Application Security Architect

Posted 3 Days Ago
Be an Early Applicant
București, ROU
In-Office
Senior level
Insurance
The Role
Design and enforce application security architecture standards across cloud, on-premise, and hybrid environments. Integrate security into SDLC and CI/CD pipelines, conduct threat modeling and architecture reviews, define secure coding and configuration practices, monitor application security metrics, promote network and operational security, and support audit remediation. Collaborate with development and IT teams as a trusted security advisor while aligning controls with OWASP practices, internal policies, and regulatory requirements.
Summary Generated by Built In

We are seeking an Application Security Architect to join our Security team and lead the design and implementation of secure software solutions across the organization. The ideal candidate is proactive, technically adept, and deeply knowledgeable in secure software development practices. You will collaborate closely with development teams to embed security into the software lifecycle from the ground up, ensuring robust protection of sensitive data and systems.

This role involves conducting security assessments, defining application security requirements, and promoting secure coding standards. You will also stay ahead of emerging threats and vulnerabilities, applying this intelligence to continuously strengthen the organization’s application security posture. Your expertise will be critical in safeguarding the confidentiality, integrity, and availability of our applications.

Responsibilities

Key duties and responsibilities

 

As an Application Security Architect, you will be responsible for designing and implementing secure software solutions across SCOR’s IT landscape. You will collaborate with development and IT teams to embed security into the software development lifecycle (SDLC), define and enforce secure coding practices, and ensure compliance with SCOR’s internal control and security standards. You will also monitor emerging threats and vulnerabilities, and proactively adapt security measures to maintain the confidentiality, integrity, and availability of SCOR’s business applications.

Key Responsibilities:

•    Security Architecture Standards: Develop and maintain security architecture standards for cloud infrastructures, APIs, and applications, and promote their adoption across IT functional teams 
•    Secure SDLC Integration: Participate in the review and definition of the software development and SaaS integration lifecycle, aligning with SCOR’s internal control and OWASP-based best practices (e.g., SAMM, ASVS, Top 10 proactive controls, STG, Cheat Sheet Series) 
•    Operational Security Practices: Define and maintain standard operational security practices across application environments.
•    Network Security Advocacy: Promote and drive adoption of network security practices throughout the enterprise.
•    Security Metrics and Dashboards: Develop and maintain dashboards to track program maturity, incidents, and operational effectiveness.
•    Security Configuration Management: Define and enforce standard security configurations for technical solutions to ensure availability, integrity, data protection, and privacy.
•    Security Assessment and Enhancement: Review current security measures on business applications and recommend enhancements based on evolving standards.
•    Audit Remediation Support: Assist IT teams in implementing remediation plans for security findings identified during audits.

Key Duties:

•    Design and enforce secure architecture standards for cloud and application environments.
•    Integrate security into the software development lifecycle using OWASP-aligned frameworks.
•    Maintain and promote operational and network security practices.
•    Monitor and report on application security posture using metrics and dashboards.
•    Review and enhance security configurations and controls for business applications.
•    Support remediation efforts for audit findings and ensure compliance with SCOR’s security policies.
 

Qualifications

Required experience & competencies

 

Must adhere to our Key Security Principles and Team Values:

  • Security Principles: Defend the business, support the business, and promote responsible information security behavior.
  • Team Values: Professionalism, Ethics, Transparency, and Team Spirit.


Hard skills

  • Minimum 5-10 years of overall IT experience, with at least 3 years in a dedicated Application Security, Security Architecture, or Secure Software Engineering role in complex enterprise environments.

  • Proven experience designing and enforcing application security architectures for business‑critical and regulated systems, covering on‑premise, cloud, and hybrid environments.

  • Hands-on experience embedding security into the SDLC across multiple delivery models (Agile, DevSecOps, SaaS integration), including security gates, threat modeling, and architecture reviews.

  • Demonstrated experience working with development teams as a security authority and trusted advisor, not only as a reviewer or auditor.

  • Prior exposure to audit, regulatory, or internal control environments, with a track record of supporting remediation and demonstrating security-by-design.

  • Strong hands-on experience securing cloud-based applications

  • Experience integrating security into CI/CD pipelines, including: SAST, DAST, SCA, and dependency scanning
  • Solid understanding of modern authentication and identity federation mechanisms (OIDC, OAuth2, SAML), and their application in enterprise and SaaS contexts.
  • Good understanding of networking fundamentals and security controls (protocols, proxies, firewalls, WAFs, segmentation).
  • Strong knowledge of enterprise IAM and identity platforms (hybrid IdP, IAM, MDM), and their impact on application security design.
  • Scripting and automation capability (PowerShell and/or equivalent) to support security assessments, controls, or integrations.
  • Working knowledge of Windows and cross-platform environments, including security services and policy enforcement.
  • Demonstrated ability to translate security principles into enforceable requirements aligned with internal control frameworks and policies.

