices
  • API Security
  • Web Application Security
  • Microservices Security
  • Cloud-Native Security
  • Cloud Security
  • AWS Security
  • Microsoft Azure Security
  • Google Cloud Platform (GCP) Security
  • Authentication
  • Authorization
  • Encryption
  • Secrets Management
  • Logging & Monitoring
  • SAST
  • DAST
  • Software Composition Analysis (SCA)
  • Container Security
  • Kubernetes Security
  • Docker Security
  • CI/CD Security
  • GitHub Actions
  • Azure DevOps
  • Jenkins
  • GitLab CI/CD
  • Security Governance
  • Risk Assessment
  • Security Architecture
  • Enterprise Architecture
  • Secure Design Reviews
  • Security Standards
  • Agile Methodology

Qualifications:

  • 10+ years of experience in Cybersecurity, Application Security, or Security Architecture.
  • 5+ years leading security architecture reviews and threat modeling engagements.
  • Demonstrated expertise implementing Secure SDLC and DevSecOps programs at enterprise scale.
  • Strong experience with Secure-by-Design methodologies.
  • Hands-on experience conducting threat modeling using STRIDE, Attack Trees, PASTA, or similar methodologies.
  • Expertise with OWASP ASVS, OWASP Top 10, and NIST SSDF.
  • Experience reviewing application, API, cloud-native, and microservices architectures.
  • Strong understanding of authentication, authorization, encryption, secrets management, and secure coding.
  • Experience working in regulated industries such as Financial Services, Banking, Insurance, or Healthcare.
  • Excellent communication, leadership, and stakeholder management skills.

Preferred Certifications:

  • CISSP
  • CSSLP
  • CCSP
  • SABSA
  • AWS Security Certification
  • Azure Security Certification
  • Google Cloud Security Certification
  • GIAC GWEB
  • GSEC
  • Certified Secure Software Lifecycle Professional (CSSLP)

Benefits

Paid Sick Days, Employee Referral Program, Employee Events, Retirement / Pension Plans

About Company

Since 1996, RJT has provided successful SAP, Oracle, and IT consulting solutions and staffing services to clients around the world. The new Apolis brings you the same personalized service fortified with a greater array of IT solutions, global expertise, and cost-management strategies.

We are a global IT consultancy that seamlessly integrates experts and leading-edge solutions into your organization so you can focus on what really matters.

Similar Jobs

See more jobs