📋 External Recruiting Agencies

Jobgether is a remote job matching platform and talent marketplace; the job listing explicitly states it is posted on behalf of an anonymous partner company, making Jobgether a recruiting intermediary rather than the direct employer.

This company was flagged and excluded from default search results. Proceed with caution.

J
Posted 6d ago

Architect, Information Security - DevSecOps/Application Security

Jobgether
United States
$72k-$157k/yrRemoteFull Time
Responsibilities
  • assessing security
  • conducting threat modeling
  • defining controls
Requirements
  • Requires 3+ years in application security
  • Software security, or DevSecOps
  • Expertise in secure SDLC
  • Threat modeling
  • Architecture, SAST, DAST, SCA
  • OWASP Top 10, APIs, CI/CD, and risk communication
Technical tools mentioned
SASTDASTSCACI/CDOWASP Top 10OWASP SAMMNIST SSDF

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Architect, Information Security – DevSecOps/Application Security based in the United States.

This role is an opportunity to shape application security architecture and governance across a large, complex technology environment.
You will help development and engineering teams build security into applications from design through deployment.
The position combines hands-on security expertise with architecture, risk management, and cross-functional collaboration.
You will champion a shift-left DevSecOps approach by embedding effective security controls throughout the SDLC.
The role also focuses on secure design patterns, software supply chain risk, cloud-native applications, APIs, and CI/CD security.
You will act as a trusted security advisor and subject matter expert, helping teams turn technical risks into practical business decisions.
This is a high-impact opportunity to strengthen security maturity while enabling teams to deliver software securely and at scale.



Accountabilities:
  • Partner with application, development, solution architecture, DevOps, and security teams to assess and manage application security risks across design, development, testing, and deployment.
  • Conduct and support threat modeling, secure design assessments, and architecture reviews for applications, APIs, and cloud-native environments.
  • Define, document, and promote secure architecture patterns, guardrails, reusable controls, and security requirements aligned with organizational AppSec standards.
  • Guide teams in integrating and effectively using application security testing technologies, including SAST, DAST, and SCA, within CI/CD pipelines.
  • Support the implementation and enforcement of security requirements, standards, and control gates throughout the software development lifecycle.
  • Identify application and software supply chain security gaps and collaborate with engineering teams to develop practical, prioritized risk mitigation strategies.
  • Track vulnerabilities, security exceptions, and risk acceptances in accordance with established governance and risk management processes.
  • Collaborate with Security Champions and development teams to increase application security awareness, adoption, and overall maturity.
  • Contribute to AppSec education, training, awareness, and enablement programs that strengthen secure development practices.
  • Serve as a subject matter expert on application security, secure software development, and DevSecOps practices, providing guidance across technology initiatives.
  • Requirements:

    • 3+ years of professional experience in application security, software security, DevSecOps, or a closely related discipline.
    • Strong knowledge of secure SDLC methodologies, threat modeling, secure architecture, and secure-by-design principles.
    • Hands-on familiarity with application security testing tools and methodologies, including SAST, DAST, and software composition analysis (SCA).
    • Solid understanding of the OWASP Top 10, API security vulnerabilities, application security risks, and secure coding practices.
    • Familiarity with CI/CD pipelines, DevOps practices, and common development and deployment tooling.
    • Ability to assess technical security issues and clearly translate risks, potential business impact, and remediation options for both technical and non-technical stakeholders.
    • Strong analytical, problem-solving, communication, and collaboration skills, with the ability to influence development teams and security stakeholders.
    • Experience working within governance frameworks and translating security standards into practical engineering controls is highly valuable.
    • Preferred certifications include CISSP, CISM, CCSP, or an equivalent information security credential.
    • Experience implementing or aligning application security programs with frameworks such as OWASP SAMM or NIST SSDF is preferred.
    • Experience leading AppSec or DevSecOps transformation initiatives, security maturity programs, or enterprise-wide security improvements is an advantage.
    • Benefits:

      • Competitive annual compensation range of $72,370.82–$156,803.45, with actual compensation varying based on geographic location, experience, education, and skill level.
      • Comprehensive benefits and compensation package.
      • Full-time opportunity with a U.S.-based position.
      • Opportunity to influence application security architecture, governance, and DevSecOps practices across a complex technology environment.
      • Exposure to modern application security, cloud-native technologies, APIs, CI/CD, software supply chain security, and secure development practices.
      • Opportunity to collaborate with engineering, architecture, DevOps, and cybersecurity professionals while contributing to enterprise-wide security maturity.
      • Equal opportunity workplace committed to fair consideration of qualified candidates.


How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1

Similar jobs

Information Security Architect roles
1w
Save
Mark Applied
Hide
Information Security Architect
Middletown, Connecticut, United States
OnsiteFull Time
Liberty Bank
Liberty Bank: Provides retail and commercial banking services in the Northeast.
5+ YOEBachelor's or master's degree in a relevant field, 5–10+ years of IT/security experience, architecture expertise, and knowledge of networks, cloud, IAM, risk management, compliance, and security controls.
LAN, WAN, Windows, Linux/Unix, AWS, Microsoft Azure, GCP, IAM, DLP, WAF, SIEM, DevSecOps
3w
Save
Mark Applied
Hide
Information Security Architect (Endpoints and Servers)
United States or Saint Petersburg or Tampa
$126k-$227k/yr RemoteFull Time
Jabil
JabilNYSE: JBL: Provider of comprehensive global manufacturing and supply chain solutions.
12+ YOEBachelor's degree and 12+ years in a related discipline required. Requires endpoint/server security architecture expertise, enterprise risk knowledge, strong communication, and independent problem-solving skills.
Windows, MacOS, iPhone, Android, CrowdStrike, Qualys, CIS, Active Directory, Microsoft Intune, Java, C#, Node, Angular, Agile, SOA, REST, SOAP, API Management, ESB, EIP, SQL, UML, ArchiMate, Lean Six Sigma
3w
Save
Mark Applied
Hide
Architect, Information Security - DevSecOps/Application Security - Remote
United States
$72k-$157k/yr RemoteFull Time
Molina Healthcare
Molina HealthcareNYSE: MOH: Provides managed health insurance through government-sponsored benefit programs.
3+ YOE3+ years in application security/DevSecOps, knowledge of secure SDLC, threat modeling, application security testing, CI/CD, and ability to translate technical risk to business context.
SAST, DAST, SCA, CI/CD, OWASP SAMM, NIST SSDF, OWASP Top 10
3w
Save
Mark Applied
Hide
Information Security Architect
St Thomas, Virgin Islands, United States
$140k-$150k/yr OnsiteFull Time
Ryder
RyderNYSE: R: Provides fleet management and supply chain logistics solutions.
7+ YOEBachelor's in CS/InfoSec,7+ years Information Security Architect experience, knowledge of NIST/ISO/COBIT, hands-on firewall and network security, Azure/cloud and DevSecOps experience, APIs, regex/JSON, Palo Alto certs and other security certs.
Microsoft Azure, ServiceNow, CloudFormation, Terraform, Azure Resource Manager, GCP Cloud Deployment Manager Templates, JSON, regex, APIs, Palo Alto
3w
Save
Mark Applied
Hide
Information Security Architect
Coral Gables or United States
$140k-$150k/yr HybridFull Time
Ryder
RyderNYSE: R: Provides commercial vehicle leasing, logistics, and supply chain solutions.
7+ YOEBachelor's in CS/InfoSec,7+ years as an information security architect, experience with network and cloud security, regulatory frameworks (NIST/ISO), firewall configuration, and collaboration with engineering teams.
Microsoft Azure, APIs, CloudFormation, Terraform, Azure Resource Manager, GCP Cloud Deployment Manager Templates, JSON, regular expressions (regex), ServiceNow, Microsoft Windows, Linux
3w
Save
Mark Applied
Hide
Information Security Architect
Milwaukee or Houston or Mayfield Heights
HybridFull Time
Rockwell Automation
Rockwell AutomationNYSE: ROK: Sells industrial automation hardware and digital manufacturing software solutions.
7+ YOEBachelor's or equivalent, legal U.S. work authorization (no sponsorship), strong enterprise security architecture experience, threat modeling and risk assessment skills; security certifications preferred.
Zscaler, Forescout, CrowdStrike, Microsoft Defender, Microsoft Sentinel, Proofpoint, SailPoint, CyberArk, BeyondTrust, AWS, Azure, GCP
4w
Save
Mark Applied
Hide
Information Security Architect
United States
$130k-$160k/yr RemoteFull Time
Airship
Airship: SaaS platform for mobile app engagement and customer messaging.
8+ YOE8+ years in information security or security architecture with deep GCP security, CI/CD pipeline security, threat modeling, scripting (Python/Java/Bash), IAM and application security experience.
Google Cloud Platform (GCP), Python, Java, Bash, CI/CD, Infrastructure-as-Code (IaC), DevSecOps, Splunk, CrowdStrike, Rapid7, Vanta, Okta, Kubernetes, CSPM, CWPP, SAML, OAuth2, NIST AI RMF, ISO 42001
1mo
Save
Mark Applied
Hide
Information Security Architect
Boston or Quincy
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
7+ YOE7+ years in information security with strong security architecture and data protection experience; bachelor's degree required, master's preferred; CISSP/CISM/CISA/CCSP preferred; experience in regulated industries and cryptography.
Data Security Posture Management (DSPM), Cloud Access Security Brokers (CASB), Security Service Posture Management (SSPM)