{"id":1272602,"url":"https://alion.io/job/sourcebae-application-security-architect","title":"Application Security Architect","company":{"id":3776661,"name":"Sourcebae","domain":"sourcebae.com","url":"https://alion.io/company/sourcebae","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["India"],"countries":["IN"],"hiring_countries":["IN"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":39000,"max_usd":93000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":395},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-09-01T07:51:31Z","employer_posted_date":null,"last_verified_at":"2026-09-01T07:51:31Z","board_verified":false,"closed_at":null,"days_open":26,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":26},"description":"Application Security Architect\n\nWork Mode: Remote\n\nShift: 4:30 PM - 2:30 AM IST\n\nAbout the Role:\n\nWe are looking for an experienced Application Security Architect to join our dedicated security team supporting US-based stakeholders. The ideal candidate will have strong hands-on experience in Application Security, Security Architecture, Threat Modeling, Secure SDLC, and DevSecOps.\n\nThis is an architecture and security assessment-focused role, requiring a strong attacker mindset and the ability to identify application risks, recommend secure design solutions, and work closely with engineering and architecture teams to drive remediation.\n\nKey Responsibilities:\n\n- Conduct application security assessments across web applications, APIs, mobile applications, and enterprise platforms.\n\n- Perform security architecture and design reviews and provide recommendations throughout the solution lifecycle.\n\n- Conduct threat modeling, attack surface analysis, data-flow analysis, and abuse-case analysis.\n\n- Identify and assess application security vulnerabilities and potential attack paths.\n\n- Review authentication, authorization, session management, API security, encryption, secrets management, and secure integration patterns.\n\n- Apply OWASP Top 10, OWASP ASVS, and OWASP API Security Top 10 principles to application security assessments.\n\n- Support and enhance Secure SDLC and DevSecOps practices.\n\n- Integrate and support security controls and testing tools within CI/CD pipelines.\n\n- Work with development, infrastructure, enterprise architecture, and cybersecurity teams to prioritize and remediate security risks.\n\n- Translate technical findings into risk assessments, security requirements, architectural recommendations, and remediation roadmaps.\n\n- Support vulnerability management and application security testing activities.\n\n- Apply penetration testing and red-team methodologies from an attacker's perspective, while this role is not primarily a penetration testing position.\n\nRequired Skills & Experience:\n\n- 8 - 12 years of overall experience in Cybersecurity/Application Security, including 4+ years of hands-on Application Security, Security Assessments, and Security Architecture experience.\n\nTech Stack:\n\n- Application Security / AppSec\n\n- Threat Modeling\n\n- Security Architecture\n\n- OWASP Top 10 / ASVS / API Security Top 10\n\n- Secure SDLC / DevSecOps\n\n- SAST, DAST, SCA, API Security, vulnerability scanning, and secrets scanning tools.\n\nCommon Application Vulnerabilities:\n\n- Broken Authentication, Broken Access Control, Injection, Insecure APIs, Session Management Issues, Cryptographic Weaknesses, Security Misconfigurations.\n\nSkills\nCyber Security, OWASP, Cloud Security, DevSecOps, Applications Security, IT Security Strategy, SAST, DAST, Threat Modeling","description_format":"text","description_chars":2783,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security"],"lifecycle":[{"event":"open","at":"2026-09-26T00:07:01Z"}],"liveness":{"score":30,"band":"fade","label":"Fading","p_open":0.85,"p_active":0.639,"p_room":0.55,"age_days":25,"expected_fill_days":22,"reasons":["seen:25","velocity","win:tail"],"computed_at":"2026-09-27T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sourcebae-application-security-architect","json_url":"https://alion.io/job/sourcebae-application-security-architect.json","meta":{"generated_at":"2026-09-28T05:41:00Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3850,"day_limit":5000,"remaining_today":1150,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}