26 sep
|
Jones Lang Lasalle
|
Barcelona
26 sep
Jones Lang Lasalle
Barcelona
As a Senior Application Security Architect, you will bridge application security engineering with enterprise security architecture to safeguard JLL’s complex real estate platforms. You will design and own security architectures for apps, cloud-native environments, and integrations, guiding secure SDLC practices and threat modeling. You’ll act as a technical authority on secure design patterns, mentoring peers and aligning efforts across engineering, architecture, and business teams. You will drive secure digital transformation with a focus on reducing risk and enabling scalable, secure delivery.Design and maintain security architecture standards, policies, and patterns for enterprise apps, platforms, and cloud-native environmentsDevelop secure design patterns, ADRs, and architecture guidance across development teamsLead security architecture reviews against OWASP, NIST, and SANS frameworksIncorporate zero-trust and defense-in-depth strategies into application architectureDefine enterprise security requirements and produce metrics to measure complianceLead threat modeling sessions and provide remediation guidance for feature developmentChampion secure coding standards and developer security enablement programsAnalyze security requirements across technology domains to address risk and regulatory obligationsCommunicate security designs and risk assessments to technical and non-technical stakeholdersCoordinate security design reviews and cross-team alignment between security, engineering,
and enterprise architectureContribute to the application security strategy roadmap and identify emerging threatsMentor junior security engineers and developers on secure design practicesLead cross-functional security initiatives and drive integration across development and architecture teamsSupport secure development training to build security competency across engineering organizationsComprehensive knowledge of application security methodologies (OWASP, SANS/CWE) and security architecture patternsExperience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containersProficiency in DevSecOps tooling (SAST, DAST, SCA, container image scanning, secrets management, CI/CD security)Experience with NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust principlesWorking knowledge of IAM, OAuth 2.0/OIDC, and app-layer auth controlsUnderstanding of cryptography, data protection, encryption, and PKIFamiliarity with threat modeling methods (STRIDE, PASTA)Knowledge of OWASP GenAI, LLM Top 10, Security Exchange, Ai Exchange a plusBachelor's degree and 7+ years in information security focusing on application security or architectureRelevant certifications (CSSLP, CISSP, AWS/Azure Security Specialty, OSCP) preferredStrong communication with diverse stakeholdersMentoring and leadership of junior engineersIndependent, proactive initiative on security initiativesOWASP Top 10SANS/CWELead Application Security Architect - barcelona barcelona, catalunya, es
#J-18808-Ljbffr
📌 Lead Application Security Architect - Barcelona
🏢 Jones Lang Lasalle
📍 Barcelona