Sr. Architect - SRARCH

Ipolarity LLC

  • Saint Louis, MO
  • 6 days ago

    Highlights

    The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.

    Numbers & Facts

    LocationSaint Louis, MO

    Description

    Application Security (AppSec) Engineer
    ####
    Onsite - Maryland Heights, MO
    Cog Kit
    BGV must be cleared to start

    What are the top 3 skills required for this role?
    Application Security (AppSec)
    Secure SDLC / DevSecOps
    SAST, DAST, IAST, SCA
    Web, Mobile & API Security Testing
    Manual Penetration Testing & Business Logic Testing
    Threat Modelling
    Vulnerability Management
    Secure Code Review
    CI/CD Security Integration


    Job Description/ Responsibilities
    The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.
    The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.
    ________________________________________
    Key Responsibilities
    Application Security Engineering
    Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
    Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
    Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
    Enable continuous post-deployment security validation and risk monitoring.
    Security Testing & Validation
    Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
    Perform authenticated and unauthenticated security assessments of applications and APIs.
    Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
    Validate remediation effectiveness and secure deployment practices.
    DevSecOps Integration
    Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
    Automate vulnerability triage, prioritization, and remediation workflows.
    Develop security-as-code controls and policy enforcement mechanisms.
    Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
    Vulnerability Management
    Analyze findings from multiple security tools and eliminate false positives.
    Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
    Track remediation efforts through SDLC and release cycles.
    Develop security metrics, dashboards, and executive reporting.
    Developer Enablement
    Conduct secure coding reviews and developer education sessions.
    Establish security champions programs across engineering teams.
    Provide remediation guidance and hands-on support during application releases.
    Drive adoption of secure development standards and best practices.
    Cloud & API Security
    Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
    Secure REST, GraphQL, and microservice-based APIs.
    Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
    Support software supply chain security initiatives, including SBOM/SCA validation.



    8 15 years of experience in Application Security, DevSecOps, or Security Architecture.
    Experience securing large-scale enterprise applications across cloud and hybrid environments.
    Relevant certifications preferred:
    o CISSP
    o CSSLP
    o GWAPT
    o OSCP
    o CEH
    o Azure/AWS Security Certifications

    Similar Jobs

    GlobalPundits

    Teamcenter Architect

    • St. Louis, MO
    30+ days ago
    See more jobs