Talent.com
Sr Application Security Architect
Sr Application Security ArchitectSAS • Cary, NC, United States
Sr Application Security Architect

Sr Application Security Architect

SAS • Cary, NC, United States
30+ days ago
Job type
  • Full-time
Job description

Senior Application Security Architect - Remote or Hybrid

Nice to meet you!

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

We’re also a debt-free multi-billion-dollar organization on our path to IPO-readiness. If you're looking for a dynamic, fulfilling career coupled with flexibility and world-class employee experience, you'll find it here.

About the job

As a Senior Application Security Architect within the Product Security Organization (PSO), you will be a key contributor to SAS security solution. Successful candidates will partner with architecture, engineering, and cloud hosting helping to solve complex technical problems anywhere in the Software Development Lifecycle (SDLC) from design and development through to deployment and operations. Technical security breadth and depth as well as clear, concise and effective communications are key – this role requires a diverse set of skills in systems architecture, software development, and cyber-security. Success will depend on your collaborative skills working toward the SAS goal of meeting legal, compliance, and customer security requirements as part of providing SAS customers with the most trustworthy solutions globally.

As a Senior Application Security Architect at SAS, you will :

  • Collaborate across R&D and cloud hosting teams to strategically improve the security posture of business-critical multi-tier solutions in legacy, hybrid cloud, and public cloud environments. Includes tactical refactoring, environment promotion, and Secure by Default deployment and configuration to maintain security consistency if not parity between all environments.
  • Collaborate in the planning of evolutionary paths for secure architectures and systems incorporating and aligning dependent third-party architectures as well as the adoption of new technologies while maintaining a robust and consistent security posture. Includes employing specific security compensating controls, defense in depth, and security posture aspects in support of Secure by Design, Secure by Default (deployment and configuration), and Zero Trust Architectural principles.
  • Work with development teams providing security assessment and hardening of products spanning the SDLC and development pipelines left / early-shifted wherever possible. Includes performing periodic secure design, threat modeling, code reviews, or direct verification to identify and triage issues assessing the security risk and recommending remediation steps for vulnerabilities and weaknesses.
  • Collaborate with Product Management stakeholders to ensure security implementations are consistent with business objectives, customer requirements, and applicable global regulations.
  • Identify, train, and partner with Security Champions in place with product R&D teams. Help champions assess and gauge risk to identify security gaps or seams in the products and integrated solutions.
  • Create and maintain secure engineering documentation, guidance, or training collateral supporting with PSO standards, policies, and procedures.
  • Collaborate with other teams within security to identify new tools and processes to integrate into the Secure SDLC. Recommend and promote software security policies, standards, and procedures that can improve the global SAS security posture. Mentor and coach within the Product Security Office and other Security Architects aligned with your security breadth and building depth via subject matter expertise.

Required Qualifications

  • 8+ years of secure software development, secure system architecture and design, or related experience.
  • 4+ years of demonstratable experience in developing or adopting software security best practices.
  • Bachelor's degree with major study in Computer Science, Electrical Engineering, or related.  Possess relevant security certifications such as from SANS, GIAC, or ISACA CEH, for CCSP, CSSLP, CISM, or CISSP.
  • An equivalent combination of related education, training, or experience may be considered in place of any of the above qualifications.
  • Knowledge of current Global Enterprise security risks and attacker TTPs as published by MITRE.
  • Experience with programming languages such as C / C++, Java, Python, JavaScript, PHP, Golang, etc. allowing you to review code or logic and be confident in giving prescriptive guidance to R&D and hosting / ops in security patterns and best practices.
  • Expertise in securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE and SANS-25.
  • Experience with security best practices for modern R&D such as micro-services and containers, Agentic AI, hyper-scale cloud hosting and operations, etc.
  • You’re curious, passionate, authentic and accountable. These are our values and influence everything we do.
  • Preferred Qualifications

  • Experience with cloud hosting and operational security for public clouds (Azure, AWS, or GCP) and hybrids such as the domains and requirements in the Microsoft Cloud Security Benchmark (MCSB).
  • Experience with SAST tools, such as : Snyk, Black Duck, Sonar, etc.
  • Experience with DAST / IAST tools, such as : ZAP, BurpSuite, Kali, Nessus, etc.
  • Knowledge of and experience with auditing, implementing, and supporting Dev(Sec)Ops.
  • World-Class Benefits

    Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include...

  • PPO with low annual deductible and copays.
  • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.
  • Diverse and Inclusive

    At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our diverse workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers. Our commitment to diversity is a priority to our leadership, all the way up to the top; and it’s essential to who we are. To put it plainly : you are welcome here.

    Additional Information :

    To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity / Affirmative Action employer. All qualified applicants are considered for employment without regard to race, color, religion, gender, sexual orientation, gender identity, age, national origin, disability status, protected veteran status or any other characteristic protected by law. Read more : Know Your Rights.

    Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.

    SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact Recruitingsupport@sas.com.

    #SAS

    Create a job alert for this search

    Application Architect • Cary, NC, United States

    Related jobs
    Cardiac Surveillance Tech - Cardiac Surveillance (Per Diem)

    Cardiac Surveillance Tech - Cardiac Surveillance (Per Diem)

    UNC Health • Chapel Hill, North Carolina, United States
    Full-time
    Cardiac Surveillance Tech needed for Cardiac Surveillance.This position monitors telemetry patients, ensuring telemetry is applied correctly. This position has the responsibility of monitoring and i...Show more
    Last updated: 1 day ago • Promoted
    IT Consultant - Identity & Access Management

    IT Consultant - Identity & Access Management

    Duke Clinical Research Institute • Durham, NC, United States
    Full-time
    At Duke Health, we're driven by a commitment to compassionate care that changes the lives of patients, their loved ones, and the greater community. No matter where your talents lie, join us and disc...Show more
    Last updated: 8 days ago • Promoted
    Enterprise Architect - Cloud / Cyber (Raleigh, NC; Phoenix, AZ)

    Enterprise Architect - Cloud / Cyber (Raleigh, NC; Phoenix, AZ)

    First Citizens Bank • Raleigh, NC, US
    Full-time
    This is a hybrid role with the expectation that time working will regularly take place inside and outside of a company office in either Raleigh, NC or Phoenix, AZ. This position establishes and impl...Show more
    Last updated: 21 days ago • Promoted
    Cardiac Surveillance Tech - Cardiac Surveillance (Per Diem)

    Cardiac Surveillance Tech - Cardiac Surveillance (Per Diem)

    UNC Health Care • Chapel Hill, NC, United States
    Full-time
    Cardiac Surveillance Tech needed for Cardiac Surveillance.This position monitors telemetry patients, ensuring telemetry is applied correctly. This position has the responsibility of monitoring and i...Show more
    Last updated: 30+ days ago • Promoted
    Principal Firmware Security Engineer

    Principal Firmware Security Engineer

    Microsoft Corporation • Raleigh, NC, United States
    Full-time
    Do you want to be at the forefront of innovating the latest hardware designs to propel Microsoft's cloud growth? Are you seeking a unique career opportunity that combines technical capabilities, cr...Show more
    Last updated: 1 day ago • Promoted
    Information Security Architect (Remote)

    Information Security Architect (Remote)

    First Citizens Bank • Raleigh, NC, US
    Remote
    Full-time
    This is a remote role that may be hired in several markets across the United States.Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as ne...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    US Navy • Durham, North Carolina, US
    Part-time
    Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    U.S. Navy • Clayton, NC, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show more
    Last updated: 1 day ago • Promoted
    Research Analyst II - Center for Advanced Hindsight

    Research Analyst II - Center for Advanced Hindsight

    Duke Clinical Research Institute • Durham, NC, United States
    Full-time
    Duke University was created in 1924 through an indenture of trust by James Buchanan Duke.Today, Duke is regarded as one of America's leading research universities. Located in Durham, North Carolina,...Show more
    Last updated: 30+ days ago • Promoted
    IT Security Specialist

    IT Security Specialist

    Sunrise Systems • Raleigh, North Carolina, United States
    Full-time
    Quick Apply
    Duration : 11 Months On Contract.Security Management & Compliance : .Ensure the Epic EHR system is secure and compliant with federal, state, and organizational security policies, including HIPAA, ...Show more
    Last updated: 30+ days ago
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    Local Government Federal Credit Union • Raleigh, North Carolina, United States, 27601
    Full-time
    Our organization believes we can all do well by doing good.We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our...Show more
    Last updated: 30+ days ago
    Senior Information Security Architect (Remote)

    Senior Information Security Architect (Remote)

    First Citizens Bank • Raleigh, NC, US
    Remote
    Full-time
    This is a remote role that may be hired in several markets across the United States.Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as ne...Show more
    Last updated: 30+ days ago • Promoted
    Sr Software Security Architect

    Sr Software Security Architect

    Lenovo • Raleigh, NC, United States
    Full-time
    Here at Lenovo, we believe in smarter technology for all, so we spend our time building a society that's brighter and more inclusive. We're not just a Fortune 500 company, we're one of Fortune's Mos...Show more
    Last updated: 30+ days ago • Promoted
    Microsoft Endpoint Security Engineer (Hybrid)

    Microsoft Endpoint Security Engineer (Hybrid)

    Serigor Inc. • Raleigh, NC, VA, US
    Full-time
    Quick Apply
    Microsoft Endpoint Security Engineer (Hybrid) Location : Raleigh, NC Duration : 12+ Month Job Description : Contractor (Engineer Level) is required to assist with implementing additional security feat...Show more
    Last updated: 12 days ago
    D365 CE Functional Architect

    D365 CE Functional Architect

    Avanade • Durham, NC, United States
    Full-time
    As a D365 CE Functional Architect, you'll engage deeply with clients to understand their needs, translating them into viable, value-driven D365 CE solutions. You'll collaborate with cross-functional...Show more
    Last updated: 1 day ago • Promoted
    IT Analyst, AUDS

    IT Analyst, AUDS

    Duke Clinical Research Institute • Durham, NC, United States
    Full-time
    The Office of Information Technology at Duke University is seeking an OIT-AUDS IT Analyst to join our team.This role is crucial in delivering top-tier technical computing support services to the Du...Show more
    Last updated: 28 days ago • Promoted
    Network Security Engineer

    Network Security Engineer

    Openkyber • NC, United States
    Full-time
    Quick Apply
    We are seeking a senior Information Security / Privacy Analyst with 8 12+ years of experience to support security assessments, risk management, and compliance activities for federal systems.This ro...Show more
    Last updated: 30+ days ago
    VP, Identity & Access Management Engineering Lead

    VP, Identity & Access Management Engineering Lead

    Banc of California • Durham, NC, United States
    Full-time
    BANC OF CALIFORNIA AND YOUR CAREER.NYSE : BANC) is a bank holding company headquartered in Los Angeles with one wholly-owned banking subsidiary, Banc of California (the "bank").Banc of California is...Show more
    Last updated: 1 day ago • Promoted