1

Application Security Architect Jobs (NOW HIRING)

Lead Security Architect | Enterprise, Cloud & Application Security Location: Phoenix, AZ (Day 1 Onsite) Duration: Long-Term Contract Interview : Inperson We are seeking a highly experienced Lead ...

The Application Security Architect will report to the Application Security Architect Lead and will be responsible for assuring that IT application software and infrastructure is designed, implemented ...

Lead Security Architect | Enterprise, Cloud & Application Security Location: Phoenix, AZ (Day 1 Onsite) Duration: Long-Term Contract Interview : Inperson We are seeking a highly experienced Lead ...

AI-Application Security Engineer

Saint Louis, MO · On-site

$57 - $76.25/hr

In partnership with the AI-Application Security Architect, contribute to detailed technical design and operationalize security architecture, standards, and approved security patterns across ...

In partnership with the AI-Application Security Architect, contribute to detailed technical design and operationalize security architecture, standards, and approved security patterns across ...

In partnership with the AI-Application Security Architect, contribute to detailed technical design and operationalize security architecture, standards, and approved security patterns across ...

next page

Showing results 1-20

Application Security Architect information

See salary details

$131K

$161.2K

$211K

How much do application security architect jobs pay per year?

As of Jul 24, 2026, the average yearly pay for application security architect in the United States is $161,211.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $169,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Application Security Architects when integrating security into the software development lifecycle (SDLC)?

Application Security Architects often encounter challenges such as balancing security requirements with agile development timelines and ensuring that security measures do not impede developer productivity. They must work closely with development teams to embed security practices early in the SDLC, which can involve overcoming resistance to change and fostering a security-first mindset. Additionally, they need to stay updated on emerging threats and technologies to provide relevant guidance and solutions, making ongoing communication and collaboration critical to success.

What does an Application Security Architect do?

An Application Security Architect is responsible for designing and implementing security measures within software applications to protect them from threats and vulnerabilities. They work closely with development teams to ensure secure coding practices, conduct security assessments, and integrate security controls throughout the software development lifecycle. Their goal is to minimize security risks and ensure compliance with regulatory requirements and industry best practices.

What is the difference between Application Security Architect vs Security Engineer?

AspectApplication Security ArchitectSecurity Engineer
CredentialsCertifications like CISSP, CSSLP, CEHCertifications like CISSP, Security+
Work EnvironmentDesigns security frameworks, oversees security architectureImplements security measures, monitors systems
Industry UsageUsed in organizations with complex applications and security needsCommon across various industries for security operations

The Application Security Architect focuses on designing and overseeing security architecture for applications, ensuring security best practices are integrated from the ground up. In contrast, the Security Engineer implements and maintains security measures, responding to threats and vulnerabilities. Both roles require similar certifications and work in security-focused environments, but their core responsibilities differ in scope and focus.

What Does an Application Security Architect Do?

An application security architect is required to design and manage IT systems and programs and analyze and troubleshoot issues related to security and access. Your main duties in this career are to collaborate with developers and other applications specialists to determine the scope of security necessary for an application. You then design and develop these measures. You also periodically test the security system’s capabilities to ensure that they are working properly. You make recommendations and reports to senior security architects about how to improve security as well.

What cities are hiring for Application Security Architect jobs? Cities with the most Application Security Architect job openings:
Who are the top companies hiring for Application Security Architect jobs? The top employers for Application Security Architect jobs are:
What states have the most Application Security Architect jobs? States with the most job openings for Application Security Architect jobs include:
What job categories do people searching Application Security Architect jobs look for? The top searched job categories for Application Security Architect jobs are:
Infographic showing various Application Security Architect job openings in the United States as of July 2026, with employment types broken down into 77% Full Time, 17% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $161,211 per year, or $77.5 per hour.
Staff Application Security Architect

Staff Application Security Architect

Rock Connections

Detroit, MI

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 5 days ago


Job description

As the Senior Application Security Architect, you work strategically with engineering and product teams to enable the delivery of secure application patterns and software solutions. You design standard security requirements for how applications should be built, deployed, and maintained, ensuring security is baked into the software development lifecycle from the start. You also build and mature team processes that empower development teams to own their software's security posture while mentoring internal security team members.

About therole

  • Perform Security Reviews of applications throughout the SDLC including at the design and implementation phases through formal threat modeling and source code reviews, focusing on designing secure applications from the start and ensuring secure design principles are correctly implemented.

  • Help to set strategic direction for application security initiatives, shift-left processes, and secure coding standards across the enterprise with a focus on treating security as quality.

  • Build relationships and collaborate with software engineering, product, and architecture teams to ensure alignment of company vision and secure coding goals.

  • Continually identify opportunities for improvement within software delivery pipelines and work with engineering leadership to implement automated security guardrails and remediations.

  • Collaborate with business, product owners, architecture, and information security teams to enable the delivery of secure software patterns that support business velocity

  • Coordinate and drive initiatives for AppSec engineers to build, execute, and scale application security strategies.

  • Help to build processes that test the compliance and effectiveness of software security requirements through automated guardrails and continuous security testing.

