JOBSEARCHER

Senior Application Security Architect - GCP

Overview In this role you will guide secure application architectures for the ADP ecosystem, partnering with product, engineering, and cloud teams. You will shape secure-by-design practices and influence decisions across the SDLC to reduce risk. You’ll specialize in application and cloud security, with a focus on GenAI/AI security, delivering secure, compliant solutions. This is a chance to impact data protection and security maturity at scale in a global enterprise. ResponsibilitiesDesign, review, and evolve secure application architectures across multi-country environmentsPerform in-depth security architecture reviews with actionable requirements and guidanceAdvise on GenAI, LLM, and AI/ML security including data protection and prompt injection mitigationAssess Cloud Services security for AWS, Azure, GCP, OCIInfluence leaders to adopt secure-by-design principles and improve security maturitySupport Threat Modeling activities using tools like IriusRiskDevelop and maintain secure architecture patterns and standards aligned with NIST/OWASP/CISEmbed security across the SDLC including secure coding, API design, CI/CD security, and automated testingEnsure secure integration of third-party platforms and vendor risk managementCollaborate with Cloud Architecture teams to apply cloud security controls consistentlyCommunicate complex security concepts to technical and non-technical stakeholders Key requirements8+ years of experience in Application Security or Security ArchitectureDeep expertise in secure coding, API security, microservices, cloud security, DevSecOps, and security testing toolsStrong knowledge of GenAI/LLM security, data governance, prompt risks, and secure integration patternsSolid understanding of cloud platforms (AWS, Azure, OCI, GCP) security capabilitiesFamiliarity with security frameworks (OWASP ASVS, SAMM, NIST 800-53/CSF, ISO 27001, CIS Controls)Hands-on threat modeling methodologies and tools (IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool)Knowledge of IAM, OAuth2/OIDC, JWT, secrets management, key management, and zero-trustExperience with CI/CD security and IaC securityUnderstanding of data security, encryption, privacy-by-design, and secure logging/monitoringExcellent communication and stakeholder engagementExcellent communicationCollaborationStakeholder engagementApplication SecurityCloud SecurityGenAI / LLM / AI security