Sr. Application Security Architect
$143.4k - $189.1kWex Health
Job Summary Wex, Inc. is looking for a Sr. Application Security Architect with broad software development and application security experience. This individual would be responsible for designing, guiding, and assessing security solutions in software projects to ensure that security is built in from the beginning. With the assistance of tools including SAST, DAST and SCA, perform assessments of software projects to identify security issues and guide teams to effective remediations. About Us WEX is a global leader in financial technology solutions, based in Portland, Maine, United States, with over 6,000 WEXers distributed in over 40 countries. We simplify the complexities of payment systems across continents and industries like Fleet, Corporate Payments, and Benefits. We look to manage employee benefits, streamline how companies pay and get paid by suppliers, save on fuel costs, or modernize how companies manage their fleet, WEX solutions reduce the administrative burdens. Who Are We? We're the Global Product Security Team at WEX, responsible for enabling a modern and effective Secure Software Development Lifecycle throughout WEX.. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high-standard and we collaborate closely with one another to ensure strong, reliable and effective relationships. We own our results and we take pride of ownership in everything we do. We need help! Changing the world isn't easy, and we have a lot of work ahead of us. From securing applications, data centers and cloud resources, we've got more work than we can handle and we're looking for great people to come along for the ride. Who are you? Culturally, you're:
- A highly motivated security architect who loves working on small, high performing teams that interface with the entire enterprise
- A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion
- Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks
- Comfortable balancing the need to move fast with the realities of working in a highly regulated organization
- Passionate about security, but pragmatic about delivering business value
- Customer focused - whether it's internal teams that we're supporting or the WEX partner, you prioritize ensuring they have a great experience with WEX and our team
- A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight
- A strong leader who builds consensus and drives change through buy-in and education rather than mandates
- Work closely with development teams on securing Wex's applications
- Able to mentor other engineers & architects on your team and other teams both technically and professionally
- Champion of a shift-left and DevSecOps approach to security, but tenacious enough to build such a program from the ground up
- A lifelong learner that is excited by new technologies and challenges
- Are a Subject Matter Expert in software development and software security, particularly with web applications, APIs, mobile apps and enterprise applications delivered in a SaaS model.
- Provide leadership and help shape the WEX application security program and strategy
- Have a deep understanding of web application attacks and mitigations
- Think strategically about and research the latest trends in identity management, software attacks and mitigations
- Mentor and lead threat modeling sessions, focused primarily on teaching others to effectively practice effective and lightweight threat modeling
- Train other team members in risk based analysis of issues uncovered in manual and automated secure code reviews, and commercial static and dynamic application security scanning tools (SAST, DAST, SCA, etc)
- Do web application and mobile app penetration testing
- Deliver actionable security guidance to project teams
- Lead Security Development Lifecycle efforts, coordinating other security architects, security champions and project teams in performing secure architecture reviews, secure code reviews, threat models and penetration testing through the software development lifecycle;
- Keeps abreast of security industry best practices and OWASP recommendations utilizing knowledge to contribute to remediation efforts across the platform, as well as security policies and procedures;
- Actively identify and collaborate with security champions in the development and engineering organization to scale security expertise and awareness.
- Write and oversee the creation of application security standards and guidelines and assist in the implementation of these standards across the organization
- Deep experience working with compliance and regulatory frameworks such as PCI-DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc.
- Have 8+ years of progressive experience in software development and software architecture
- Have 3+ years experience with software security or information security
- Have 3+ years experience with application and container security tools such as SAST, DAST, SCA, IaC scanning and container image scanning, including integrating them to build and ticketing tools.
- Are an expert at identifying, exploiting and mitigating common application security issues, ie OWASP Top10,
- Are an expert at customer identity and related technologies, including OpenID Connect, OAuth 2.0, SAML 2.0
- Are able to troubleshoot security issues within a complex on-prem and multi-cloud environment
- A degree in Business, Computer Science or equivalent combination of education and relevant experience.
- Have experience working closely with many teams across departmental and business unit boundaries and can effect change in such complex environments
- Can commit and deliver on very specific project/delivery timelines with minimal supervision
- Have excellent communication skills, both written and verbal
- Security certifications such as CISSP, CEH, OSCP, GWAPT or similar and cloud certifications
- Have an understanding of modern CI/CD approaches and tooling, preferably with multiple toolsets such as Azure DevOps, GitHub Actions, Jenkins and others
- Hands on experience with IAM tools like Okta, Auth0, Ping or similar
- Experience with designing and securing container technologies - Kubernetes, Docker, EKS, ECS, AKS, service mesh
- Experience with infrastructure as code (Terraform, CloudFormation, ...) and automation
- 3+ years of cloud hosted applications and public cloud experience (IaaS, PaaS, FaaS, SaaS)
- Experience working on agile teams
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. Application Security Architect in United States vacancy
- ...Senior Application Security Architect We are seeking a highly skilled and experienced Senior Application Security Architect to join our team. In this role, you will be part of the Product Security organization within ADP's Global Security Organization (GSO), which...Senior
- ...Sr. Application Security Architect Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Application Security Architect for a Contract assignment with one of our premier Regulatory clients in New York, NY, Tysons, VA, Woodbridge, NJ or Rockville, MD...SeniorContract work
- ...About Our Team This position is for a Senior Software Security Architect in the Security Center of Excellence for PC and Smart... ...and security professionals - assessing and securing Lenovo applications and devices. You will work with multiple development teams...SeniorLocal areaHome office
$140.5k - $205k
Bank of America is looking for an experienced professional to analyze, design, and deliver secure application security solutions. This role requires 5+ years in application security and knowledge of relevant laws and regulations. The ideal candidate will have strong analytical...Senior- A leading waste management solutions provider is seeking a Principal Application Security Engineer to define and implement application security strategies. This hybrid role involves leading efforts in secure design and development throughout the software lifecycle and...Senior
- ...tech firm located in Pontiac, Michigan, is seeking a Senior Security Architect. The role involves securing enterprise information,... ...enhancing team capabilities. Candidates should have experience in application security or DevSecOps along with a proven ability to support...Senior
- A leading material handling equipment company in Ohio is seeking a Security Architect to define security standards, assess risks for applications, and collaborate with teams to ensure secure design principles. The ideal candidate has a Bachelor's degree in a related field...Senior
- \u00a0 Join the Clean Energy Revolution Become an Application Security Architect, Senior Advisor at Southern California Edison (SCE) and build a better tomorrow. In this job, you will design and oversee security, compliance, solution delivery, for SAP cloud (...SeniorFull timeRemote workRelocation
$120k - $175k
...technologies in support of U.S. National Security and Defense. For the past forty-five... ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will... ..., CO office for an Application Security Architect with experience in the Software Development...SeniorTemporary workFor contractorsWork experience placementWork at officeImmediate startRemote workFlexible hours- A technology company based in Michigan is seeking a Senior Security Architect to secure enterprise information by determining security requirements... ...systems. The ideal candidate will have experience in application security and DevSecOps, as well as a strong understanding...Senior
- A leading consulting firm in Pennsylvania is seeking a Lead Consultant specializing in Application Security with a minimum of 10 years of experience in IT security. The role requires proficiency in vulnerability scanning tools and the ability to manage customer relationships...Senior
- ...infrastructure team and help support a secure, scalable, and user-friendly computing environment... ...next-generation AI and machine learning applications, particularly in the domain of... ...Responsibilities: Security Architecture & Design: Architect and define security features for the AI...SeniorFull time
- Position: Principal Application Security Architect Gen AI Location: Charlotte, NC / Dallas, TX / Columbus, OH / Chandler, AZ Duration: 12 months Job ID: 176330 Only W2 Job Description: Overview: ~Client is seeking a highly skilled and experienced Application...Full time
- ...Technologies, we are excited to announce a new opening for a dedicated security architect in our dynamic team. You will lead the implementation of a... ...OT security standards. Familiarity with security standards applicable to industrial and critical infrastructure environments (e.g....SeniorWork experience placementRemote work
