EXL logo
EXL

We make sense of data to drive your business forward. #MakeSenseofData #DriveYourBusinessForward #PartnerYourWay

Senior Application Security Architect

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$160K - $195.1K / year

Seniority

Lead

Bachelor Degree8 yrs expEnglishAWSAzureCloudGoogle Cloud PlatformSDLC

Job Description

Senior Application Security Architect

EXL

• Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure. • Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. • Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. • Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. • Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. • Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection. • Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. • Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. • Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. • Provide clear, actionable recommendations and track follow-through with engineering teams. • Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment.

Job Requirements

  • 8+ years related IT experience; 5+ years' experience in security application tools
  • 6+ years' experience in application security reviews of new architecture; 5 + years of experience with public and hybrid cloud (AWS, Azure and GCP) environments.
  • Strong software development background with the ability to read, understand, and advise on production code and design decisions.
  • Demonstrated expertise in threat modeling and secure architecture review for modern web and API-based applications.
  • Expertise securing CI/CD and SDLC processes (pipeline security, secrets management, artifact integrity, build/release controls, and automation).
  • Experience with application security tooling and processes, including managing findings and resolving false positives (SAST/SCA/DAST and related scanning in pipelines).
  • Working knowledge of AI/ML security risks and mitigations for applications that use ML models or GenAI components.
  • Strong collaborative and consulting skills ability to influence without authority, communicate clearly, and deliver pragmatic, developer-friendly recommendations.

Related Categories

Related Job Pages

More Security Engineer Jobs

LivePerson logo

Security Engineer II

LivePerson

Conversational AI that’s anything but artificial. Fast Company named us the #1 Most Innovative AI Company in the World.

Full TimeRemoteTeam 1,001-5,000Since 1995H1B Sponsor

Role Description In this role, you will have the opportunity to: - Design, build, and maintain security measures to protect LivePerson's computer systems, networks, and information. - Identify and define security needs for our systems, following industry best practices and rules. - Create detailed security plans for our computer systems, both our own and those we use in cloud services. - Collaborate with other teams to find, fix, and reduce security issues in our cloud systems, software, and processes. - Write clear instructions and procedures for our security practices. - Set up and fix problems with security tools and services. - Develop technical solutions to make our systems more secure and automate repetitive security tasks. - Serve as a key expert to help Security Analysts and external security partners with complex issues. - Ensure the security of all IT and operations areas so our systems work well, and our data stays private, accurate, and available. - Document, monitor, and report on various security systems and processes to make sure our systems and data are secure and working correctly. - Help choose the best security tools with other teams to meet the company's needs. - Test, maintain, and improve our security solutions to meet the highest security standards. - Work closely with IT and System teams to strengthen the security of our cloud and infrastructure tools, following security rules and best practices. - Analyze data from systems to find any unusual or potentially harmful activity. - Be available to respond to urgent security issues outside of regular work hours (on-call rotation). Qualifications - Hands-on experience working with multiple cloud services. - Practical experience with networking, and systems like Elastic, OKTA, IDM, AD, JAMF, Windows, Linux, and MacOS. - Experience in responding to security incidents and analyzing system logs. - Familiarity with Python or other scripting languages. - At least 3 years of experience in IT or System teams within a software or cloud-based company. - Experience creating and working with procedures, reports, service level agreements (SLAs), and escalation processes. - Ability to perform well under pressure in fast-changing environments. - Strong communication and teamwork skills, including excellent written and spoken English skills. - Good problem-solving skills and the ability to stay calm under pressure. - A valid Comptia CySA+ certification. Requirements - You need to be available to provide support during US business hours. - This job includes being part of an on-call rotation for after-hours support. - Strong interpersonal skills are important. - Critical thinking abilities are necessary. - Attention to detail is required. - You should be able to manage your tasks and meet deadlines. - The ability to work independently with minimal supervision is important. Benefits - Your entrepreneurial spirit will be supported. - We love team members who chase down their big ideas, become experts, help colleagues, and own their work. - We are proud to be on Fast Company's list of Most Innovative Companies and Newsweek's list of most-loved workplaces. - The option to work remotely has helped shape who we are today. - Employees choose the environments that work best for them from anywhere in North America.

United States + 1 moreAll locations: United States | Canada

Especialista en Ciberseguridad

Talenter

We scale IT teams, You lead the future.

