Principal Application Security Architect - 861
Api Security
Application Security
Cloud Platforms
Cloud Security Architecture
Dependency Scanning
DevSecOps
Dynamic Application Security Testing
Information Security
InfoSec
Security Automation
Security Compliance
Security Testing
Solution Architecture
Static Application Security Testing
Technical Lead
Threat Modeling
Job Description
Quantinuum offers a competitive salary range of USD 184,000 to 230,000 per year, a flexible work schedule, and a comprehensive benefits package that includes health, dental, and vision insurance, a 401(k) match, student loan repayment assistance, equity, paid holidays, generous vacation, sick time, paid parental leave, and employee discounts. This onsite role in Broomfield, CO provides the chance to serve as the hands-on technical lead for the security and architectural integrity of the application ecosystem, defining secure architectures, guiding assessments, and building tooling.
Responsibilities
- Perform manual code reviews to uncover logic flaws and vulnerabilities that automated scanners may miss.
- Lead hands-on threat modeling sessions for complex systems to establish security requirements before coding begins.
- Conduct targeted technical testing of web services, APIs, and cloud workloads to verify defenses perform as intended.
- Architect and manage the enterprise scanning ecosystem, including tuning SAST, DAST, and dependency scanning tools for high-quality results.
- Build and maintain security gates directly within CI/CD pipelines to provide developers with fast, actionable feedback.
- Collaborate with engineering teams to review pull requests and ensure security fixes are technically sound and effective.
- Create Golden Patterns for authentication, encryption, and data handling to guide secure development roadmaps.
- Ensure compliance with regulatory frameworks such as CIS CSC18, NIST CSF, ISO27001, GDPR, and SOC 2.
- Establish technical standards for identifying and prioritizing vulnerabilities by real-world exploitability and business impact.
- Partner with product and engineering teams to design secure architectures for new applications and major feature releases.
- Serve as the organization’s primary subject matter expert on application security tools, modern attack methods, and defensive coding.
- Translate complex vulnerabilities into clear business risks for technical teams and executive stakeholders.
- Stay current with emerging threats, vulnerabilities, and security technologies.
- Drive automation in security testing and monitoring and contribute to the evolution of enterprise application security strategy.
Requirements
- Bachelor's degree minimum.
- At least 10 years of experience in application security, penetration testing, or secure software development.
- At least 5 years of hands-on software engineering experience.
- Due to contractual requirements, must be a U.S. Person defined as a U.S. citizen, permanent resident or green card holder, or asylee/refugee status.
- National security requirements restrict candidates who are nationals of the PRC or Russia unless the candidate is also a U.S. citizen.
Technologies
- Java, Python, JavaScript, Go
- SAST, DAST, and dependency scanning tools
- CI/CD pipelines
- AWS, Azure, GCP
We value
- Bachelor's degree in computer science, cybersecurity, information systems, or a related field, or equivalent work experience.
- Strong technical knowledge of OWASP Top 10, SANS CWE, and secure coding practices.
- Fluency in at least two modern programming languages such as Java, Python, JavaScript, or Go.
- Hands-on experience building and tuning enterprise-grade SAST and DAST processes.
- Expert knowledge of cloud-native application security across AWS, Azure, and GCP.
- Professional certifications such as CISSP, CSSLP, OSCP, or GWAPT are preferred.
- Excellent analytical, problem-solving, collaboration, and communication skills.