15 sep
|
Jones Lang Lasalle
|
Barcelona
15 sep
Jones Lang Lasalle
Barcelona
Overview
As a Senior Application Security Architect, you will bridge application security engineering with enterprise security architecture to safeguard JLL's complex real estate platforms. You will design and own security architectures for apps, cloud-native environments, and integrations, guiding secure SDLC practices and threat modeling. You'll act as a technical authority on secure design patterns, mentoring peers and aligning efforts across engineering, architecture, and business teams.
You will drive secure digital transformation with a focus on reducing risk and enabling scalable, secure delivery.
Responsabilidades
Design and maintain security architecture standards, policies, and patterns for enterprise apps, platforms, and cloud-native environments
Develop secure design patterns, ADRs, and architecture guidance across development teams
Lead security architecture reviews against OWASP, NIST, and SANS frameworks
Incorporate zero-trust and defense-in-depth strategies into application architecture
Define enterprise security requirements and produce metrics to measure compliance
Lead threat modeling sessions and provide remediation guidance for feature development
Champion secure coding standards and developer security enablement programs
Analyze security requirements across technology domains to address risk and regulatory obligations
Communicate security designs and risk assessments to technical and non-technical stakeholders
Coordinate security design reviews and cross-team alignment between security, engineering, and enterprise architecture
Contribute to the application security strategy roadmap and identify emerging threats
Mentor junior security engineers and developers on secure design practices
Lead cross-functional security initiatives and drive integration across development and architecture teams
Support secure development training to build security competency across engineering organizations
Requisitos principales Comprehensive knowledge of application security methodologies (OWASP, SANS/CWE) and security architecture patterns
Experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containers
Proficiency in DevSecOps tooling (SAST, DAST, SCA, container image scanning, secrets management, CI/CD security)
Experience with NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust principles
Working knowledge of IAM, OAuth 2.0/OIDC, and app-layer auth controls
Understanding of cryptography, data protection, encryption, and PKI
Familiarity with threat modeling methods (STRIDE, PASTA)
Knowledge of OWASP GenAI, LLM Top 10, Security Exchange, Ai Exchange a plus
Bachelors degree and 7+ years in information security focusing on application security or architecture
Relevant certifications (CSSLP, CISSP, AWS/Azure Security Specialty, OSCP) preferred
Strong communication with diverse stakeholders
Mentoring and leadership of junior engineers
Independent, proactive initiative on security initiatives
OWASP Top 10
SANS/CWE secure development frameworks
📌 Lead Application Security Architect (Barcelona)
🏢 Jones Lang Lasalle
📍 Barcelona