Assistant Manager - Application Security Architect
At Mercedes-Benz, technology is at the heart of transforming the customer experience. Our SWT suite of applications is a mission-critical platform that powers both wholesale transactions with dealers and direct sales to customers, ensuring seamless operations across our sales ecosystem.
We are looking for a passionate and experienced Assistant Manager – Application Security Architect to join our IT team. In this role, you will be instrumental in embedding security into the design, development, and operation of our application landscape. You will work closely with product teams, infrastructure specialists, cybersecurity experts, and business stakeholders to drive secure-by-design practices while enabling innovation and agile delivery.
If you thrive in a dynamic environment where cybersecurity, architecture, governance, and business transformation intersect, we invite you to be part of our journey.
Your Role
As the Application Security Architect, you will define and champion application security standards, frameworks, and best practices across the SWT application landscape. You will help ensure our systems remain resilient, secure, compliant, and ready to support the future of mobility.
Key Responsibilities
1. Application Security and Architecture
· Define application security architecture standards (e.g., authorization, session management, API security, encryption, secrets handling management) and maintain a living architecture playbook for development teams.
· Develop security standards, procedures, and guidelines across multiple platforms and diverse environment (e.g., client server, distributed systems, cloud, on-premises environments etc) aligned with company’s risk posture and delivery model.
· Drive the secure Software Development Lifecycle (SDLC) strategy in partnership with Product Teams and Security leadership, balancing governance requirements with developer experience.
· Conduct architecture and design reviews for high-impact initiatives, including new products, major application refactoring, new authorization flows, data-sharing solutions, and platform migrations.
· Plan and implement security measures to protect sensitive data and systems from cyber threats and unauthorized access, in accordance with global cybersecurity guidelines.
· Establish and promote processes, frameworks, and methodologies to strengthen application cybersecurity.
· Assess and manage the security posture of external vendors and service providers that process or access sensitive and personal data.
· Analyze security risks and provide advisory support across a broad range of business and technology initiatives.
2. Governance and Application of Global Cybersecurity Standards
· Contribute to the development of Mercedes-Benz's cybersecurity strategy and support the implementation of security policies, standards, and initiatives within the responsible area.
· Support global and local security awareness programs in collaboration with the Business Information Security Officer (BISO) and Global Cybersecurity organization.
· Establish and facilitate a regular information security forum for application stakeholders.
· Provide consultation and communication on RISE policies and related changes, while enhancing organizational understanding and awareness of cybersecurity requirements.
· Monitor, manage and report cybersecurity KPIs and performance metrics status, and recommend improvement measures to support target achievement.
· Provide relevant cybersecurity inputs to ensure information security requirements are appropriately reflected in Operational Plan (OP) budget planning.
· Conduct periodic compliance reviews and security assessments for IT projects and application initiatives
3. Global and Application Cybersecurity Collaboration
· Act as a key liaison between the SWT suite of applications and Global Cybersecurity teams.
· Ensure alignment between global cybersecurity strategies and local execution at application level while supporting effective communication, collaboration, and feedback mechanisms.
· Provide cybersecurity advisory and consulting support to application teams and IT stakeholders across cloud transformation and DevSecOps initiatives.
· Support the adoption of global cybersecurity standards and contribute to continuous enhancement of cloud and DevSecOps security practices, ensuring scalability, resilience, and consistency across the applications
4. Application Audit Single Point of Contact (SPoC)
· Serve as the primary point of contact for audits relating to the SWT suite of applications.
· Maintain the audit-related documentation, including Application Support Handbooks, Standard Operating Procedures (SoPs), Authorization Concept Documents, Design Documents, and other relevant artefacts)
· Maintain a secure SharePoint repository for storing and distributing audit-relevant materials.
· Ensure application information and records remain current and accurate in LeanIX.
· Create, monitor, and maintain application-related risks and mitigation plans in Archer.
· Support creation, development, maintenance, and testing of Application Recovery Plans and related IT Service Continuity Management (ITSCM) documentation.
· Initiate and coordinate application-related security assessments and controls, including EPA, SCAS, Architecture Review, ICFR, and other required security checks.
· Track and manage remediation activities for cybersecurity issues and risks identified through key security assessments and KPIs, including EPA, SCAS, CIVA-I, and ITSCM, encompassing vulnerability management and risk management activities.