1

Application Security Architect Jobs in California

Lead Security Architect | Enterprise, Cloud & Application Security Location: Phoenix, AZ (Day 1 Onsite) Duration: Long-Term Contract Interview : Inperson We are seeking a highly experienced Lead ...

Lead Security Architect | Enterprise, Cloud & Application Security Location: Phoenix, AZ (Day 1 Onsite) Duration: Long-Term Contract Interview : Inperson We are seeking a highly experienced Lead ...

The Security Architect will work closely with various infrastructure, application, and business teams globally to provide guidance and technical thought leadership, as well as helping to lead design ...

The Security Architect will work closely with various infrastructure, application, and business teams globally to provide guidance and technical thought leadership, as well as helping to lead design ...

The Security Architect will work closely with various infrastructure, application, and business teams globally to provide guidance and technical thought leadership, as well as helping to lead design ...

Product Security Architect III

San Jose, CA · On-site

$76.25 - $98.50/hr

Product Security Architect III Our Technology Team partners with teams across Expedia Group to ... Provide technical leadership on application security controls (authentication, authorization ...

next page

Showing results 1-20

Application Security Architect information

See California salary details

$129.3K

$159.1K

$208.2K

How much do application security architect jobs pay per year?

As of Aug 31, 2026, the average yearly pay for application security architect in California is $159,100.00, according to ZipRecruiter salary data. Most workers in this role earn between $141,100.00 and $167,300.00 per year, depending on experience, location, and employer.

What does an Application Security Architect do?

An Application Security Architect is responsible for designing and implementing security measures within software applications to protect them from threats and vulnerabilities. They work closely with development teams to ensure secure coding practices, conduct security assessments, and integrate security controls throughout the software development lifecycle. Their goal is to minimize security risks and ensure compliance with regulatory requirements and industry best practices.

What does an Application Security Architect do?

An application security architect is required to design and manage IT systems and programs and analyze and troubleshoot issues related to security and access. Your main duties in this career are to collaborate with developers and other applications specialists to determine the scope of security necessary for an application. You then design and develop these measures. You also periodically test the security system’s capabilities to ensure that they are working properly. You make recommendations and reports to senior security architects about how to improve security as well.

What are some common challenges faced by Application Security Architects when integrating security into the software development lifecycle (SDLC)?

Application Security Architects often encounter challenges such as balancing security requirements with agile development timelines and ensuring that security measures do not impede developer productivity. They must work closely with development teams to embed security practices early in the SDLC, which can involve overcoming resistance to change and fostering a security-first mindset. Additionally, they need to stay updated on emerging threats and technologies to provide relevant guidance and solutions, making ongoing communication and collaboration critical to success.

What is the difference between Application Security Architect vs Security Engineer?

AspectApplication Security ArchitectSecurity Engineer
CredentialsCertifications like CISSP, CSSLP, CEHCertifications like CISSP, Security+
Work EnvironmentDesigns security frameworks, oversees security architectureImplements security measures, monitors systems
Industry UsageUsed in organizations with complex applications and security needsCommon across various industries for security operations

The Application Security Architect focuses on designing and overseeing security architecture for applications, ensuring security best practices are integrated from the ground up. In contrast, the Security Engineer implements and maintains security measures, responding to threats and vulnerabilities. Both roles require similar certifications and work in security-focused environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Application Security Architect jobs in California?

For Application Security Architect jobs in California, the most frequently searched job titles are:

What job categories do people searching Application Security Architect jobs in California look for?

The top searched job categories for Application Security Architect jobs in California are:

Infographic showing various Application Security Architect job openings in California as of August 2026, with employment types broken down into 73% Full Time, 21% Part Time, and 6% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $159,100 per year, or $76.5 per hour.

