IT Application Security Architect; Hybrid
Berlin, Hartford County, Connecticut, 06037, USA
Listed on 2025-12-26
-
IT/Tech
Cybersecurity, IT Consultant
Overview
Eversource will not offer immigration-related sponsorship for this position. Applicants who require immigration sponsorship—either now or in the future—should not apply. This includes, but is not limited to, direct company sponsorship, listing Eversource as the employer of record on immigration documents, or any work authorization that requires company involvement or documentation (e.g., H-1B, OPT, STEM OPT, CPT, TN, J-1, O-1, etc.).
Eversource supports work-life balance by offering hybrid schedules for certain roles. Eligibility is based on job responsibilities, operational needs, nature of work and team dynamics. Current guidelines require employees to work at least three days in the office, including Tuesdays and Wednesdays, with the third day set by the employee and supervisor based on department needs. These guidelines apply to roles approved for remote work and are subject to change, based on managerial discretion and work performance.
All applicants must be able to work up to five days in the office if needed (for example: emergencies, training, or other business needs) or should the policy change.
As the Application Security Architect, and part of the Cybersecurity Architecture team at Eversource, you will work alongside other cybersecurity specialists within the Cybersecurity, Network, and Compliance organization. You’ll have the opportunity to apply your knowledge across multiple projects and collaborate across multiple business lines and technical domains. You will aid the firm in remaining at the forefront of industry trends, best practices, and technological advances in application cybersecurity.
The Application Security Architect will interact with the technology and business colleagues associated with projects. They will deliver project level planning, design, and implementation of security solutions and controls related to Secure Software Development Life Cycle (SSDLC) (e.g. code review, risk assessments, threat modeling, static code analysis, and dynamic application scanning). One of your primary tasks will be to get deeply involved in security issues around secure coding and secure design.
You will assist others in resolving security issues by offering alternative coding solutions and other means. You will also work with project teams to incorporate security into the design architecture. The Application Security Architect will continuously raise the security bar by promoting a security mindset and educating application developers regarding Eversource security practices. They will cultivate a security culture as you interact with the developers, project teams, and business areas.
Functions
- Assess the current design and codebase to identify areas in need of improvement. Work with members of project teams to resolve security issues.
- Must work seamlessly with the Eversource developers to ensure the successful adoption of required security approaches and capabilities.
- Conduct threat modeling for new and existing applications. Perform security testing such as static code analysis, pen testing, and dynamic application security testing.
- Apply a cybersecurity background to perform code analysis when resolving false positives and provide remediation recommendations.
- Establish application security requirements based on company standards and industry best practices.
- Develop and maintain infrastructure as code security policies.
- Test and evaluate security tools, and products.
Education:
- Bachelor’s degree in Information Systems or a related technical field or equivalent experience
Experience:
- 5+ years applied experience in application security or related position.
- Must have a background performing cybersecurity code analysis. This includes identifying and resolving false positives, explaining vulnerabilities in simple terms to project teams, and providing remediation recommendations to development teams.
- Experience with software composition analysis and tools to scan source and binary code for the purpose of identifying dependency vulnerabilities.
- Experience with implementing and using static and dynamic…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).