  • Influence decision-makers in the areas of secure application architecture, API design, authentication/authorization controls, and modern cloud deployment.

  • Create and evangelize application security policy sets and secure design patterns to be used throughout the company that balance velocity and external compliance requirements.

  • Work directly with development and audit teams to help align security architectures against upcoming compliance, regulatory (e.g., SSDF, Executive Orders on Cybersecurity), and contractual landscapes.

  • Mentor software engineers and information security team members on threat modeling, secure code design, and modern vulnerability remediation techniques.

Aboutyou

Minimum Qualifications

  • 10 years of experience in an information security, application development with a secure coding background or software engineering role with a focus on secure code & design principles, OR bachelor's degree in computer science, information security, or a related field and 5 years of experience.

  • Proven experience performing architectural threat modeling on complex systems and applications using formal frameworks (e.g., STRIDE, DREAD, PASTA)

  • Strong ability to read, write, and audit code for security vulnerabilities, with the ability to provide engineering teams with precise, actionable remediation guidance

  • Deep technical familiarity with Java ecosystem (strongly preferred), as well as .NET and/or Python

  • Proficiency in at least one scripting language (e.g., PowerShell, Bash, Python) for automation and custom tooling

  • Demonstrated aptitude for leveraging AI-assisted engineering tools to drive operational efficiency, balanced with the critical thinking required to identify, validate, and correct AI inaccuracies or hallucinations

  • Practical experience or working knowledge of the following:

    • Secure SDLC frameworks

    • DevSecOps pipeline integration (CI/CD)

    • SAST /DAST/SCA/Secret Scanning tooling

    • Identity and access management (OAuth 2.0, OIDC, SAML)

    • Container security (Docker, Kubernetes)

    • OWASP Top 10 / ASVS mappings

    • Familiarity with the MITRE ATT&CK Framework

  • Strong knowledge of fundamental InfoSec concepts, such as least privilege, zero trust architectures, secure input validation, layered security, secure defaults, etc.

  • Deep understanding of modern enterprise security risks such as software supply chain Security, securing & hardening development environments, and identifying and mitigating risk at scale.

Preferred Qualifications

  • Master's degree in computer science, information security, or a related field

  • Advanced expertise in architectural threat modeling and building automated threat modeling capabilities into developer workflows

  • OSCP, OSWE, GWAPT, CISSP, CCSP, or other relevant security certifications

  • Hands-on experience scaling AppSec programs across large engineering organizations, including, integrating secure solutions across an organization's SDLC, and/or experience administering a developer security champion program

  • Strong technical experience with Java

Whatyou'llget

Our team members fuel our strategy,innovationand growth, so we ensure the health and well-being of not just you, but your family, too! We goabove and beyondto give you the support you need on an individual level and offer all sorts of ways to help you live your best life. We are proud to offer eligible team members perks and health benefits that will help you have peace of mind. Simply put:We'vegot your back. Check out our full list ofBenefits and Perks.

On-Call Expectations
This role may include participation in an on-call rotation to support production systems and ensure service reliability. On-call responsibilities may include coverage during nights and weekends. If applicable, frequency and scheduling will bedeterminedby team needs and communicated accordingly.

Aboutus

Rocketis a Detroit-based company made up of businesses that provide simple,fastand trusted digital solutions for complex transactions. The name comes from our flagship business, now known as Rocket Mortgage, which was founded in 1985. Today,we'rea publicly traded company involved in many different industries, including mortgages, fintech, realestateand more.We'reinsistently different in how we look at the world and are committed to an inclusive workplace where every voice is heard.Apply today to join a team that offers career growth, amazingbenefitsand the chance to work with leading industry professionals.

This job description is an outline of the primary responsibilities of this position and may bemodifiedat the discretion of thecompany at any time. Decisions related to employment are not based on race, color, religion, national origin, sex, physical or mental disability, sexual orientation, gender identity or expression, age, military or veteran status or any other characteristic protected by state or federal law. Thecompany provides reasonableaccommodationsto qualified individuals with disabilitiesin accordance withapplicable state and federal laws. Applicantsrequiringreasonable accommodations in completing the application and/orparticipatingin the application process should contact a member of the Human Resources team, atCareers@Rocket.com.

The compensation information below is provided in compliance with all applicable job posting disclosure requirements. The compensation for this position is$149,000.00-$318,000.00.The position may also be eligible for an annual bonus, incentives, and other employment-related benefits including, but not limited to, medical, dental, and vision benefits, 401K retirement plan, and paid-time off. More informationregardingthese benefits and others can be foundhere. The informationregardingcompensation and other benefits included in this paragraph is the company's current, good faithestimateat the time of posting. [Compensation and benefits are subject to modification from time to time as the Company, in its sole and exclusive discretion,deemsappropriate.] The Company maydetermineduring its future reviews of the proposed compensation and benefits provided for this position, that the compensation and benefits for suchpositionshould be reduced. In no event will the Company reduce the compensation for the position to a level below the applicable jurisdictional minimum wage rate for the position. Los Angeles County and San Francisco Candidates only: qualified applicants with arrest or conviction records will be considered for employment per the Fair Chance Ordinance and the Fair Chance Initiative for Hiring.