Application Security Solution Architect

Bank of America Bank of America · Banking · Denver, CO +2

Seeking an experienced Application Security Solution Architect to design, strengthen, and secure Bank applications and overall security posture across their entire lifecycle. This role involves collaboration across Lines of Business and CIO teams to improve security adherence, identify risks, and prioritize improvements. The architect will apply knowledge of laws, rules, regulations, and information security concepts to establish policies and standards, and work with security engineering and product teams to identify risk gaps and direct application security design strategy.

What you'd actually do

  1. Analyze, design, develop, and deliver secure application security solutions.
  2. Support with creating new and leveraging existing secure patterns to optimize application security designs that align to business requirements.
  3. Manage all aspects of delivery of solution design, including capturing security requirements, identifying risks & opportunities, and alignment to application security policy.
  4. Cross collaborates with line(s) of business teams, as well as other security and IT support functions.
  5. Serve as a technical security design resource through the Software Development Lifecyle.

Skills

Required

  • Application Security
  • NIST
  • OWASP
  • ISO/EC
  • CIS
  • SOX
  • OCC
  • PCI
  • DGPR
  • FISMA
  • FFIEC
  • Financial Services Sector
  • Application Security Methodologies
  • Pen Testing Methodologies
  • Software Development Lifecycle
  • Security Compliance Integration
  • Core Technology Infrastructure
  • Cloud Technologies
  • Application Security Practice
  • Application Development Tools
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Bill of Materials
  • Penetration Testing
  • Threat Modeling
  • Development Pipelines
  • Cloud Architectures
  • On-Premise Architectures
  • Data Management
  • Data Analytical Capabilities
  • Metadata Management
  • Analytical Thinking
  • Architecture
  • Result Orientation
  • Solution Design
  • Technical Strategy Development

Nice to have

  • CISSP certification
  • Knowledge of software development lifecycle related tools and methodology which support automated security compliance integration within different pipeline solutions

What the JD emphasized

  • Knowledge and understanding of Application Security specific laws, rules, regulations, and Guidelines such as OWASP, NIST, ISO/EC, CIS, SOX, OCC, PCI, DGPR, FISMA, FFIEC within the financial services sector.
  • Knowledge of application security and pen testing methodologies, techniques, and technologies.
  • Security knowledge which covers core technology infrastructure, cloud technologies, and application security practice.
  • Experience with application development tools, Static and Dynamic Application Security Testing, Bill of Materials, Penetration Testing, Threat Modeling, common development Pipelines, and common cloud and on-premise designs and architectures.