- ...Responsibilities: Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses. Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities...Remote work
$160k - $180k
...AVD transformation that Microsoft and Nerdio are leading, then we want to speak with you. Nerdios growing security team seeks an Application Security Architect to help us enhance the security of our cutting-edge applications. Partnering closely with our engineering and...Remote workFlexible hours- ...Title : Security Architect Location : Rockville, MD or McLean, VA Target Start Date : ASAP Type : contract... ...Information Security organization. This role will focus heavily on application security, security engineering, and enterprise security...Contract workImmediate startRemote work
$116k - $190k
...want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Application Security Architect to join our team in Boston, Massachusetts (US-MA), United States (US). The NTT DATA Services Security Analysis...Contract workTemporary workWork experience placementWork at officeRemote workFlexible hours- ...Application Security Architect Application Security Secure Development is seeking an application security architect to threat model applications, services, and platforms. A successful candidate will: Engage and collaborate with application, service, and platform...Work experience placement
$116k - $190k
...Application Security Architect NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking an Application...Contract workTemporary workWork experience placementFlexible hours- ...Looking for a PeopleSoft Application Security Architect for an on-going project starting within 2-3 weeks. There may be an occasional trip or two to Tallahassee for work sessions but the majority of the work and maybe all will be remote. Trips in would be paid by the...Remote work
$157.5k - $175k
...Job Title: Application Security Architect Area: Technology Services & Information Security Reports to: Security Officer Classification: Exempt Location: Evanston, IL This position is designated as Hybrid - Fully Flexible and expected to work from...Work at officeRelocation packageFlexible hours- ...business by analyzing the data, scale and support digital transformation initiatives. Job Description Established Application Security Architect with at least 10 years within the broader IT Security disciplines and technologies. At least 7-8 years Application...
- ...Application Security Architect Client needs contractor well versed with design and development with IDM product. DES has procured Optimal IDM(OIDM) for authorization security. DES has over 30 existing applications. SCUBI (Southeast Consortium Unemployment Benefits...For contractors
- ...Application Security Architect Boston, MA – Local Candidates, First Preference Hybrid Onsite 3 Days (Tues-Thurs Onsite) 6 Months With Possible Extension We are hiring for an experienced Senior Application Security Architect. Must have the following background...Local areaRelocation
- ...Key Responsibilities: Conduct comprehensive architecture reviews of new software applications to identify security risks, propose mitigation strategies, and ensure alignment with security best practices. Perform Security Risk and Assessments (SRA) for critical...
- ...Responsibilities The Application Security Architect partners with software development, platform, cybersecurity, and cloud engineering teams to embed security throughout the modern software development lifecycle (SDLC). This role focuses on secure-by-design...Temporary workLocal areaWorldwideFlexible hoursShift work
- ...Application Security Solution Architect Denver, Colorado;Washington, District of Columbia; Chicago, Illinois To proceed with your application, you must be at least 18 years of age. Acknowledge ( Bank of America employees are required to meet all posting eligibility...Work at officeShift workDay shift
$128.4k - $192.6k
...communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through... ...the future-you'll create it. We are seeking an Application Security Architect to secure the design, development, integration, and operation...Full timeTemporary workWork at officeLocal areaRelocation- ...Sr. Information Security Architect – AI & Cloud Security Washington, District of Columbia;Chicago, Illinois; Denver, Colorado To proceed with your application, you must be at least 18 years of age. Acknowledge ( Bank of America employees are required to meet...SeniorWork at officeShift workDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Application Security Architect. Be the first to apply!
Related searches
- .net software architects (remote) United States
- software architect United States
- senior software architect United States
- principal software architect United States
- application security architect United States
- application architect United States
- remote software architect United States
- cyber security architect United States
- cloud security architect United States
- aws security architect United States

