HamburgerMenu
hirist

Zensar Technologies - Application Security Risk Architect - SAST/DAST

Posted on: 19/09/2025

Job Description

Job Title : Application Security Risk Architect

Experience : 7 - 9

Job Description

Threat Modeling & Security Architecture Reviews (Primary Focus) :

- Lead threat modeling sessions using frameworks like STRIDE, PASTA, LINDDUN to identify risks and mitigations.

- Conduct security architecture reviews for new and existing applications (web, mobile, APIs, microservices, cloud-native).

- Analyze data flow diagrams, trust boundaries, and third-party integrations for attack vectors.

- Collaborate with solution architects to embed secure design principles and zero-trust models in architectures.

- Maintain a central repository of threat models and risk assessments for traceability.

Application Security & Vulnerability Management :

- Perform secure design and code assessments for critical applications.

- Support the SAST program (Checkmarx, Fortify, SonarQube), prioritizing findings linked to design flaws.

- Partner with developers to guide remediation with secure design patterns and mitigation strategies.

Governance, Awareness & Developer Support :

- Define secure design guidelines and best practices for development teams.

- Provide training and mentorship on threat modeling and secure architecture principles.

- Create security playbooks, checklists, and documentation for architecture security reviews.

Required Skills & Qualifications :

- 5+ years of experience in Application Security or Secure Software Architecture with a focus on Threat Modeling & Architecture Security Reviews.

- Strong knowledge of secure application design: authentication, authorization, data protection, API security, microservices security.

- Experience with threat modeling tools (Microsoft Threat Modeling Tool, IriusRisk) or manual frameworks (STRIDE).

- Familiarity with cloud security principles across AWS, Azure, GCP architectures.

- Hands-on experience with SAST tools (Checkmarx, Fortify, SonarQube) & secure coding standards (OWASP, CWE).

Preferred Qualifications :

- Experience integrating secure design practices into Agile and DevOps CI/CD pipelines.

- Knowledge of compliance & risk frameworks: OWASP ASVS, NIST 800-53, ISO 27001, PCI DSS.

- Relevant security certifications: CSSLP, SABSA, CISSP, AWS Security Specialty.

- Exposure to DAST, SCA, container security, or penetration testing methodologies


info-icon

Did you find something suspicious?