Security Architect - Application Security
Summary
Designs and secures cloud-native SaaS platforms, performing threat modeling, penetration testing, and secure architecture reviews while collaborating with engineering teams to implement cloud security controls.
About Us
Our People
Our Impact
What You’ll Be Doing:
- Demonstrated expertise in cloud security architecture across AWS/GCP/Azure, including designing secure, scalable cloud environments with a strong focus on identity, network security, encryption, and compliance best practices.
- Extensive experience conducting security architecture reviews for distributed systems and cloud-native applications, identifying design risks early and recommending secure, scalable architectural patterns aligned with business and engineering goals.
- Perform and lead manual and automated penetration testing across applications, APIs, and cloud services
- Drive threat modeling and secure architecture reviews across app and infrastructure layers
- Collaborate with Infra/DevOps on cloud network architecture, including VPC design, security groups, routing, and segmentation
- Design and advise on cloud-native security controls — IAM hardening, role boundaries, secrets management, least privilege
- Evaluate and improve Kubernetes and container security posture (runtime, image, and network layers)Implement secure-by-default patterns across SDLC, CI/CD, and Infrastructure-as-CodeMonitor emerging threats, CVEs, and vulnerabilities relevant to our stack (web, cloud, infra)
- Influence internal security tooling, automation pipelines, and security review processes
- Serve as a security advisor to engineering, SRE, and product teams across key projects
What You’ll Bring:
- 8+ years of experience in Application Security, Product Security, or Cloud Security, with a strong focus on securing large-scale cloud-native applications.
- Strong hands-on experience with threat modeling, secure architecture reviews, and pen testing
- Familiar with OWASP Top 10, STRIDE, and modern security frameworks
- Experience with tools like Burp Suite, ZAP, Snyk, Metasploit, Semgrep
- Ability to read and analyze code (e.g., JavaScript, Go, PHP, or Node.js)Working knowledge of cloud security principles (preferably AWS)
Preferred Qualifications
- Experience with multi-tenant SaaS platforms or white-labeled architectures
- Familiarity with network-level security concepts: VPC design, IAM, zero-trust networksExposure to container security (Docker, Kubernetes)
- Background in B2B SaaS, especially servicing regulated industries (health, legal, finance)
- Hands-on with IaC security and CI/CD pipelines (e.g., GitHub Actions, Terraform)
Equal Employment Opportunity Information
Originally posted on Himalayas