HamburgerMenu
hirist

Application Security Architect - SAST/DAST

Sourcebae
8 - 12 Years
Multiple Locations

Posted on: 01/09/2026

Job Description

Application Security Architect

Work Mode: Remote

Shift: 4:30 PM - 2:30 AM IST

About the Role:

We are looking for an experienced Application Security Architect to join our dedicated security team supporting US-based stakeholders. The ideal candidate will have strong hands-on experience in Application Security, Security Architecture, Threat Modeling, Secure SDLC, and DevSecOps.

This is an architecture and security assessment-focused role, requiring a strong attacker mindset and the ability to identify application risks, recommend secure design solutions, and work closely with engineering and architecture teams to drive remediation.

Key Responsibilities:

- Conduct application security assessments across web applications, APIs, mobile applications, and enterprise platforms.

- Perform security architecture and design reviews and provide recommendations throughout the solution lifecycle.

- Conduct threat modeling, attack surface analysis, data-flow analysis, and abuse-case analysis.

- Identify and assess application security vulnerabilities and potential attack paths.

- Review authentication, authorization, session management, API security, encryption, secrets management, and secure integration patterns.

- Apply OWASP Top 10, OWASP ASVS, and OWASP API Security Top 10 principles to application security assessments.

- Support and enhance Secure SDLC and DevSecOps practices.

- Integrate and support security controls and testing tools within CI/CD pipelines.

- Work with development, infrastructure, enterprise architecture, and cybersecurity teams to prioritize and remediate security risks.

- Translate technical findings into risk assessments, security requirements, architectural recommendations, and remediation roadmaps.

- Support vulnerability management and application security testing activities.

- Apply penetration testing and red-team methodologies from an attacker's perspective, while this role is not primarily a penetration testing position.

Required Skills & Experience:

- 8 - 12 years of overall experience in Cybersecurity/Application Security, including 4+ years of hands-on Application Security, Security Assessments, and Security Architecture experience.

Tech Stack:

- Application Security / AppSec

- Threat Modeling

- Security Architecture

- OWASP Top 10 / ASVS / API Security Top 10

- Secure SDLC / DevSecOps

- SAST, DAST, SCA, API Security, vulnerability scanning, and secrets scanning tools.

Common Application Vulnerabilities:

- Broken Authentication, Broken Access Control, Injection, Insecure APIs, Session Management Issues, Cryptographic Weaknesses, Security Misconfigurations.

The job is for:

May work from home
info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...