Executive Director, Application Security Architect

Culver City, CA • On-site

Sony Pictures Entertainment
Travel Arrangement Services • 1 - 10 employees

Full-time

Re-posted 12 days ago


Job description

We are seeking a visionary and hands-on Executive Director of Security Architecture with mature skill in Application Security/DevSecOps, Data Security and Cloud who will excel in leading the strategic design, implementation, and continuous improvement of Sony Pictures application security posture. This is a highly influential role, requiring both deep technical expertise and business-aligned leadership. The ideal candidate will have previous experience in application architecture and engineering and is now focused on information and cybersecurity to define robust security design patterns, reference architecture across applications, data, and cloud environments, proactively addressing cyber risks and promoting secure coding practices aligned with the Sony Pictures goals.
Key Responsibilities
  • Strategic Vision: Develop and articulate a comprehensive security architecture strategy for application, data and cloud for Sony Pictures information and content assets. Continuously evaluate emerging threats and industry best practices to evolve our security posture.
    • Define, document, and promote security architecture, DevSecOps, and technical standards throughout Sony Pictures.
    • Lead the development and implementation of comprehensive security architecture strategies for application, data and cloud environments to protect against current and emerging threats.
  • Architecture Design and Engineering: Lead hands-on design and implementation reviews of security solutions across application, data and cloud domains. Thoroughly assess security risks in existing and planned systems and infrastructure. Define technical security standards and governance processes.
    • Lead security architecture review processes, ensuring all new systems and changes to existing systems comply with Sony's security standards.
    • Conduct in-depth assessments of current security architectures, identify threats and vulnerabilities, and develop mitigation strategies.
    • Recommend design patterns and security best practices for technology and application implementations.
  • Security Solution Evaluation and Selection: Research, evaluate, and recommend cutting-edge security technologies and tools. Oversee proof-of-concept initiatives and guide vendor selection.
    • Conduct market research to assess the landscape of available security solutions in specific areas (e.g., data security, cloud security, application security).
    • Liaise with IT and security operations teams to define and orchestrate POC testing for shortlisted security solutions.
  • Enterprise Security: Work closely with IT infrastructure, application development, DevSecOps, and business stakeholders to embed application security principles throughout all phases of technology development and deployment.
    • Develop and maintain security architecture documentation and standards.
    • Collaborate with IT and business units to integrate security best practices into the development lifecycle of projects and technology initiatives.
  • Governance and Compliance Maintain a deep understanding of security regulations and frameworks (e.g., NIST, ISO 27001, PCI DSS, OWASP, SAFECode) for designing systems and processes that not only protect data but also demonstrate adherence to industry standards and regulations.

Required Qualifications
Technical Skills
  • Mastery of Security Architecture Principles: Deep understanding of defense-in-depth strategies, zero-trust models, identity and access management (IAM), AI Security, Product Security, Threat modeling, GPDR and privacy, vulnerability assessment techniques, DevSecOps, Secure Coding Principles and Practices.
  • Application Security Expertise: Demonstrated experience with Full Stack WebApp/API, firewalls (WAFs), secure software development lifecycles (S-SDLCs), DevSecOps, IaC, Docker/Container Security, Data Security, static/dynamic application security testing (SAST/DAST), API security, Authentication/Authorization Best Practices, and Secure Coding Standards and Techniques.
  • Cloud Security Expertise: Proficient in cloud security models (IaaS, PaaS, SaaS), cloud-native security tools, encryption and key management, privileged access management (PAM), security posture and compliance within cloud environments, mainly AWS and Azure.
  • Network Security Expertise: Excellent knowledge of firewalls, intrusion detection/prevention systems (IDS/IPS), network segmentation, VPNs, network access control (NAC), DMZ design, and DDoS mitigation.
  • Proficiency in Major Frameworks: Demonstrated knowledge of NIST Cybersecurity Framework, ISO 27001/27002, PCI DSS (if handling payment card data), OWASP, SAFECode, and other relevant entertainment industry guidelines such as TPN and MotionLabs.
  • Translation to Practice: The ability to take concepts from frameworks and benchmarks and apply them practically to the design of security solutions. This includes mapping controls, risk assessment techniques, and documentation in alignment with standards.

Leadership Skills
  • Leadership: Strong ability to lead, motivate, and develop a team of security professionals. Foster a collaborative and results-oriented environment.
  • Strategic Thinking: Capacity to align security objectives with Sony broader business and Cybersecurity goals, effectively quantifying risks and prioritizing initiatives for optimal impact.
  • Communication and Influence: Excellent written and verbal communication skills. The ability to translate technical concepts for non-technical audiences and secure buy-in at the executive level.
  • Problem-solving: Analytical mindset with demonstrated adeptness in solving complex security challenges.
  • Adaptability: Ability to thrive in a dynamic, fast-paced environment where technologies and threat landscapes rapidly evolve.

Education and Experience
  • Bachelor's degree in Computer Science, Information Security, or a related field. Advanced technical certifications strongly preferred (CISSP, CCSP, CSSLP, OSCP, or vendor-specific architecture and security certifications).
  • Minimum of 10+ years of progressive experience in cybersecurity, application security engineering, with at least 5+ years in a security architecture leadership role with hands-on experience.

The anticipated base salary for this position is $205,000-$258,000. This role may also qualify for annual incentive and/or comprehensive benefits. The actual base salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location of the position.
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, age, sexual orientation, gender identity, or other protected characteristics.
SPE will consider qualified applicants with arrest or conviction records in accordance with applicable law.
Sony Pictures does not allow audio recording, video recording or use of AI note-taking tools during interviews. Please be aware these tools may be enabled as a default and can be difficult to disable once the interview has started, so we recommend you check your device and disable these tools prior to the start of your interview. If recording or the use of the tools occurs during the interview and cannot be promptly turned off or disabled, the interviewer may end the interview.
To request an accommodation for purposes of participating in the hiring process, you may contact us at SPE_Accommodation_Assistance@spe.sony.com.