
Sr Application Security Architect
SAS Institute2 hours ago
Remote, United States or Cary, NC, USASenior
Responsibilities
- Collaborate with R&D and cloud hosting teams to improve the security posture of business-critical solutions across legacy, hybrid-cloud, and public-cloud environments.
- Plan secure architectural evolution, including third-party dependencies, compensating controls, defense in depth, Zero Trust, and Secure by Design and Secure by Default principles.
- Perform secure design reviews, threat modeling, code reviews, security assessments, and direct verification across the software development lifecycle and development pipelines.
- Identify, triage, and recommend remediation for security vulnerabilities, weaknesses, and product security gaps.
- Partner with product management and security teams to align security implementations with business objectives, customer requirements, and global regulations.
- Identify, train, and support Security Champions within product R&D teams.
- Create secure engineering documentation, guidance, training materials, policies, standards, and procedures.
- Recommend tools and processes for the Secure SDLC and mentor other security architects and Product Security Office personnel.
Requirements
- 8+ years of experience in secure software development, secure system architecture and design, or related work.
- 4+ years of experience developing or adopting software security best practices.
- Bachelor's degree with major study in Computer Science, Electrical Engineering, or a related field, or an equivalent combination of related education, training, and experience.
- Relevant security certifications such as SANS, GIAC, ISACA, CEH, CCSP, CSSLP, CISM, or CISSP are expected or valued.
- Knowledge of global enterprise security risks and attacker TTPs published by MITRE.
- Programming experience with languages such as C/C++, Java, Python, JavaScript, PHP, or Golang sufficient for code review and prescriptive security guidance.
- Expertise securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE, and SANS-25.
- Experience securing microservices, containers, agentic AI, hyperscale cloud hosting, and operations.
- Experience with public-cloud and hybrid-cloud operational security, including Azure, AWS, GCP, and Microsoft Cloud Security Benchmark requirements.
- Experience with SAST tools such as Snyk, Black Duck, and Sonar, and DAST/IAST tools such as ZAP, BurpSuite, Kali, and Nessus.
- Knowledge of auditing, implementing, and supporting DevSecOps.
- Strong communication, collaboration, mentoring, accountability, and continuous-improvement skills.
Benefits
- Hybrid work in Cary, North Carolina, or Glasgow, Scotland, with remote work available in the EST or GMT time zones.
- Comprehensive medical, prescription, dental, and vision plans, including PPO and HDHP options.
- Onsite health care center and pharmacy benefits for eligible headquarters employees and families, with prescription shipping available for nonlocal employees.
- Industry-leading 401(k) plan.
- Tuition assistance and professional development programs and resources.
- Vacation, paid holidays, a U.S. Winter Wellness Break from December 25 through January 1, volunteer time off, parental leave, and unlimited paid sick days.
- Generous childcare benefits for full-time employees.