Overview
Skills
Job Details
Job Title: Application Security Architect
Location: Charlotte, NC (Hybrid)
Duration: 12+ Months (Contract-to-Hire)
Must Haves:
-
4+ years Systems Architecture; 3+ years Cybersecurity
-
1+ year with Azure, Google Cloud Platform, or AWS; 1+ year Python
-
Experience leading Architecture Risk Reviews & building threat models
-
Proficiency in threat-modeling methodologies (STRIDE, PASTA, OCTAVE, LINDDUN, VAST)
-
Hands-on with ThreatModeler, MS Threat Modeling Tool, or OWASP Threat Dragon
-
Strong knowledge of OWASP Top 10, CAPEC, MITRE ATT&CK, secure design principles
-
Ability to manage multiple concurrent threat models with urgency and quality
-
Strong communication/collaboration; enterprise experience
Day-to-Day:
-
Partner with app/platform teams to understand and document architectures
-
Build threat models and identify/prioritize threats
-
Review designs/config/code for mitigation evidence
-
Recommend security controls and present findings
-
Work with Cybersecurity Architecture to develop new mitigations when needed
Preferred:
-
Security/cloud certs (CISSP, CCSP, Azure/Google Cloud Platform/AWS)
-
Experience with GenAI threat modeling
-
Familiarity with Threat-Modeling-as-Code (TaaC)