Full TimeRemoteTeam 1-10H1B No Sponsor

• Ejecutar pruebas de penetración (pentesting) y ethical hacking sobre aplicaciones, APIs e infraestructura. • Identificar, analizar y priorizar vulnerabilidades siguiendo OWASP Top 10 y el estándar ASVS. • Realizar security assessments y revisiones de seguridad sobre el ciclo de desarrollo. • Trabajar junto a los equipos de ingeniería para remediar hallazgos y elevar el nivel de seguridad. • Documentar hallazgos y comunicar riesgos de forma clara a perfiles técnicos y de negocio.

Chile
Apple logo

Senior Security Engineer - Kernel & Embedded Security

Apple

Well-known for creating the Mac, iPhone, iPad, and Apple Watch, as well as its App Store, Apple Music, Apple Pay, and iTunes services, Apple's goal is to leave the world better tha

Role Description Apple's Security Engineering & Architecture organization is responsible for the security of all Apple products. Passionate about safeguarding our users, we take an offensive approach to defense — finding and fixing vulnerabilities before they can be exploited. When it comes to securing more than a billion devices running the world's most sophisticated operating systems, that means finding vulnerabilities first. In this role, your primary focus will be on the kernel and embedded layers of Apple platforms but extends to all parts of the platforms. You will: - Partner with vulnerability researchers to understand attacks found by others. - Propose architecture changes/mitigation in partnership with other experts in the field. - Drive these changes into the products by partnering with engineering teams. - Work in cross-functional teams alongside other researchers and engineering teams to evaluate and strengthen the most privileged layers of our products. - Develop proof of concept to validate some approaches. This job is for individuals with outstanding technical skills and a genuine passion for building things. If this is you, we'd love to hear from you. In-office roles in Paris, and other locations. Remote considered for experienced candidates. Qualifications - Proven experience in code development and product development. - Deep understanding of operating system kernels, firmware, or embedded components. - Ability to apply AI techniques and tools, such as LLMs or Machine Learning, for security research. - Understanding and experience in shipping products. Requirements - Deep knowledge of kernel internals, including virtual memory management, system call interfaces, and driver frameworks. - Experience with firmware and boot ROM security analysis, including secure boot chains and hardware trust anchors. - Familiarity with embedded processors and coprocessors security (e.g., Secure Enclave, DMA-capable peripherals, baseband). - Fluency with tool development, using programming languages such as C, C++, Python, Swift, or Objective-C. - Ability to propose and drive architecture changes. - Knowledge of Apple operating systems like iOS or macOS is nice-to-have, but not required. - Outstanding collaboration skills.

France
CARTO logo

Core Software Engineer – Security & Platform

CARTO

Unlock the power of spatial analysis

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Improve the security of the platform through code. Work directly in the CARTO codebase to identify, prioritize, and fix security weaknesses. This may involve refactoring existing components, redesigning risky flows, improving authorization boundaries, strengthening input validation, removing unsafe patterns, or building new platform capabilities that make secure development easier for everyone. • Strengthen our cloud and infrastructure foundations. Work with our infrastructure and platform teams to harden CARTO’s cloud-native environments across GCP and AWS. You will contribute to areas such as IAM, Kubernetes, containerized workloads, networking, workload isolation, Infrastructure as Code, and secure-by-default deployment patterns. • Make security part of the development workflow. Build and improve tools, checks, libraries, CI/CD integrations, and engineering practices that help developers catch security issues early. The goal is not to create gates that slow teams down, but to make the secure path the easiest path. • Improve supply-chain security. Help protect CARTO from modern supply-chain attacks by improving dependency management, build integrity, container security, artifact provenance, CI/CD security, and automated scanning. Stay up to date with emerging attack techniques and translate that knowledge into practical protections. • Use AI to improve security. Experiment with the latest AI models and tools to assess and improve CARTO’s security posture. This could include AI-assisted code review, automated vulnerability discovery, codebase analysis, threat modeling, dependency analysis, or internal agents that continuously look for risky patterns and misconfigurations. • Secure AI and agentic systems. CARTO is building an Agentic GIS platform, which creates new security challenges. You will help us reason about and defend against risks such as prompt injection, tool misuse, data leakage, privilege escalation through agents, untrusted content flowing into automated workflows, and unsafe model/tool interactions. • Raise the security bar across engineering. Partner with engineering teams to review designs, identify risks, and implement improvements. Help make every team more security-aware while remaining pragmatic, collaborative, and focused on enabling product velocity.

Spain