cover
Full Time

Application Security Architect/ 2 days ago

SAS
Attractive
Application ends: 2025-12-02

Application Security Architect - Remote or Hybrid

We are a leader in data and AI, inspiring customers worldwide to transform data into intelligence. If you seek a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We are recognized globally for our inclusive culture and innovative technologies.

About the Job

As an Application Security Architect within the Product Security Organization (PSO), you will be a key contributor to overall product security. You will partner within SAS to solve complex technical problems across the Software Development Lifecycle (SDLC), from architecture and design to deployment and operations. This role requires strong technical breadth and depth, as well as clear communication skills, encompassing systems architecture, software development, and security. Success depends on collaborative skills to meet legal, compliance, and customer security requirements, ensuring SAS provides the most trustworthy solutions globally.

As an Application Security Architect, you will:

  • Partner with development teams to identify and build solutions for secure code and implement application vulnerability scanning and penetration testing. Provide documentation, developer guidance, training, and repositories with best practice examples in secure architecture, design, and operational patterns.
  • Perform risk-based, prioritized reviews of application architecture to identify security gaps and enhance the security posture of business-critical multi-tier applications in legacy, hybrid cloud, and public cloud environments.
  • Collaborate cross-organizationally with engineering (security champions, architects, developers) and operations to assist in identifying, assessing risk, and remediating security issues. Work with Product Management to ensure security implementations align with business objectives and customer requirements, adhering to SAS security standards, policies, procedures, and global regulatory requirements.
  • Assist in creating dashboards and on-demand reporting of product division security posture and recommend improvements aligned with Secure by Default and Zero Trust principles.
  • Identify, train, and partner with divisional Security Champions within product architecture and engineering teams. Help champions assess and gauge risk to identify security gaps or seams in products and integrated solutions.
  • Collaborate with other security teams to identify new tools and processes for integration into the Secure SDLC. Recommend and promote software security policies, standards, and procedures to improve the global security posture.
  • Ensure all applicable security policies and processes are followed to support the organization's secure software development goals. Refer to GCF and include if security is listed.
  • Embrace curiosity, passion, authenticity, and accountability – our core values.

Required Qualifications:

  • Bachelor's degree in technical disciplines such as Electrical Engineering or Computer Science.
  • 5+ years of secure software development, secure system architecture and design, or related experience.
  • Demonstrated knowledge in securing enterprise web applications and supporting systems/services (OWASP Top 10, CVSS, CWE/CVE).
  • Demonstrated ability to guide development and operational teams on effective remediation of security issues identified by SAST/DAST scanners, customer reports, or offensive security testing/audits.
  • An equivalent combination of related education, training, and experience may be considered.

Additional Competencies, Knowledge, and Skills:

  • Technical Knowledge: Possess a satisfactory level of technical, functional, and professional skill, staying current with developments and trends in areas of expertise.
  • Decision Making: Identify and understand problems/opportunities, gather and analyze information, evaluate alternatives, and make timely decisions consistent with facts and constraints.
  • Continuous Improvement: Originate action to improve existing conditions and processes, identify improvement opportunities, generate ideas, and implement solutions.
  • 2+ years of experience in developing or adopting software security patterns and best practices.
  • Demonstrated knowledge and willingness to learn security principles for Kubernetes, containers, micro-services, SaaS (public/private cloud), ML, GenAI, and Agentic AI.
  • Experience with programming languages such as Java, C/C++, C#, Rust, Python, JavaScript, PHP, Golang. Ability to review code and provide prescriptive guidance on security patterns and best practices.
  • Active security certification (CISSP, CSSLP, CEH, CCSP, OSCP, etc.). Knowledge of security best practices for regulated industries (healthcare, financial services) and global privacy frameworks.

World-class benefits:

Includes comprehensive medical, prescription, dental, and vision plans; an industry-leading 401k plan; Tuition Assistance Program; generous time off (vacation, holidays, Winter Wellness Break); Volunteer Time Off, parental leave, unlimited paid sick days; and generous childcare benefits.

You are welcome here. At SAS, we value adding to our culture with unique talents. Our inclusive workforce inspires teams to create amazing software reflecting our diverse users and customers.

Additional Information: Applicants must be legally authorized to work in the U.S. without sponsorship. SAS is an equal opportunity employer. Resumes are considered in the order received. SAS may obtain nationality or citizenship information for export control compliance. SAS communications originate from verified “sas.com” email addresses.

Join our Talent Community to stay updated!

Share

SAS

SAS

  • Address
    100 SAS Campus Drive
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy