Sr. Application Security Architect
Listed on 2026-05-31
-
IT/Tech
Cybersecurity
Job Overview
Wex, Inc. is looking for a Sr. Application Security Architect with broad software development and application security experience.
Responsible for designing, guiding, and assessing security solutions in software projects to ensure that security is built in from the beginning. With the assistance of tools including SAST, DAST and SCA, perform assessments of software projects to identify security issues and guide teams to effective remediations.
About WEXWEX is a global leader in financial technology solutions, based in Portland, Maine, with more than 6,000 employees worldwide. It simplifies complexities of payment systems across industries such as Fleet, Corporate Payments, and Benefits, and reduces administrative burdens through modern technology.
Who Are You- A highly motivated security architect who loves working on small, high‑performing teams that interface with the entire enterprise
- A collaborative communicator who works well with your team and stakeholders to drive projects from inception to completion
- A team player who can work independently to deliver high‑quality solutions for projects and operational tasks
- Comfortable balancing the need to move fast with the realities of working in a highly regulated organization
- Passionate about security, yet pragmatic about delivering business value
- Customer focused—prioritizing a great experience for internal teams and WEX partners
- Motivated, skilled, and able to operate independently across global time zones with minimal oversight
- A strong leader who builds consensus and drives change through buy‑in and education rather than mandates
- Works closely with development teams to secure Wex's applications
- Able to mentor other engineers and architects both technically and professionally
- A champion of shift‑left and Dev Sec Ops , capable of building such a program from the ground up
- A lifelong learner excited by new technologies and challenges
- Subject Matter Expert in software development and application security, especially for web applications, APIs, mobile apps, and SaaS‑delivered enterprise applications.
- Lead the Wex application security program and strategy.
- Deeply understand web application attacks, mitigations, and emerging identity‑management trends.
- Mentor and lead threat‑modeling sessions, focusing on lightweight, effective threat modeling practices.
- Train team members in risk‑based analysis of issues uncovered in manual and automated secure code reviews and in commercial SAST, DAST, and SCA tools.
- Perform web application and mobile app penetration testing.
- Provide actionable security guidance to project teams.
- Lead Security Development Lifecycle efforts—coordinating secure architecture reviews, secure code reviews, threat models, and penetration testing throughout the lifecycle.
- Maintain security best practices and OWASP recommendations, and contribute to remediation efforts, policies, and procedures.
- Identify and collaborate with security champions across development and engineering to scale expertise and awareness.
- Write and oversee application security standards and guidelines, assisting their implementation across the organization.
- Deep experience with compliance and regulatory frameworks such as PCI‑DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc.
- 8+ years of progressive experience in software development and architecture
- 3+ years of experience in application security or information security
- 3+ years of experience with SAST, DAST, SCA, IaC scanning, and container image scanning, including integration into build and ticketing tools
- Expertise in identifying, exploiting, and mitigating common application security issues such as OWASP Top 10
- Expertise in customer identity technologies, including OpenID Connect, OAuth 2.0, and SAML 2.0
- Proficiency in troubleshooting security issues in complex on‑prem and multi‑cloud environments
- Degree in Computer Science, Business, or related field (or equivalent experience)
- Strong cross‑functional communication and change‑management skills
- Ability to deliver on tight project schedules with minimal supervision
- Excellent written and verbal communication skills
- Security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).