Staff Application Security Architect
Job Description
Role Details
Location: Seattle, WA, onsite
Salary: USD 149,000 - 318,000 per year
Education: Bachelor's degree in computer science, information security, or a related field
Experience: Minimum 5 years of relevant work experience. Alternatively, 10 years in information security or secure development, or a bachelor’s degree with at least 5 years in a related role.
Responsibilities
- Conduct security reviews across the SDLC, from design through implementation, using formal threat modeling and source code reviews to ensure secure design principles are properly applied.
- Help define the strategic direction for application security, shift-left initiatives, and enterprise secure coding standards with a focus on treating security as a quality attribute.
- Build and nurture collaboration with software engineering, product, and architecture teams to align with the company vision and secure coding goals.
- Continuously identify opportunities to improve software delivery pipelines and collaborate with engineering leadership to implement automated security guardrails and remediations.
- Work with business stakeholders, product owners, architecture, and information security teams to enable secure software patterns that support business velocity.
- Coordinate and drive initiatives for AppSec engineers to develop, execute, and scale application security strategies.
- Help establish processes to test the compliance and effectiveness of software security requirements through automated guardrails and ongoing security testing.
- Influence decision-makers on secure application architecture, API design, authentication and authorization controls, and modern cloud deployments.
- Create and promote application security policy sets and secure design patterns that balance development speed with external compliance requirements.
- Collaborate with development and audit teams to align security architectures with upcoming compliance, regulatory (SSDF, Executive Orders on Cybersecurity), and contractual landscapes.
- Mentor software engineers and information security team members on threat modeling, secure code design, and contemporary vulnerability remediation techniques.
Requirements
- Experience: 10 years in information security or application development with secure coding, or a bachelor’s degree plus 5 years of relevant experience.
- Proven ability to perform architectural threat modeling on complex systems using formal frameworks such as STRIDE, DREAD, or PASTA.
- Strong capability to read, write, and audit code for security vulnerabilities and provide precise, actionable remediation guidance to engineering teams.
- Deep technical familiarity with the Java ecosystem (highly preferred), along with .NET and/or Python.
- Proficiency in at least one scripting language (PowerShell, Bash, Python) for automation and tooling.
- Experience leveraging AI-assisted engineering tools to improve efficiency, while applying critical thinking to validate results and address inaccuracies.
- Hands-on experience with secure SDLC frameworks, DevSecOps pipeline integration (CI/CD), and security testing tools including SAST, DAST, SCA, and Secret Scanning.
- Knowledge of identity and access management (OAuth 2.0, OIDC, SAML), container security (Docker, Kubernetes), and OWASP Top 10 / ASVS mappings.
- Familiarity with the MITRE ATT&CK Framework and core InfoSec concepts such as least privilege, zero trust, secure input validation, and defense in depth.
- Understanding of modern enterprise security risks, including software supply chain security, development environment hardening, and risk mitigation at scale.
Technologies
- Java
- .NET
- Python
- PowerShell
- Bash
- Docker
- Kubernetes
- OAuth 2.0
- OIDC
- SAML
- MITRE ATT&CK Framework
- STRIDE
- DREAD
- PASTA
- OWASP Top 10
- ASVS
- SAST
- DAST
- SCA
- Secret Scanning tooling
- CI/CD
Benefits
- Medical, dental, and vision benefits
- 401K retirement plan
- Paid time off
Preferred Qualifications
- Master’s degree in computer science, information security, or a related field
- Advanced expertise in architectural threat modeling and integrating automated threat modeling into developer workflows
- Security certifications such as OSCP, OSWE, GWAPT, CISSP, CCSP, or equivalent
- Experience scaling AppSec programs across large engineering organizations, including integrating secure solutions throughout the SDLC and running a developer security champion program
- Strong Java development experience
What You’ll Get
Our team drives strategy, innovation, and growth, and the well-being of you and your family matters. We offer comprehensive support and benefits to help you thrive. Eligible team members receive benefits and perks designed to provide peace of mind. See our full Benefits and Perks for details.
On-Call Expectations
The role may participate in an on-call rotation to support production systems and ensure service reliability. On-call duties could involve night and weekend coverage, with frequency and scheduling determined by team needs.
About Us
Rocket is a Detroit-based company made up of businesses that provide simple, fast and trusted digital solutions for complex transactions. The name comes from our flagship business, now known as Rocket Mortgage, which was founded in 1985. Today, we’re a publicly traded company involved in many different industries, including mortgages, fintech, real estate and more. We’re insistently different in how we look at the world and are committed to an inclusive workplace where every voice is heard. Appl