First seen by Alion on Sep 1, 2026.
Application Security Architect
Work Mode: Remote
Shift: 4:30 PM - 2:30 AM IST
About the Role:
We are looking for an experienced Application Security Architect to join our dedicated security team supporting US-based stakeholders. The ideal candidate will have strong hands-on experience in Application Security, Security Architecture, Threat Modeling, Secure SDLC, and DevSecOps.
This is an architecture and security assessment-focused role, requiring a strong attacker mindset and the ability to identify application risks, recommend secure design solutions, and work closely with engineering and architecture teams to drive remediation.
Key Responsibilities:
- Conduct application security assessments across web applications, APIs, mobile applications, and enterprise platforms.
- Perform security architecture and design reviews and provide recommendations throughout the solution lifecycle.
- Conduct threat modeling, attack surface analysis, data-flow analysis, and abuse-case analysis.
- Identify and assess application security vulnerabilities and potential attack paths.
- Review authentication, authorization, session management, API security, encryption, secrets management, and secure integration patterns.
- Apply OWASP Top 10, OWASP ASVS, and OWASP API Security Top 10 principles to application security assessments.
- Support and enhance Secure SDLC and DevSecOps practices.
- Integrate and support security controls and testing tools within CI/CD pipelines.
- Work with development, infrastructure, enterprise architecture, and cybersecurity teams to prioritize and remediate security risks.
- Translate technical findings into risk assessments, security requirements, architectural recommendations, and remediation roadmaps.
- Support vulnerability management and application security testing activities.
- Apply penetration testing and red-team methodologies from an attacker's perspective, while this role is not primarily a penetration testing position.
Required Skills & Experience:
- 8 - 12 years of overall experience in Cybersecurity/Application Security, including 4+ years of hands-on Application Security, Security Assessments, and Security Architecture experience.
Tech Stack:
- Application Security / AppSec
- Threat Modeling
- Security Architecture
- OWASP Top 10 / ASVS / API Security Top 10
- Secure SDLC / DevSecOps
- SAST, DAST, SCA, API Security, vulnerability scanning, and secrets scanning tools.
Common Application Vulnerabilities:
- Broken Authentication, Broken Access Control, Injection, Insecure APIs, Session Management Issues, Cryptographic Weaknesses, Security Misconfigurations.
Skills
Cyber Security, OWASP, Cloud Security, DevSecOps, Applications Security, IT Security Strategy, SAST, DAST, Threat Modeling

