12 дней назад
Senior Application Security Architect (AI & API)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Architect (AI & API) (Application Security, AI, and APIs): Guiding engineering teams in designing and securing application, API, and AI/agentic architectures with an accent on secure SDLC, authentication, authorization, API gateways, and cloud-native systems. Focus on threat modeling LLM-powered components, preventing prompt injection and data exfiltration, governing AI-assisted development, and translating architectural tradeoffs into secure implementation guidance.
Location: United Kingdom
Company
provides business travel services and technology while promoting travel as a force for good.
What you will do
- Guide application, API, and AI/agentic architecture decisions, explaining tradeoffs between REST, GraphQL, gRPC, synchronous and event-driven designs, and AI frameworks.
- Partner hands-on with engineering teams to implement authentication, authorization, API gateways, AI gateways, and secure cloud-native architectures.
- Assess existing applications, APIs, and AI implementations using SAST, DAST, SCA, API security, and AI security tooling.
- Lead threat modeling and secure design reviews for applications, APIs, AI/ML services, and agentic systems.
- Define application, API, and responsible AI governance policies with engineering, security, legal, and product leadership.
- Develop security decision frameworks, documentation, KPI reporting, and technical guidance while mentoring engineers and representing the organization in industry standards efforts.
Requirements
- 10+ years of experience in software engineering, application security, or security architecture.
- Strong expertise in secure SDLC, vulnerability management, SAST/DAST/SCA, secure coding, OWASP Top 10, API security, OAuth 2.0, OpenID Connect, JWT/JOSE, and API gateway or service mesh architectures.
- Hands-on experience with AWS, Azure, or GCP and Kubernetes.
- Practical experience with AI-native and agentic development tools and understanding of the security risks of AI-assisted and autonomous workflows.
- Strong background in applied cryptography, threat modeling, secure design reviews, architecture governance, and secure software design.
- Proficiency in multiple programming languages such as Go, Java, or Python, plus strong written and verbal communication skills. A bachelor's degree or equivalent practical experience is required.
Nice to have
- Advanced degree in Computer Science, Artificial Intelligence, or a related field.
- Publications, conference talks, published CVEs, or contributions to OAuth, JOSE, or other security standards bodies.
- Experience with PCI-DSS and securing AI/LLM-powered systems, agentic architectures, and AI gateway deployments.
- Experience leading application security programs or mentoring engineering teams at principal, staff, or architect level.
Culture & Benefits
- Inclusive and collaborative environment with opportunities to contribute to company-wide initiatives.
- Country-specific health and welfare insurance, retirement programs, parental leave, adoption assistance, and wellbeing resources.
- Travel deals covering flights, hotels, cruises, car rentals, and other travel services.
- Access to more than 20,000 learning courses, leadership development, and internal career opportunities.
- Inclusion groups supporting discussion, awareness, and action around shared identities and initiatives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →