Application Security Architect

Remote Relocation
Apply
AI Summary

Design and implement secure architecture standards for web, mobile, and cloud applications. Collaborate with development teams to ensure secure design principles. Provide training and guidance on secure development practices.

Key Highlights
Define security architecture standards and blueprints
Collaborate with DevOps and Engineering teams
Provide training and guidance on secure development practices
Key Responsibilities
Define security architecture standards and blueprints for web, mobile, cloud, and API-based applications
Review design documents and perform architecture risk assessments for new and existing applications
Collaborate with DevOps, Engineering, and Infrastructure teams to ensure architectures align with secure design principles
Integrate automated security testing/scanning tools into Continuous Integration (CI) or Continuous Delivery (CD) pipelines
Define and enforce secure coding standards and practices across development teams
Provide training and guidance to developers on secure development principles and vulnerability prevention
Conduct threat modeling and attack surface reviews for high-risk or critical applications
Identify potential security flaws and recommend mitigations early in development process
Track and communicate technical risk to product managers, developers, and leadership teams
Develop and maintain application security policies, baselines, and architecture frameworks
Ensure application security practices align with regulations including GDPR and PCI-DSS
Technical Skills Required
Static Application Security Testing (SAST) Software Composition Analysis (SCA) Open Web Application Security Project (OWASP) Top 10 National Institute of Standards and Technology (NIST) Secure Software Development Life Cycle (SDLC) Web Application Firewall (WAF) implementation Identity and Access Management Cloud security practices (AWS, Azure) Container security (Docker, Kubernetes) Authentication protocols (Open Authorization (OAuth) and Security Assertion Markup Language (SAML)) DevSecOps tools and container security tools
Benefits & Perks
Health/Dental/Vision/Prescription Drug Plan
Flexible Benefits Plan
401K Retirement Savings Plan
Life and Disability Benefits
Paid Parental Leave
Paid Holidays
Paid Vacation
Tuition Reimbursement
Nice to Have
Experience with Securing Secrets and Service Accounts
Experience with Web Application Firewall (WAF) implementation/support
Familiarity with Identity and Access Management and cloud security practices (AWS, Azure)
Certified Information Systems Security Professional (CISSP)
Familiarity with container security (Docker, Kubernetes)
Understanding of authentication protocols (Open Authorization (OAuth) and Security Assertion Markup Language (SAML))
Experience with DevSecOps tools and container security tools

Job Description


Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world’s largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.


Remote Work: Crown offers hybrid remote work for this position. A reasonable commute is necessary as some onsite work is required. Relocation assistance is available.


Primary Responsibilities

  • Define security architecture standards and blueprints for web, mobile, cloud, and Application Programming Interface (API)-based applications.
  • Review design documents and perform architecture risk assessments for new and existing applications.
  • Collaborate with DevOps, Engineering, and Infrastructure teams to ensure architectures align with secure design principles.
  • Integrate automated security testing/scanning tools (Static Application Security Testing (SAST), Software Composition Analysis (SCA)) into Continuous Integration (CI) or Continuous Delivery (CD) pipelines.
  • Define and enforce secure coding standards and practices across development teams.
  • Provide training and guidance to developers on secure development principles and vulnerability prevention.
  • Conduct threat modeling and attack surface reviews for high-risk or critical applications.
  • Identify potential security flaws and recommend mitigations early in development process.
  • Track and communicate technical risk to product managers, developers, and leadership teams.
  • Develop and maintain application security policies, baselines, and architecture frameworks.
  • Ensure application security practices align with regulations including General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI-DSS).
  • Support audit and compliance initiatives by providing documentation and evidence of secure development practices.


Minimum Qualifications

  • Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related field is required, along with 2-4 years related experience. Non-degree considered if 12+ years of related experience along with a high school diploma or GED


Preferred Qualifications

  • 5+ years in cybersecurity with at least 3 years in application security or secure software development experience.
  • Secure Software Development Life Cycle (SDLC) in development. Deep knowledge of Open Web Application Security Project (OWASP) Top 10, National Institute of Standards and Technology (NIST), and secure coding frameworks.
  • Experience with Securing Secrets and Service Accounts desired.
  • Experience with Web Application Firewall (WAF) implementation/support preferred.
  • Familiarity with Identity and Access Management and cloud security practices (AWS, Azure).
  • Certified Information Systems Security Professional (CISSP), or similar certification (Certified Secure Software Lifecycle Professional, Certified Ethical Hacker (CEH) certified).
  • Familiarity with container security (Docker, Kubernetes).
  • Understanding of authentication protocols (Open Authorization (OAuth) and Security Assertion Markup Language (SAML)).
  • Experience with DevSecOps tools and container security tools desired.


Work Authorization:

Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.


No agency calls please.


Compensation and Benefits:

Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.

EOE Veterans/Disabilities


Similar Jobs

Explore other opportunities that match your interests

Security Intern

Cyber Security
2h ago
Visa Sponsorship Relocation Remote
Job Type Internship
Experience Level Internship

voltus

United State

Principal or Sr. Principal Cybersecurity Systems Engineer

Cyber Security
2h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State

Principal or Sr. Principal Cybersecurity Systems Engineer

Cyber Security
3h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State

Subscribe our newsletter

New Things Will Always Update Regularly