×
Register Here to Apply for Jobs or Post Jobs. X

Staff Application Security Architect

Job in Seattle, King County, Washington, 98127, USA
Listing for: Rocket Homes Real Estate LLC
Full Time position
Listed on 2026-07-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Security Management & Operations, Data Security
Salary/Wage Range or Industry Benchmark: 149000 - 318000 USD Yearly USD 149000.00 318000.00 YEAR
Job Description & How to Apply Below

As the Senior Application Security Architect, you work strategically with engineering and product teams to enable the delivery of secure application patterns and software solutions. You design standard security requirements for how applications should be built, deployed, and maintained, ensuring security is baked into the software development lifecycle from the start. You also build and mature team processes that empower development teams to own their software's security posture while mentoring internal security team members.

Responsibilities

Perform security reviews of applications throughout the SDLC, including threat modeling and source code reviews, focusing on designing secure applications from the start and ensuring secure design principles are correctly implemented.

Help set strategic direction for application security initiatives, shift-left processes, and secure coding standards across the enterprise, treating security as quality.

Build relationships and collaborate with software engineering, product, architecture, and information security teams to ensure alignment of company vision and secure coding goals.

Identify opportunities for improvement within software delivery pipelines and work with engineering leadership to implement automated security guardrails and remediations.

Collaborate with business, product owners, architecture, and information security teams to enable delivery of secure software patterns that support business velocity.

Coordinate and drive initiatives for App Sec engineers to build, execute, and scale application security strategies.

Build processes that test compliance and effectiveness of software security requirements through automated guardrails and continuous security testing.

Influence decision makers in secure application architecture, API design, authentication/authorization controls, and modern cloud deployment.

Create and evangelize application security policy sets and secure design patterns to balance velocity and external compliance requirements.

Work directly with development and audit teams to align security architectures against upcoming compliance, regulatory (e.g., SSDF, Executive Orders on Cybersecurity), and contractual landscapes.

Mentor software engineers and information security team members on threat modeling, secure code design, and modern vulnerability remediation techniques.

Minimum Qualifications
  • 10 years of experience in information security, application development with a secure coding background or software engineering role with a focus on secure code & design principles, OR bachelor’s degree in computer science, information security, or a related field and 5 years of experience.
  • Proven experience performing architectural threat modeling on complex systems and applications using formal frameworks (e.g., STRIDE, DREAD, PASTA).
  • Strong ability to read, write, and audit code for security vulnerabilities, with the ability to provide engineering teams with precise, actionable remediation guidance.
  • Deep technical familiarity with Java ecosystem (strongly preferred), as well as .NET and/or Python.
  • Proficiency in at least one scripting language (e.g., Power Shell, Bash, Python) for automation and custom tooling.
  • Demonstrated aptitude for leveraging AI‑assisted engineering tools to drive operational efficiency, balanced with critical thinking to identify, validate, and correct AI inaccuracies or hallucinations.
  • Practical experience or working knowledge of secure SDLC frameworks, Dev Sec Ops  pipeline integration (CI/CD), SAST/DAST/SCA/Secret Scanning tooling, identity and access management (OAuth
    2.0, OIDC, SAML), container security (Docker, Kubernetes), OWASPTop
    10 / ASVS mappings, MITRE ATTACK Framework, and fundamental Info Sec concepts such as least privilege, zero trust architectures, secure input validation, layered security, secure defaults.
  • Deep understanding of modern enterprise security risks such as software supply chain security, securing and hardening development environments, and identifying and mitigating risk at scale.
Preferred Qualifications
  • Master’s degree in computer science, information security, or a related field.
  • Advanced expertise in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary