This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Application Security Architect is a senior, influential role responsible for orchestrating and leading Arrive’s global application security strategy. As a core member of the Global Security Architecture & Engineering team, you will act as the central driver for how we securely design, build, and deploy software across the company. Your primary focus is to unite our efforts by creating, standardizing, and scaling our Secure Software Development Lifecycle (SSDLC) globally. This involves building upon the expertise and best practices that already exist within our teams and forging a powerful partnership with the Platform Security team in Engineering. You will lead by unifying—setting global standards that empower our developers and security engineers and ensuring the security of our next generation of products and platforms.
Job Responsibility
Champion and orchestrate the definition of Arrive’s global Secure Software Development Lifecycle (SSDLC), from threat modeling to secure release, in close partnership with key stakeholders across Engineering and IT
Develop and maintain a comprehensive set of global security standards, baselines, and guidelines for secure coding, vulnerability management, and secure architecture
Create and champion the strategy for our application security tooling, including SAST, DAST, IAST, and Software Composition Analysis (SCA)
Define and manage the application security standards for Mergers & Acquisitions, establishing clear requirements and guiding the architectural integration of acquired technologies
Act as a lead security consultant and strategic partner for product and engineering teams, providing expert guidance on secure design patterns and vulnerability remediation
Forge a dynamic partnership with the Platform Security team: co-design the security tooling roadmap, consume their platforms where they meet global standards, and introduce new architectural patterns where needed
Lead security architecture reviews and threat modeling sessions for new applications and high-risk features
Act as a senior mentor and advocate for security engineers and champions across the organization, helping to grow our security talent
Stay at the forefront of emerging application security threats, with a particular focus on the risks associated with AI/ML systems
Collaborate with Data & AI teams to develop security principles and architectural patterns for securely integrating AI into our products
Drive innovation in our security practices, continuously seeking opportunities to automate and improve the effectiveness of our AppSec program
Lead the strategy for leveraging AI within the AppSec program, both to mature the SSDLC and to establish the secure-by-design principles required for our AI-first engineering landscape
Requirements
10+ years of experience in technology, with at least 7 years in a dedicated application security or product security role
Demonstrated experience designing and implementing a Secure SDLC in a cloud-native environment (GCP, AWS)
Hands-on experience with the architecture and strategy of AppSec tools (e.g., Snyk, Checkmarx, Veracode,)
Experience with securing microservices architectures, APIs, and modern web/mobile applications
Experience with securing AI/ML systems
A Bachelor’s degree in a relevant field or equivalent professional experience