Haystack
← Back to Jobs
Administrative

Application Security Architect – AWS(15+ EXP)

V-Work Infotech Solutions INCUnited States🇺🇸United StatesPosted 7 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-WEB:1f105e79-b632-42f4-bfb2-57710bbc985e-0" data-turn-id-container="request-WEB:1f105e79-b632-42f4-bfb2-57710bbc985e-0" data-testid="conversation-turn-2" data-turn="assistant">
  • 15+ years of experience in Application Security, Product Security, or DevSecOps, including 3+ years securing AWS-based applications.
  • Strong expertise in securing applications throughout the Secure Software Development Lifecycle (SSDLC).
  • Perform threat modeling and secure architecture reviews for applications, APIs, microservices, and cloud-native workloads.
  • Hands-on experience securing AWS services including EC2, ECS/EKS, Lambda, API Gateway, IAM, WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, and CloudTrail.
  • Implement and manage security controls across CI/CD pipelines using SAST, DAST, SCA, container image scanning, and Infrastructure-as-Code (IaC) scanning.
  • Integrate security into GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline, or similar CI/CD platforms.
  • Configure and enforce least-privilege IAM policies, role-based access control (RBAC), secrets management, and encryption standards.
  • Conduct secure code reviews and vulnerability assessments using OWASP Top 10, CWE, and secure coding best practices.
  • Experience with security tools such as SonarQube, Checkmarx, Veracode, Snyk, Prisma Cloud, Aqua Security, Burp Suite, and OWASP ZAP.
  • Secure containerized workloads using Docker, Kubernetes (EKS), ECS, and serverless applications using AWS Lambda.
  • Perform Infrastructure-as-Code (IaC) security using Terraform or CloudFormation with Checkov, tfsec, cfn-nag, or similar tools.
  • Develop automation scripts using Python, Go, or similar languages for security validation and compliance.
  • Strong understanding of API security, OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and authentication/authorization mechanisms.
  • Implement cloud security guardrails using AWS Organizations, Service Control Policies (SCPs), AWS Config, and policy-as-code frameworks such as OPA.
  • Coordinate penetration testing activities, validate findings, and drive remediation with development teams.
  • Support security audits and compliance initiatives including SOC 2, ISO 27001, PCI-DSS, HIPAA, and FedRAMP.
  • Respond to application security incidents, investigate threats, and develop detection rules and incident response runbooks.
  • Experience with Cloud Native Application Protection Platforms (CNAPP) such as Wiz, Prisma Cloud, or CrowdStrike Falcon Cloud.
  • Strong knowledge of threat modeling methodologies including STRIDE and PASTA.
  • Collaborate with development, DevOps, infrastructure, and client security teams to promote DevSecOps best practices.
  • Mentor engineering teams on secure coding, cloud security, and vulnerability remediation.
  • Excellent communication, analytical, troubleshooting, and stakeholder management skills.
  • AWS Certified Security – Specialty preferred; CSSLP, CISSP, or OSWE certifications are highly desirable.
  • Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or a related field.
  •  
     

    Skills

    SAFe
    Stakeholder Management

    Similar jobs

    Apply now