Application Security Architect
EpiqAbout the role
It's fun to work at a company where people truly believe in what they are doing!
Job Description:
Position Overview
In this role, you will be a part of the Product Development Operations (DevOps) Team and work cross-functionally to ensure security is built and automated into every application we develop in our proprietary suite. You will lead the definition of application security standards and work with Product Development to ensure we are complying with the best practices set forth by the CISO and the 3rd party vendors used for security compliance.
You will perform product security assessments including secure code review, pen testing and general security consulting to proactively build security controls. You will lead compliance remediation efforts to completion.
This role will require you to assist and enable development teams to follow secure development practices, while also empowering them to own security within their product area. You will lead these initiatives with the assistance of Dev Sec Ops resources.
Responsibilities
- Champion application security by partnering with application development and security operations teams to drive a security-first mindset for all applications, APIs, and cloud implementation.
- Engage in the initial requirements definition (including analysis of threats and risks and alignment with security, Engineering, IT and Architecture standards) and validation
- Consult with development and operations teams to provide guidance and recommend secure design patterns and secure Development Lifecycle methodologies
- Perform security assessments on new and existing applications and cloud-based services to identify security risks and establish baseline security requirements
- Establish and drive security standards across the Epiq landscape to improve cybersecurity and resiliency of software architecture and the infrastructure it resides on.
- Act as SME for application security initiatives among developers and architects
- Automate security tools and processes ensuring innovation and advancement strategies that keep pace in the areas of access control, security-in-depth, secure coding practices for web applications and API
- Present security risks to Product Development and IT leadership and influence cybersecurity strategy and direction
- Coordinate and lead analysis exercises in conjunction with other IT leaders; and plan the resolution of any identified vulnerabilities/issues
- Manage and prioritize and act on Security Work Item backlog related items as they pertain to Critical, High, Medium, and Low vulnerability
Qualifications & Characteristics
- Bachelor's Degree in computer science, computer engineering, information systems, or related field. Or related experience as it pertains to job history.
- 3 – 5 years application security, security engineering or information security experience
- 5+ years of preferred experience in software development, ideally automating tools and processes
- Experience performing security design reviews for complex applications, including distributed systems, APIs, and services deployed to cloud and on-premises environments.
- Experience with the OWASP Top 10, SANS Top 25 programming errors and other common vulnerabilities and exploit techniques
- Experience defining and implementing security controls and measures across multiple disciplines, including web application, network, and operating systems security
- Deep understanding of common application and network protocols, cryptographic technologies, and authentication and authorization protocols
- Experience supporting cloud operational models, including, IaaS, SaaS security architecture, microservices, containerization
- Experience with account security and best practices in regards to the setup and policy creation of IAM, network traffic, public and private accessibility, WAF, Azure and AWS storage encryption, logging and monitoring.
- Strong leadership, interpersonal, negotiation and communication skill set with demonstrated ability to communicate effectively at a leadership level.
Knowledge and Exposure to:
- Cloud based Network, Database and Storage security. (AWS, Azure)
- SOC2 and other Audit Risk and Compliance protocols.
- SAST, DAST, SCA, IAST.
- PowerShell/Linux shells.
- Windows and Linux operating systems.
- Programming languages - .NET, Python and Java.
- Ansible, Terraform automation tools
- GitHub/VSTS/AZDO
- CI/CD.
- Cloud technologies (Azure/AWS.)
- Solid application to networking/infrastructure knowledge.
- 3rd Party scanning and pen testing software (Examples: Veracode, Whitesource, GitHub, Lacework)
Nice to Have:<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s