×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Application Security Architect

Job in Milpitas, Santa Clara County, California, 95035, USA
Listing for: Payactiv,-Inc.
Full Time position
Listed on 2026-06-10
Job specializations:
  • Security
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 175000 - 195000 USD Yearly USD 175000.00 195000.00 YEAR
Job Description & How to Apply Below

Senior Application Security Architect

Position: Senior Application Security Architect

Location: Milpitas, CA

Job : 216

# of Openings: 1

Reports to: Director of Information Security

At Payactiv, we believe everyone is worthy of financial dignity. Our team is built on a shared obsession to create products that reduce financial stress and improve lives.

Responsibilities
  • Partner with product owners, engineering teams, and solution architects to architect, formalize, and implement a Secure SDLC framework based on NIST SSDF, OWASP SAMM, BSIMM, and Microsoft SDL standards, incorporating mandatory security checkpoints throughout the planning, development, testing, deployment, and operational phases to guarantee that security protocols are integrated from the project’s inception.
  • Lead the architectural review process by overseeing ADRs, evaluating system architectures, and directing threat modeling sessions with methodologies such as attack trees, PASTA, and STRIDE. Act as the authoritative figure for security architecture, with the mandate to approve or deny designs based on established security benchmarks while championing a secure‑by‑design philosophy.
  • Establish and uphold robust benchmarks for data handling and logging, alongside standards for cryptography, secure coding, and authentication/authorization frameworks such as FIDO2, mTLS, SAML, OIDC, and OAuth 2.1.
  • Manage comprehensive .NET application security: provide end‑to‑end oversight for C#, .NET 6/7/8+, ASP.NET Core (MVC, Web API, Minimal APIs), Blazor, gRPC, and EF Core. This includes securing the supply chain, hardening legacy .NET Framework environments, and implementing identity solutions.
  • Deliver architectural guidance for modern stacks: provide secure‑coding expertise for Node.js, Type Script (Express, NestJS, Next.js), and Angular, defining approved libraries and language‑specific security patterns.
  • Oversee development governance and reviews: manage Git branching strategies and repository protections across Git Hub, Azure Dev Ops, and Git Lab. Lead a tiered peer‑review program for high‑risk changes, conducting final reviews on critical paths.
  • Architect and manage the App Sec toolchain: operate security automation including SAST, DAST, SCA, and secrets scanning. Define build‑break policies, manage SBOM/SLSA compliance, and consolidate results via ASPM platforms.
  • Lead vulnerability and incident response: own application‑layer risk management, prioritizing issues via CVSS/EPSS and coordinating responses to supply‑chain threats or zero‑day events.
  • Team leadership and mentorship: supervise App Sec engineers and Security Champions, fostering a security culture through paired coding, internal CTFs, and the development of reference architectures and playbooks.
Qualifications
  • 8+ years in a dedicated Application Security / Secure SDLC role.
  • 8+ years of production C# / .NET – expert in modern .NET (6/7/8+), ASP.NET Core, EF Core, secure deserialization, authorization policies, Data Protection, and NuGet supply‑chain hygiene.
  • Working architect‑level proficiency in Python, Node.js / Type Script, and Angular – able to define standards, review code, and threat‑model these stacks.
  • Expert in Git internals, branching strategies, merge semantics, signed commits, and large‑scale repo governance on Git Hub Enterprise / Azure Dev Ops / Git Lab.
  • Proven track record standing up or significantly maturing a Secure SDLC at enterprise scale, security‑as‑code, metric‑driven App Sec.
  • Deep knowledge of OWASP Top 10, API Top 10, ASVS L2/L3, CWE Top 25, MITRE ATT&CK, applied cryptography, and identity protocols (OAuth 2.1, OIDC, SAML, FIDO2).
  • Excellent written communication – authors standards, ADRs and executive briefings; calm, structured incident leadership.
  • Third‑party/vendor risk assessments, ensuring alignment with internal security policies and risk tolerance.
Nice to Have
  • Public CVEs, OSS security tooling, or conference talks (Black Hat, DEF CON, OWASP, NDC, .NET Conf).
  • Experience building paved‑road platforms / internal developer platforms (Backstage).
  • AI / LLM application security (OWASP LLM Top 10, prompt injection, model supply chain).
  • Fuzzing experience (Sharp Fuzz, lib Fuzzer) and prior PSIRT leadership.
Benefits
  • Company‑sponsored Health, Dental, and Vision insurance
  • 401(k), traditional and Roth with a company match
  • Tuition assistance or tuition reimbursement
  • Unlimited paid time off
  • Monthly gym reimbursement
  • Paid time off to volunteer
  • Paid family leave
  • Complimentary lunches onsite
  • Opportunity to grow
  • Opportunity to work with a great team committed to making a difference.
  • Salary range $175k to $195k + bonus

Payactiv is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all team members.

#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary