Senior Application Security Architect
Overview
In this role, you will lead secure application architecture efforts within ADP’s Global Security Organization to enable secure product delivery. You’ll partner with product, engineering, and cloud teams to embed secure-by-design principles across ADP’s ecosystem. You will guide GenAI, cloud, and API security decisions and influence across multi-country environments. This is a chance to shape security maturity, risk reduction, and trusted solutions at scale.
ResponsibilitiesDesign and evolve secure application architectures with global product and engineering teamsPerform in-depth security architecture reviews and provide actionable guidance across the solution lifecycleAdvise on GenAI/LLM/AI security, including data protection, model security, prompt injection mitigation, and risk evaluationAssess Cloud Services security (AWS, Azure, GCP, OCI) to enable secure cloud adoptionInfluence leaders to adopt secure-by-design practices and improve security maturitySupport Threat Modeling activities using tools like IriusRisk to define architecture risks and countermeasuresDevelop and maintain secure architecture patterns, reference architectures, and standards aligned with NIST/OWASP/CISEmbed security across the SDLC and educate teams on secure coding, API design, CI/CD security, and automated testingEnsure secure integration of third-party platforms and SaaS with vendor/architecture risk awarenessCollaborate with Cloud Architecture to apply consistent cloud security controls across environmentsCommunicate complex security concepts to technical and non-technical stakeholders
Key requirements8+ years in Application Security or Security ArchitectureDeep expertise in secure coding, API security, microservices, cloud security, DevSecOps, and security testing toolsStrong knowledge of GenAI/LLM/security incl. data governance, RAG, model threats, prompt injection, secure integrationCloud platform security knowledge for AWS/Azure/OCI/GCPFamiliarity with security frameworks (OWASP ASVS, SAMM, NIST 800-53, NIST CSF, ISO 27001, CIS Controls)Experience with Threat Modeling tools (IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool)Knowledge of IAM, OAuth2/OIDC, JWT, secrets management, KMS, zero-trustCI/CD security and infrastructure-as-code securityData security, encryption, privacy-by-design, secure logging and monitoringExcellent communication and stakeholder engagement skillsSecurity certifications a plus (CISSP, CISM, CCSP, CSSLP, CEH, SANS/GIAC, or cloud security certs)communicationcollaborationstakeholder engagementApplication securitySecure codingAPI security