About the Company
We are seeking a highly experienced Senior AI & Application Security Architect to lead security architecture for AI-driven and business-critical applications across the enterprise. This role is 100% focused on AI and application security, including internally built agentic applications, AI-assisted and vibe-coded applications, integrations with existing business applications and data, on-prem and cloud application environments, and API security. The ideal candidate will bring deep technical security expertise, strong application and AI security knowledge, and a solid understanding of infrastructure, identity, cloud, networking, and enterprise architecture to ensure secure-by-design solutions that are practical, scalable, and aligned with business needs.
About the Role
We are seeking a highly experienced Senior AI & Application Security Architect to lead security architecture for AI-driven and business-critical applications across the enterprise.
Responsibilities
- AI & Application Security Architecture
- Lead security architecture for AI-enabled applications, internal agentic applications, LLM-based solutions, RAG pipelines, AI integrations, and business-critical applications.
- Define secure-by-design architecture patterns, guardrails, and technical standards for applications built internally, by vendors, or using AI-assisted and vibe coding approaches.
- Review and approve application designs, AI workflows, data flows, integrations, APIs, identity models, and access patterns before production deployment.
- Ensure applications are secure across on-prem, cloud, SaaS, hybrid, containerized, and API-driven environments.
- Translate security requirements into practical engineering controls, reference architectures, reusable patterns, and automated guardrails.
- AI, Agentic Apps & Data Security
- Lead AI security reviews for internal and third-party AI solutions, including agentic applications, copilots, chatbots, automation agents, AI-assisted workflows, and embedded AI features.
- Design security controls for prompt injection, data leakage, excessive agency, insecure tool use, model/API abuse, unsafe plugins, malicious content handling, and sensitive data exposure.
- Define governance, guardrails, approval criteria, and secure implementation patterns for AI adoption across enterprise and R&D environments.
- Assess security risks across AI supply chains, including third-party models, AI APIs, training data, embeddings, vector databases, orchestration layers, and connected tools.
- Establish monitoring, logging, auditability, and incident response requirements for AI and application security events.
- Architect API security controls, including authentication, authorization, OAuth/OIDC, service-to-service access, rate limiting, API gateway protections, API discovery, inventory, and abuse prevention.
- Define threat modeling practices for applications, APIs, AI workflows, agentic behavior, data access, and integrations with enterprise systems.
- Application Security, DevSecOps & Secure SDL
- Embed security into the full application lifecycle, from ideation and architecture through development, testing, deployment, and operations.
- Partner with R&D, DevOps, IT, cloud, data, and business application teams to identify risks and implement scalable security controls.
- Define and improve secure SDLC processes, including SAST, DAST, SCA, secrets scanning, IaC scanning, container security, dependency governance, and remediation workflows.
- Guide vulnerability management for applications and APIs, including risk-based prioritization, remediation guidance, exception handling, and recurring risk reduction.
- Technical Leadership & Advisory
- Act as the security authority for AI and application architecture decisions, providing clear guidance to engineering, IT, data, and leadership teams.
- Evaluate emerging AI, agentic, application, API, and cloud technologies and define secure adoption requirements.
- Lead architecture reviews, security design discussions, risk acceptance processes, and technical governance for AI and application initiatives.
Qualifications
- Experience:
- 10+ years in cybersecurity, with deep experience in application security, AI security, cloud security, secure architecture, and technical security leadership.
- Proven experience securing enterprise applications, business systems, APIs, integrations, SaaS platforms, cloud-native applications, and on-prem application environments.
- Strong hands-on understanding of infrastructure security, including identity, networking, endpoint security, cloud platforms, containers, monitoring, SIEM/XDR, and security operations.
- Deep expertise in application security, API security, threat modeling, secure SDLC, DevSecOps, vulnerability management, authentication, authorization, encryption, secrets management, and secure coding practices.
- Extensive experience working with R&D, DevOps, product engineering, IT, cloud, data, and business application teams.
- Hands-on experience with AI security, including LLM applications, agentic applications, RAG architectures, AI APIs, prompt injection risks, AI data protection, model/API risk, and AI governance.
- Experience reviewing AI-assisted and vibe-coded applications, including validation of generated code, dependencies, permissions, data handling, and production readiness.
- Hands-on experience with Linux and Windows based platforms, cloud services, containers, CI/CD pipelines, and application hosting environments.
- Hands-on experience with AppSec and security tools such as SAST, DAST, SCA, secrets scanning, API security testing, WAF/API gateways, SIEM, XDR, CASB, DLP, and patch management tools.
- Experience with monitoring, automation, orchestration, security-as-code, and automated guardrails for development and deployment environments.
- Certifications: CISSP, CSSLP, GWAPT, AWS/Azure Security, cloud architect certifications, or equivalent hands-on experience.
Required Skills
- Strong technical depth, analytical thinking, architecture judgment, and ability to make risk-based decisions in complex application and AI environments.
- Excellent spoken and written English.
- Ability to influence technical teams without direct authority and translate AI and application security requirements into practical engineering controls.