Lead Application Security Architect
Summary
Lead an internal security consulting team focused on mobile app ecosystem (iOS/Android) and enterprise security architecture, driving threat modeling, AI/ML security governance, and CI/CD security tooling.
Our client is hiring a Software Security Architect to leadtheir internal security consulting team, with a sharp focus on their mobile appecosystem (native and hybrid, iOS/Android) alongside the broader enterprise.
What You'll Do
• Lead threat-driven architecture reviews — mobileclients/SDKs, identity flows (OAuth2, JWT), AI deployments (MCP, RAG, agent harnesses)
• Advance AI-enabled threat modelling; pilot new initiatives
• Drive architecture decisions across business units, mobilepipelines included
• Build security-by-design into mobile app development
• Uplift CI/CD security tooling (mobile SAST/DAST, secretsmanagement)
• Relaunch Security Champions into a programme people wantto join
• Design identity governance across hybrid/multi-cloud,incl. on-device token handling
• Architect frameworks for Gen AI deployment, monitoring,governance
• Own security blueprints for Gen AI, MCP, AI guardrails
• Lead agentic AI security — auth/authz of AI agents
What You Bring
• Bachelor's in CS, Engineering, or equivalent
• 5+ yrs as a software engineer/developer; mobile dev/security a plus
• 3+ yrs leading a team in security architecture/consulting
• Threat modelling experience, ideally mobile (OWASPMASVS/MSTG)
• Track record delivering complex, multi-stakeholderinitiatives
• Hands-on AI/ML security: LLMs, MCP, agentic AI
• Strong OWASP/SANS fundamentals; SAST, DAST, SCA, containerscanning
• Certifications (SANS, AWS, Azure) a plus
If you would like to explore this opportunity, pleaseemail your resume in Microsoft Word format to eugene.chang@thevinesearch.com
We thank you for your interest and will contact shortlisted candidates for a more detailed discussion.
EA License No. 25C2923
EA Registration No. R1105304