Posted on: 20/09/2025
Job Title : Application Security Risk Architect
Experience : 7 - 9
Job Description
Threat Modeling & Security Architecture Reviews (Primary Focus) :
- Lead threat modeling sessions using frameworks like STRIDE, PASTA, LINDDUN to identify risks and mitigations.
- Conduct security architecture reviews for new and existing applications (web, mobile, APIs, microservices, cloud-native).
- Analyze data flow diagrams, trust boundaries, and third-party integrations for attack vectors.
- Collaborate with solution architects to embed secure design principles and zero-trust models in architectures.
- Maintain a central repository of threat models and risk assessments for traceability.
Application Security & Vulnerability Management :
- Perform secure design and code assessments for critical applications.
- Support the SAST program (Checkmarx, Fortify, SonarQube), prioritizing findings linked to design flaws.
- Partner with developers to guide remediation with secure design patterns and mitigation strategies.
Governance, Awareness & Developer Support :
- Define secure design guidelines and best practices for development teams.
- Provide training and mentorship on threat modeling and secure architecture principles.
- Create security playbooks, checklists, and documentation for architecture security reviews.
Required Skills & Qualifications :
- 5+ years of experience in Application Security or Secure Software Architecture with a focus on Threat Modeling & Architecture Security Reviews.
- Strong knowledge of secure application design: authentication, authorization, data protection, API security, microservices security.
- Experience with threat modeling tools (Microsoft Threat Modeling Tool, IriusRisk) or manual frameworks (STRIDE).
- Familiarity with cloud security principles across AWS, Azure, GCP architectures.
- Hands-on experience with SAST tools (Checkmarx, Fortify, SonarQube) & secure coding standards (OWASP, CWE).
Preferred Qualifications :
- Experience integrating secure design practices into Agile and DevOps CI/CD pipelines.
- Knowledge of compliance & risk frameworks: OWASP ASVS, NIST 800-53, ISO 27001, PCI DSS.
- Relevant security certifications: CSSLP, SABSA, CISSP, AWS Security Specialty.
- Exposure to DAST, SCA, container security, or penetration testing methodologies
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1549083