Principal Application Security Architect
Sallie MaeAbout the role
When you join Sallie Mae, you become a champion for all students.
We’re on a mission to power confidence as students begin their unique journey. To help them plan their higher education, successfully finish, and prepare for life after school. To help them Start smart. Learn big.
Students need guidance navigating this important time in their life. They need someone who acknowledges that their education path is unique. They need a partner willing to evolve and not only meet but surpass their expectations. We’re changing. Because students need a better way.
We’re looking for people who are excited to drive this transformation. To break barriers and think of new ways to adapt, help, and create better experiences for students—and for each other.
This is where diverse backgrounds, beliefs, and perspectives matter. It’s where you’re empowered to bring your authentic self to work.
Feeling your best allows you to do your best. Our benefits take care of the whole you—from physical and mental to financial and professional. You’ll get opportunities to further your education and career, support for you and your family (including your pets!), paid time off to volunteer for the things that matter to you, and more.
We’re obsessed with impact and making a real difference. For us, that means putting relationships first, asking “why not?” when tackling challenges, and continuously learning new skills.
Come do more than join something, change something. For students, for future generations, for the future of education.
What You’ll Contribute
The Principal Application Security Architect will be responsible for ensuring that security principles and best practices are embedded into the organization’s technology landscape.
What You’ll Do
- Develop and maintain enterprise-wide security architecture frameworks, standards, and guidelines.
- Lead the design and review of secure systems architecture for cloud, on-premise, and hybrid environments.
- Collaborate with application development, infrastructure, and operations teams to integrate security controls throughout the system development lifecycle.
- Lead adoption of Secure-by-Design by maintaining Shift Left application security quality gates with key DevSecOps stakeholders.
- Conduct security architecture assessments, threat modeling, and risk analysis for new initiatives and existing systems.
- Evaluate emerging security technologies and recommend solutions that align with enterprise security strategy.
- Collaborate with the legal and compliance teams to ensure adherence to relevant laws, regulations, and standards.
- Liaise with external vendors, auditors, and partners to assess and improve the organization's security posture.
- Lead hands‑on integration of application security and DevSecOps practices by working directly with development teams to embed secure coding standards, automated security controls, and risk‑based guardrails throughout the SDLC and CI/CD pipelines.
- Design and implement cloud and SaaS application security solutions across platforms such as AWS, Azure, Salesforce, Snowflake and enterprise SaaS tools, balancing regulatory requirements, risk management, and developer velocity in a highly regulated environment.
The above information is intended to describe the general nature and level of work performed by employees assigned to this job; it is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees in this role.
What You Have
Minimum: Indicate minimum education, skills and experience required.
- Strong knowledge of security architecture principles, frameworks, and best practices.
- Deep understanding of current security technologies, including network security, application security, cloud security, and identity and access management.
- Proven experience in conducting security risk assessments and developing risk mitigation strategies.
- Strong knowledge of industry standards and regulations.
- Exceptional analytical and problem-solving abilities, with a strategic mindset.
- Excellent communication and collaboration skills, with the ability to effectively interact with stakeholders at all levels of the organization.
- Must have recent agile application development and TDD experience.
- Demonstrated, hands‑on experience recommending and implementing secure coding practices, application threat modeling, and integration of security tooling into agile development workflows.
- Experience defining and operationalizing application security in cloud or SaaS environments, with the abili
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s