Application Security Architect (freelancer)
Summary
Designs and enforces application security policies, conducts security assessments, and guides development teams on secure coding practices to protect applications across their lifecycle.
Key Responsibilities
- Work with various stakeholders across the organization to ensure security of applications throughout their lifecycle considering industry best practices, regulatory requirements, and organizational needs
- Steer external partner on conducting comprehensive security assessments of applications, identifying vulnerabilities and recommending appropriate remediation strategies
- Collaborate with development teams to integrate security controls and measures into the application development process effectively
- Define and enforce application security policies, standards, and procedures, ensuring compliance with internal and external security requirements
- Stay up to date with emerging security threats, vulnerabilities, and industry trends related to application security and assess their potential impact on the company
- Provide guidance and support to development teams on secure coding practices, secure configuration management, and vulnerability remediation
- Act as a subject matter expert and provide guidance on application security to stakeholders, management, and executives
- Any other Security Architecture topic relevant to project deliverables
- Stay abreast of industry standards and frameworks such as OWASP, SANS, and NIST, and incorporate relevant practices into the application security program
- Develop and maintain strong relationships with key vendors and strategic external partners
Minimum Requirements
- University degree or equivalent experience in computer science, engineering, information technology or other relevant field(s)
- Fluent in written and spoken English
- Proven experience working as an Application Security Architect or in a similar role, with a focus on securing applications
- Strong knowledge of application security principles, including secure coding practices, input validation, authentication, access controls, and encryption
- Experience with application security standards and frameworks, such as OWASP Top Ten, SANS CWE Top 25, and secure software development lifecycle (SDLC) methodologies
- Hands-on experience with security testing techniques ideally including code review, vulnerability scanning, and penetration testing
- Experience working in a global company and designing / deploying solutions at scale
- Excellent negotiation, communication, and interpersonal skills, ability to develop influential relationships with different stakeholders across all levels
Preferred Requirements:
- Knowledge and experience of industry standards such as ISO 27001, CIS Controls, NIST, Cyber Essentials is a plus
- Certification or accreditation in Information Security (CSSLP, CISM, CISA, CISSP, etc.,) and/or relevant vendor specific certifications is a plus