Sr Application Security Architect
We’re a leader in data and AI, inspiring customers around the world to transform data into intelligence and questions into answers. Join us for a dynamic, fulfilling career with flexibility and a world-class employee experience.
About The Role
The Risk Solution division is looking for a Senior Application Security Architect to be a key contributor to SAS solution security. Successful candidates will partner with architecture, engineering, and cloud hosting teams to solve complex technical problems across the Software Development Lifecycle (SDLC), from design and development through deployment and operations. This role requires technical security breadth and depth, along with clear, concise, and effective communication skills. Collaboration is key to meeting legal, compliance, and customer security requirements while providing SAS customers with the most trustworthy solutions globally.
Responsibilities
- Collaborate across R&D and cloud hosting teams to strategically improve the security posture of business-critical multi-tier solutions in legacy, hybrid cloud, and public cloud environments. Includes tactical refactoring, environment promotion, and Secure by Default deployment and configuration to maintain security consistency across all environments.
- Plan evolutionary paths for secure architectures and systems, incorporating third-party architectures and adopting new technologies while maintaining a robust security posture. Employ security compensating controls, defense in depth, and Zero Trust Architectural principles.
- Work with development teams to provide security assessment and hardening of products spanning the SDLC, including secure design, threat modeling, code reviews, and direct verification to identify and triage vulnerabilities.
- Collaborate with Product Management stakeholders to ensure security implementations align with business objectives, customer requirements, and global regulations.
- Identify, train, and partner with Security Champions within product R&D teams to assess and gauge risk, identifying security gaps in products and integrated solutions.
- Create and maintain secure engineering documentation, guidance, and training collateral supporting PSO standards, policies, and procedures.
- Collaborate with other security teams to identify new tools and processes for integration into the Secure SDLC.
- Recommend and promote software security policies, standards, and procedures to improve the global SAS security posture.
- Mentor and coach within the Product Security Office and other Security Architects to build subject matter expertise.
- Ensure compliance with all applicable security policies and processes to support the organization's secure software development goals.
Requirements
- 8+ years of experience in secure software development, secure system architecture and design, or related fields.
- 4+ years of experience in developing or adopting software security best practices.
- Bachelor's degree in Computer Science, Electrical Engineering, or a related field.
- Relevant security certifications such as SANS, GIAC, ISACA CEH, CCSP, CSSLP, CISM, or CISSP.
- Knowledge of current global enterprise security risks and attacker TTPs as published by MITRE.
- Experience with programming languages such as C/C++, Java, Python, JavaScript, PHP, or Golang for code review and providing prescriptive security guidance.
- Expertise in securing enterprise web applications and familiarity with OWASP Top 10, CVSS, CWE, and SANS-25.
- Experience with security best practices for modern R&D, including microservices, containers, Agentic AI, and hyper-scale cloud hosting and operations.
- Equivalent combination of related education, training, and experience may be considered.
Skills
- Experience with cloud hosting and operational security for public clouds (Azure, AWS, or GCP) and hybrids, including domains and requirements in the Microsoft Cloud Security Benchmark (MCSB).
- Experience with SAST tools such as Snyk, Black Duck, or Sonar.
- Experience with DAST/IAST tools such as ZAP, BurpSuite, Kali, or Nessus.
- Knowledge of and experience with auditing, implementing, and supporting Dev(Sec)Ops.
- Continuous Improvement: Originating action to improve existing conditions and processes; identifying improvement opportunities, generating ideas, and implementing solutions.
- Work Standards: Setting high standards of performance for self and others; assuming responsibility and accountability for assignments; self-imposing standards of excellence.
- Quality Orientation: Accomplishing tasks by considering all areas involved; showing concern for all aspects of the job; accurately checking processes and tasks.
Benefits
- Comprehensive medical, prescription, dental, and vision plans with multiple options, including a PPO with low annual deductible and copays, or an HDHP combined with a health savings account (HSA) with a SAS contribution.
- Onsite Health Care Center (HQ) free to employees and family members enrolled in the PPO plan, including a pharmacy with free shipping for remote employees.
- Industry-leading 401k plan.
- Tuition Assistance Program and resources to support professional development.
- Generous time off, including vacation, paid holidays, a U.S. Winter Wellness Break (December 25 – January 1), Volunteer Time Off, parental leave, and unlimited paid sick days.
- Generous childcare benefits for all full-time employees.
Applicants must be legally authorized to work in the United States or Scotland and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer.