
Senior Application Security Architect
State Street17 hours ago
Base Salary
$120k - $203k/yr
Responsibilities
- Design and review secure architectures for enterprise applications, APIs, cloud-native platforms, AI-enabled systems, and emerging technologies.
- Define and maintain application security and AI security standards, architecture patterns, and security requirements.
- Conduct security architecture reviews, threat modeling exercises, design assessments, risk assessments, and penetration-test remediation reviews.
- Partner with application development, cloud engineering, AI engineering, cybersecurity, architecture, and data science teams to embed security controls across software and AI development lifecycles.
- Provide expertise in secure coding, application security testing, API security, authentication, authorization, AI security, and data protection.
- Assess risks involving applications, AI models, training data, prompts, agents, integrations, and third-party AI services.
- Drive adoption of secure-by-design, Zero Trust, DevSecOps, and AI security practices across the enterprise.
- Evaluate emerging application security and AI security threats, technologies, and industry standards.
- Support application modernization, cloud transformation, DevSecOps, and AI adoption initiatives in a global environment.
- Work standard business hours with flexibility for global stakeholders; limited travel may be required.
Requirements
- Degree in Computer Science, Cybersecurity, Information Technology, Engineering, Data Science, or a related discipline.
- 14 or more years of experience in application security, software engineering, security architecture, AI security, or related technology disciplines, with at least 8 years of hands-on cybersecurity experience preferred.
- Demonstrated experience securing enterprise-scale applications across cloud, SaaS, hybrid, and on-premises environments.
- Deep expertise in secure software development lifecycles, OWASP Top 10, API security, secure coding, and application security testing methodologies.
- Strong understanding of AI/ML architectures, LLMs, Retrieval-Augmented Generation, agentic systems, model security, prompt security, and responsible AI principles.
- Experience with cloud-native technologies, containers, Kubernetes, CI/CD pipelines, DevSecOps, and Infrastructure as Code.
- Experience with threat modeling, architecture reviews, penetration-test remediation, and risk assessments for applications and AI-enabled solutions.
- Familiarity with SAST, DAST, IAST, software composition analysis, API security testing, model validation, and AI security assessment techniques.
- Strong analytical, problem-solving, risk assessment, communication, and stakeholder management skills.
- Professional certifications such as CISSP, CSSLP, CCSP, TOGAF, SABSA, AWS Security Specialty, Azure Security Engineer, or AI Security certifications are highly desirable.
- Experience in financial services or other highly regulated industries is preferred.
Benefits
- Hybrid work under State Street’s hybrid work model.
- Retirement savings plan with 401(k) company match.
- Basic life, medical, dental, vision, long-term disability, and optional insurance coverage.
- Paid vacation, sick leave, short-term disability, and family care leave.
- Employee Assistance Program, paid volunteer days, flexible work-life support, employee networks, and inclusive development opportunities.
- Eligibility for incentive compensation, annual performance-based awards, and certain tax-advantaged savings plans.
Tech Stack
Categories
About State Street
State Street is a global custodian bank and asset manager serving institutional investors with investment servicing, fund accounting, trading/FX, data, and index/active strategies. Its products include State Street Global Advisors’ funds and ETFs, the Charles River Investment Management Solution, and the front-to-back State Street Alpha platform. Founded in 1792 and headquartered in Boston, the company is publicly traded on the NYSE (ticker: STT) and operates across major markets worldwide.