
Lead Application Security Architect
Jones Lang LaSalle Incorporated2 hours ago
Remote, Spain or Barcelona, SpainStaff+
Responsibilities
- Design and maintain application security architecture standards, policies, patterns, reference architectures, and architecture decision records.
- Lead security architecture reviews for new and existing applications using frameworks such as OWASP, NIST, and SANS.
- Integrate zero-trust and defense-in-depth principles into application architectures.
- Define application security requirements and metrics and integrate security into the software development lifecycle and DevSecOps processes.
- Lead threat modeling sessions and provide remediation guidance to development teams.
- Champion secure coding standards and developer security enablement programs.
- Analyze security requirements and design solutions addressing enterprise risk and regulatory compliance obligations.
- Communicate security designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders.
- Coordinate security design reviews and approval processes across security, engineering, and enterprise architecture teams.
- Contribute to the application security strategy roadmap and identify emerging threats.
- Mentor junior security engineers, developers, and architects and lead cross-functional security initiatives.
- Support secure development training and security awareness programs.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field, or equivalent experience.
- At least 7 years of information security experience focused on application security engineering, secure software development, or security architecture.
- Comprehensive knowledge of application security methodologies, OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns.
- Experience designing security architectures for AWS, Azure, GCP, microservices, APIs, and containerized workloads.
- Proficiency with DevSecOps tooling and practices including SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration.
- Experience with NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles.
- Working knowledge of IAM, OAuth 2.0/OIDC, application-layer authentication and authorization controls, cryptography, data protection, encryption, and PKI.
- Familiarity with STRIDE, PASTA, or equivalent threat modeling methodologies.
- Ability to analyze complex application architectures, translate security requirements into implementable solutions, lead security assessments and architecture reviews, and communicate with diverse stakeholders.
- Ability to mentor junior security professionals and developers and balance security rigor with development velocity.
- Knowledge of OWASP GenAI, LLM Top 10, Security Exchange, or AI Exchange is a plus.
- Preferred certifications include CSSLP, CISSP, AWS Security Specialty, Azure Security Specialty, OSCP, or equivalent application security or architecture credentials.
Benefits
- Remote position based in Barcelona, Spain.
- JLL is an equal opportunity employer and provides reasonable accommodations during the employment process.