AVP, Cyber Application Security Architect
EXL · United States · 2026-10-04
About this role
Principle Duties Developer enablement & secure coding support
• Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure.
• Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries.
• Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches.
• Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk.
• Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture.
• Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection.
Secure by Design reviews
• Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early.
• Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk.
• Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures.
• Provide clear, actionable recommendations and track follow-through with engineering teams.
• Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment.
CI/CD and SDLC security
• Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns.
• Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows.
• Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service.
AI/ML security guidance
• Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns.
• Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features.
Collaboration & communication
• Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance.
• Create and maintain secure coding guidance, reference architectures, and reusable patterns.
• Support incident learnings by contributing to root cause analysis and preventative design improvements.
Originally posted on Himalayas
Skills asked for
- aws
- azure
- gcp
- ci/cd
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.