AVP, Cyber Application Security Architect

Posted Yesterday
Be an Early Applicant
Jersey City, NJ, USA
In-Office
160K-195K Annually
Senior level
Information Technology • Database • Consulting
The Role
Leads application security architecture across SaaS, hardware, and cloud environments. Coaches developers on secure coding, conducts threat modeling and Secure by Design reviews, and advises on authentication, authorization, secrets, monitoring, and resiliency. Oversees SAST, SCA, DAST, container, and IaC scanning, CI/CD security, software supply chain controls, and cloud-native defenses. Translates compliance requirements into measurable architecture controls and provides security guidance for AI/ML and GenAI applications.
Summary Generated by Built In

Principle Duties Developer enablement & secure coding support 

  • Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure.
  • Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. 
  • Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. 
  • Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. 
  • Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. 
  • Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection.

Secure by Design reviews 

  • Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. 
  • Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. 
  • Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. 
  • Provide clear, actionable recommendations and track follow-through with engineering teams. 
  • Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment.

CI/CD and SDLC security 

  • Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. 
  • Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. 
  • Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. 

AI/ML security guidance 

  • Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. 
  • Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. 

Collaboration & communication 

  • Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance. 
  • Create and maintain secure coding guidance, reference architectures, and reusable patterns. 
  • Support incident learnings by contributing to root cause analysis and preventative design improvements. 


Responsibilities

Principle Duties Developer enablement & secure coding support 

  • Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure.
  • Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. 
  • Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. 
  • Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. 
  • Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. 
  • Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection.

Secure by Design reviews 

  • Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. 
  • Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. 
  • Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. 
  • Provide clear, actionable recommendations and track follow-through with engineering teams. 
  • Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives—shifting from audit-driven to architecture-driven alignment.

CI/CD and SDLC security 

  • Advise on the security of CI/CD practices pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. 
  • Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. 
  • Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. 

AI/ML security guidance 

  • Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. 
  • Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. 

Collaboration & communication 

  • Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance. 
  • Create and maintain secure coding guidance, reference architectures, and reusable patterns. 
  • Support incident learnings by contributing to root cause analysis and preventative design improvements. 


Qualifications

Qualifications

  • 8+ years related IT experience; 5+ years' experience in security application tools
  • 6+ years' experience in application security reviews of new architecture; 5 + years of experience with public and hybrid cloud (AWS, Azure and GCP) environments. 
  • Strong software development background with the ability to read, understand, and advise on production code and design decisions.
  • Demonstrated expertise in threat modeling and secure architecture review for modern web and API-based applications. 
  • Expertise securing CI/CD and SDLC processes (pipeline security, secrets management, artifact integrity, build/release controls, and automation).
  • Experience with application security tooling and processes, including managing findings and resolving false positives (SAST/SCA/DAST and related scanning in pipelines). 
  • Working knowledge of AI/ML security risks and mitigations for applications that use ML models or GenAI components. 
  • Strong collaborative and consulting skills ability to influence without authority, communicate clearly, and deliver pragmatic, developer-friendly recommendations. 

Salary Range - $160,000.00 - $195,100.00
The posted range is the hiring range for this role — a subset of the broader range available to employees over time — and reflects base salary across our national hiring scale. Final offers are based on several factors, including the candidate's skills and experience, internal pay equity, work location, market conditions for the role, and the specific scope and responsibilities of the position. The top of the range is reserved for candidates who notably exceed the requirements; the lower end applies to those with less experience or fewer preferred qualifications. For positions based in higher-cost zones (e.g., California, New York, New Jersey), actual compensation may exceed the posted range; your recruiter will share specifics during the process.


Skills Required

  • 8+ years of related IT experience
  • 5+ years of experience with application security tools
  • 6+ years of experience conducting application security reviews of new architecture
  • 5+ years of experience with public and hybrid cloud environments, including AWS, Azure, and GCP
  • Strong software development background with the ability to read, understand, and advise on production code and design decisions
  • Expertise in threat modeling and secure architecture reviews for modern web and API-based applications
  • Expertise securing CI/CD and SDLC processes, including pipeline security, secrets management, artifact integrity, build and release controls, and automation
  • Experience with application security tooling and processes, including SAST, SCA, DAST, findings management, and false-positive resolution
  • Working knowledge of AI/ML security risks and mitigations for ML and GenAI applications
  • Strong collaborative and consulting skills, including influencing without authority and delivering pragmatic developer-friendly recommendations
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
30,246 Employees
Year Founded: 1999

What We Do

Choosing a digital partner is about more than capabilities — it’s about collaboration and character. Unrealistic overhauls and off-the-shelf products ignore what matters most — your unique needs, culture, goals, and your legacy data and technology environments. At EXL, our collaboration is built on ongoing listening and learning to adapt our methodologies. We’re your business evolution partner—tailoring solutions that make the most of data to make better business decisions and drive more intelligence into your increasingly digital operations. Whether your goals are scaling the use of AI and digital, redesign operating models, or driving better and faster decisions, we’re here to partner with you to help you gain—and maintain—competitive advantage with efficient, sustainable models at scale. Our expertise in transformation, data science, and change management helps make your business more efficient and effective, improve customer relationships and enhance revenue growth. Instead of focusing on multi-year, resource- and time-intensive platform designs or migrations, we look deeper at your entire value chain to integrate strategies with impact. We use our specialization in analytics, digital interventions, and operations management—alongside deep industry expertise — to deliver solutions that help you outperform the competition. At EXL, it’s all about outcomes—your outcomes—and delivering success on your terms. Share your goals with us and together, we’ll optimize how you leverage data to drive your business forward. For more information, visit www.exlservice.com.

Similar Jobs

Wipfli Logo Wipfli

Tax Manager

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
106K-160K Annually

Wipfli Logo Wipfli

Quality Assurance Lead

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-131K Annually

Wipfli Logo Wipfli

Senior Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
88K-118K Annually

Wipfli Logo Wipfli

Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
66K-89K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account