29 ago
|
Jones Lang Lasalle
|
España
29 ago
Jones Lang Lasalle
España
Experteer Overview
As a Senior Application Security Architect, you will bridge application security engineering with enterprise security architecture to safeguard JLL’s complex real estate platforms.
You will design and own security architectures for apps, cloud-native environments, and integrations, guiding secure SDLC practices and threat modeling.
You’ll act as a technical authority on secure design patterns, mentoring peers and aligning efforts across engineering, architecture, and business teams.
You will drive secure digital transformation with a focus on reducing risk and enabling scalable, secure delivery.
Compensaciones / Ventajas
• Design and maintain security architecture standards, policies, and patterns for enterprise apps, platforms, and cloud-native environments
• Develop secure design patterns, ADRs, and architecture guidance across development teams
• Lead security architecture reviews against OWASP, NIST, and SANS frameworks
• Incorporate zero-trust and defense-in-depth strategies into application architecture
• Define enterprise security requirements and produce metrics to measure compliance
• Lead threat modeling sessions and provide remediation guidance for feature development
• Champion secure coding standards and developer security enablement programs
• Analyze security requirements across technology domains to address risk and regulatory obligations
• Communicate security designs and risk assessments to technical and non-technical stakeholders
• Coordinate security design reviews and cross-team alignment between security, engineering, and enterprise architecture
• Contribute to the application security strategy roadmap and identify emerging threats
• Mentor junior security engineers and developers on secure design practices
• Lead cross-functional security initiatives and drive integration across development and architecture teams
• Support secure development training to build security competency across engineering organizations
Responsabilidades
• Comprehensive knowledge of application security methodologies (OWASP, SANS/CWE) and security architecture patterns
• Experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containers
• Proficiency in Dev
SecOps tooling (SAST, DAST, SCA, container image scanning, secrets management, CI/CD security)
• Experience with NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust principles
• Working knowledge of IAM, OAuth 2.0/OIDC, and app-layer auth controls
• Understanding of cryptography, data protection, encryption, and PKI
• Familiarity with threat modeling methods (STRIDE, PASTA)
• Knowledge of OWASP GenAI, LLM Top 10, Security Exchange, Ai Exchange a plus
• Bachelor's degree and 7+ years in information security focusing on application security or architecture
• Relevant certifications (CSSLP, CISSP, AWS/Azure Security Specialty, OSCP) preferred
Requisitos principales
•
📌 Lead Application Security Architect (España)
🏢 Jones Lang Lasalle
📍 España