EXL

AVP, Cyber Application Security Architect

EXL
Apply
1 day ago
Remote, United States or Jersey City, NJ, USAStaff+
H1B sponsor

Base Salary

$160k - $195k/yr

Responsibilities

  • Serve as the security architecture authority for product, engineering, cloud, and business stakeholders.
  • Coach developers on secure coding patterns, vulnerability classes, frameworks, libraries, and secure-by-default implementation choices.
  • Triage and validate SAST, SCA, DAST, container, and IaC scanning findings, including resolving false positives and prioritizing risk.
  • Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry.
  • Conduct Secure by Design reviews and lead threat modeling workshops for new applications and material architectural changes.
  • Review authentication, authorization, data flows, secrets handling, logging, monitoring, and resiliency controls.
  • Translate FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, and SOX requirements into auditable security architecture controls.
  • Advise on CI/CD hardening, least privilege, artifact integrity, signing, provenance, secure deployment, dependency security, and supply chain controls.
  • Provide security architecture guidance for AI/ML and GenAI-enabled applications and help implement data protection, access control, monitoring, and abuse-prevention controls.
  • Create secure coding guidance, reference architectures, reusable patterns, and preventative improvements based on incident learnings.

Requirements

  • 8+ years of related IT experience.
  • 5+ years of experience with security application tools.
  • 6+ years of experience conducting application security reviews of new architecture.
  • 5+ years of experience with public and hybrid cloud environments, including AWS, Azure, and GCP.
  • Strong software development background with the ability to read, understand, and advise on production code and design decisions.
  • Expertise in threat modeling and secure architecture reviews for modern web and API-based applications.
  • Expertise securing CI/CD and SDLC processes, including pipeline security, secrets management, artifact integrity, build and release controls, and automation.
  • Experience managing application security findings and resolving false positives using SAST, SCA, DAST, and related pipeline scanning tools.
  • Working knowledge of AI/ML security risks and mitigations for applications using ML models or GenAI components.
  • Strong collaboration, consulting, communication, and influencing skills, including the ability to influence without authority and provide pragmatic developer-friendly recommendations.
EXL

About EXL

10,000+ employees

EXL provides data analytics, AI, and digital operations services for enterprises in insurance, healthcare, banking, and other regulated industries. It delivers consulting, managed services, and technology platforms to improve decision-making, risk management, and operational efficiency. Founded in 1999 and headquartered in New York, EXL is a public company listed on the NASDAQ (ticker: EXLS).

Contact me