Senior Application Security Architect
Job Description
The Senior Application Security Architect role at State Street in Quincy, MA offers a strategic opportunity to design, review, and govern security architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems, partnering with software engineering, data science, cloud engineering, cybersecurity, and business teams to embed security throughout the software and AI development lifecycles.
Responsibilities
- Design and assess secure architectures for enterprise applications, APIs, cloud-native platforms, AI-enabled systems, and emerging technologies.
- Define and maintain application security and AI security standards, architecture patterns, and security requirements.
- Conduct security architecture reviews, threat modeling exercises, and design assessments for applications, APIs, and AI solutions.
- Collaborate with application development, cloud engineering, AI engineering, and cybersecurity teams to embed security controls across the software and AI development lifecycles.
- Provide subject matter expertise in secure coding, application security testing, API security, authentication, authorization, AI security, and data protection.
- Assess security risks associated with applications, AI models, training data, prompts, agents, integrations, and third-party AI services.
- Promote secure-by-design, Zero Trust, DevSecOps, and AI security best practices across the enterprise.
- Evaluate emerging application security and AI security threats, technologies, and industry standards.
Requirements
- Degree in Computer Science, Cybersecurity, Information Technology, Engineering, Data Science, or a related discipline.
- Minimum 14 years of experience in application security, software engineering, security architecture, AI security, or related technology disciplines; at least 8 years of hands-on cybersecurity work preferred.
- Proven experience designing and securing enterprise-scale applications across cloud, SaaS, hybrid, and on-premises environments.
- Deep expertise in SSDLC, OWASP Top 10, API security, secure coding practices, and application security testing methodologies.
- Strong understanding of AI/ML architectures, LLMs, Retrieval-Augmented Generation, agentic systems, model security, prompt security, and responsible AI principles.
- Experience with cloud-native technologies, containers, Kubernetes, CI/CD pipelines, DevSecOps, and Infrastructure as Code.
- Experience conducting threat modeling, architecture reviews, remediation after penetration tests, and risk assessments for applications and AI-enabled solutions.
- Familiarity with SAST, DAST, IAST, SCA, API security testing, model validation, and AI security assessment techniques.
- Professional certifications such as CISSP, CSSLP, CCSP, TOGAF, SABSA, AWS Security Specialty, Azure Security Engineer, AI Security, or equivalent are highly desirable.
- Experience in financial services or other regulated industries is preferred.
- Experience supporting enterprise application modernization, cloud transformation, DevSecOps, and AI adoption initiatives.
- Ability to collaborate effectively with cross-functional teams across global locations.
- Limited travel may be required based on business needs.
Technologies
- Kubernetes
- Containers
Benefits
- 401K with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional coverages
- Paid time off including vacation, sick leave, short term disability, and family care responsibilities
- Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
What We Value
- Deep expertise in application security, secure software development, and modern application architectures.
- Strong understanding of AI/ML security risks, LLMs, agentic AI systems, prompt injection, model misuse, and AI supply chain security.
- Experience securing cloud-native applications, APIs, microservices, containers, Kubernetes, and AI-enabled platforms.
- Analytical, problem-solving, and risk assessment skills with the ability to evaluate both traditional and AI-specific threats.
- Strong communication and stakeholder management skills for collaboration across architecture, engineering, cybersecurity, cloud, and data science teams.
Work Requirement
- Hybrid work model in accordance with State Street’s policy for the Quincy, MA location.
- Standard business hours with flexibility to support global stakeholders across multiple time zones.
Salary Range
$120,000 - $202,500 annually. The quoted range applies to the role in the primary location; variations may apply if the candidate works outside that location.
About State Street
State Street supports institutional investors globally by helping manage risk, respond to challenges, and drive performance and profitability. The company emphasizes an inclusive environment that fosters development opportunities, flexible work-life support, and employee networks.
Job Application Disclosure
Massachusetts law prohibits lie detector tests as a condition of employment. Violators may face penalties.