Soft skills

  • Strong analytical and problem-solving skills.

  • Effective communication and collaboration abilities.

  • Ability to work independently and in cross-functional teams.

  • Attention to detail and a proactive mindset.


Required Education 


  • Master’s degree in Computer Science, Cybersecurity, or a closely related field (mandatory).

  • Relevant security certifications strongly preferred, such as:

    • CSSLP

    • CISSP (or ISSAP)

    • CCSP

    • GIAC Application Security certifications

    • Cloud security certifications (Azure / AWS / GCP)

About Us

As a leading global reinsurer, SCOR offers its clients a diversified and innovative range of reinsurance and insurance solutions and services to control and manage risk. Applying “The Art & Science of Risk,” SCOR uses its industry-recognized expertise and cutting-edge financial solutions to serve its clients and contribute to the welfare and resilience of society in around 160 countries worldwide.

Working at SCOR means engaging with some of the best minds in the industry – actuaries, data scientists, underwriters, risk modelers, engineers, and many others – as we work together to find solutions to pressing challenges facing societies.

As an international company, our common culture is defined by “The SCOR Way.” Serving both to build momentum that drives the Group forward and as a compass to guide our actions and choices, The SCOR Way is anchored by five core values, reflecting the input of employees at all levels of the Group. We care about clients, people, and societies. We perform with integrity. We act with courage. We encourage open minds. And we thrive through collaboration.

SCOR supports inclusion and the diversity of talents, and all positions are open to people with disabilities.

Skills Required

  • Minimum 5-10 years of overall IT experience
  • At least 3 years in Application Security, Security Architecture, or Secure Software Engineering in complex enterprise environments
  • Experience designing and enforcing application security architectures for business-critical and regulated systems across on-premise, cloud, and hybrid environments
  • Experience embedding security into Agile, DevSecOps, and SaaS integration lifecycles, including security gates, threat modeling, and architecture reviews
  • Experience advising development teams as a security authority and trusted advisor
  • Exposure to audit, regulatory, or internal control environments and security remediation
  • Strong experience securing cloud-based applications
  • Experience integrating SAST, DAST, SCA, and dependency scanning into CI/CD pipelines
  • Understanding of OIDC, OAuth2, and SAML authentication and identity federation
  • Understanding of networking protocols, proxies, firewalls, WAFs, and segmentation
  • Knowledge of enterprise IAM, hybrid identity providers, and MDM platforms
  • Scripting and automation capability using PowerShell or equivalent
  • Working knowledge of Windows and cross-platform environments, security services, and policy enforcement
  • Master's degree in Computer Science, Cybersecurity, or a closely related field
  • CSSLP, CISSP or ISSAP, CCSP, GIAC Application Security, or Azure, AWS, or GCP cloud security certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Paris, Paris
4,492 Employees

What We Do

SCOR, one of the world’s largest reinsurers, serves more than 5,000 clients worldwide, providing a diversified and innovative range of solutions to control and manage risk. SCOR delivers advanced financial solutions, analytics and services across all dimensions of risk in Life & Health, Property & Casualty, and Investments. Reinsurance lies at the intersection of technical expertise and scientific progress. Models, data, and pricing and reserving tools are essential, yet they are never sufficient on their own. Sound risk decisions require expert judgment, experience and perspective. This is what we call the Art and Science of Risk. Reinsurance is a knowledge industry, where expertise grows through accumulation, transmission and practice. Across the Group, 3,600 experts based in more than 35 offices worldwide contribute to this collective intelligence. Actuaries, underwriters, risk management specialists, and Tech & Data experts transform data into insight, explore extreme scenarios, define the boundaries of insurability and help anticipate emerging risks. Together, they strengthen the resilience of SCOR, our clients and the societies we serve. This expertise is built through shared experience,continuous questioning and collective reflection. Like artists, we belong to schools of thought, learning first to observe, then to replicate, and ultimately to innovate. This ongoing transmission of knowledge enables SCOR to develop a distinctive approach, combining rigor, creativity and long-term vision in the service of risk mastery. This shared commitment underpins SCOR’s role as a global reinsurer. By turning risk into resilience and sustainable value, our collective of experts acts with responsibility and purpose. Together, we help protect the future, and shape it, for our clients, for society and for generations to come.

Similar Jobs

CrowdStrike Logo CrowdStrike

Data Sceintist I - Fixed term contract

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Bucharest, București, ROU
11000 Employees

Pfizer Logo Pfizer

Quality Assurance Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
28 Locations
121990 Employees

Pfizer Logo Pfizer

Manager Archiving and Compliance

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
28 Locations
121990 Employees

Mondelēz International Logo Mondelēz International

Platform Engineer

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
2 Locations
90000 Employees

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account