SAS Institute

Sr Application Security Architect

SAS Institute
Apply
2 hours ago
Remote, United States or Cary, NC, USASenior

Responsibilities

  • Collaborate with R&D and cloud hosting teams to improve the security posture of business-critical solutions across legacy, hybrid-cloud, and public-cloud environments.
  • Plan secure architectural evolution, including third-party dependencies, compensating controls, defense in depth, Zero Trust, and Secure by Design and Secure by Default principles.
  • Perform secure design reviews, threat modeling, code reviews, security assessments, and direct verification across the software development lifecycle and development pipelines.
  • Identify, triage, and recommend remediation for security vulnerabilities, weaknesses, and product security gaps.
  • Partner with product management and security teams to align security implementations with business objectives, customer requirements, and global regulations.
  • Identify, train, and support Security Champions within product R&D teams.
  • Create secure engineering documentation, guidance, training materials, policies, standards, and procedures.
  • Recommend tools and processes for the Secure SDLC and mentor other security architects and Product Security Office personnel.

Requirements

  • 8+ years of experience in secure software development, secure system architecture and design, or related work.
  • 4+ years of experience developing or adopting software security best practices.
  • Bachelor's degree with major study in Computer Science, Electrical Engineering, or a related field, or an equivalent combination of related education, training, and experience.
  • Relevant security certifications such as SANS, GIAC, ISACA, CEH, CCSP, CSSLP, CISM, or CISSP are expected or valued.
  • Knowledge of global enterprise security risks and attacker TTPs published by MITRE.
  • Programming experience with languages such as C/C++, Java, Python, JavaScript, PHP, or Golang sufficient for code review and prescriptive security guidance.
  • Expertise securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE, and SANS-25.
  • Experience securing microservices, containers, agentic AI, hyperscale cloud hosting, and operations.
  • Experience with public-cloud and hybrid-cloud operational security, including Azure, AWS, GCP, and Microsoft Cloud Security Benchmark requirements.
  • Experience with SAST tools such as Snyk, Black Duck, and Sonar, and DAST/IAST tools such as ZAP, BurpSuite, Kali, and Nessus.
  • Knowledge of auditing, implementing, and supporting DevSecOps.
  • Strong communication, collaboration, mentoring, accountability, and continuous-improvement skills.

Benefits

  • Hybrid work in Cary, North Carolina, or Glasgow, Scotland, with remote work available in the EST or GMT time zones.
  • Comprehensive medical, prescription, dental, and vision plans, including PPO and HDHP options.
  • Onsite health care center and pharmacy benefits for eligible headquarters employees and families, with prescription shipping available for nonlocal employees.
  • Industry-leading 401(k) plan.
  • Tuition assistance and professional development programs and resources.
  • Vacation, paid holidays, a U.S. Winter Wellness Break from December 25 through January 1, volunteer time off, parental leave, and unlimited paid sick days.
  • Generous childcare benefits for full-time employees.
SAS Institute

About SAS Institute

10,000+ employees
Contact me