{"schemaVersion":"jobsearcher.job.v1","id":"fb2d6c077d99bab0c6ea839e","url":"https://jobsearcher.com/jobs/fb2d6c077d99bab0c6ea839e","canonicalUrl":"https://jobsearcher.com/jobs/fb2d6c077d99bab0c6ea839e","title":"Application & Platform Security Architect","description":"Job Description\r\nThe Application & Platform Security Architecti is a member of the Information Security team and works closely with other members of the team to develop and implement a comprehensive information security program. This includes defining security policies, processes, and standards. We areseekinga highly skilled architect to collaborate with application development teams, ensuring secure design, coding, configuration, and deployment of technology solutions. The architect will not only focus on common security mechanisms like encryption and authentication but will also dive into application-level risks, session management, securing configuration files, and risk identification in system configurations. This role requires a deep understanding of secure application development practices, including the security of API interactions and cloud application environments.\r\nResponsibilities\r\nDefine reusable security architecture patterns and guardrails to enable consistent, secure implementation across high-risk business applications.\r\nDrive secure-by-design initiatives by integrating security considerations early in the software architecture lifecycle and influencing enterprise architecture direction.\r\nRepresent security architecture in design authority boards and technical review councils, advocating for risk-based security controls.\r\nWork with in-business IT customers, including application architects and engineers to evaluate application software and infrastructure designs, for the purpose of defining/designing application controls aligned with enterprise standards.\r\nDefine application-specific security control architectures and produce design artifacts to guide secure implementation of business-critical systems.\r\nDevelop re-usable implementation guidance and design patterns based onpreviousengagements to scale the service.\r\nWork with information security leadership to develop strategies and plans to enforce security requirements and addressidentifiedrisks in the infrastructure and applications.\r\nAct as a security architecture liaison to IT delivery and engineering teams, embeddingsecurity principles into technical delivery and architecture review forums.\r\nSupport security aspects of business & IT initiatives byassistingin architecture, design, implementation, deployment, and operational transition of innovative & secure technology solutions.\r\nWork with information security leadership to develop strategies and plans to enforce security requirements and addressidentifiedrisks in the infrastructure.\r\nResearch, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies.\r\nEstablishcollaborative working relations with the Information Technology functions to ensure that solutions align with security architecture and business strategy.\r\nPlay an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned. Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed.\r\nResearch and assessnew informationsecurity threats and recommend remedial actions.\r\nFoster an information security culture through education, skill development, and implementation of effective information security processes and practices.\r\nUnderstand and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety,GxPcompliance, data security, and the software development lifecycle.\r\nMatures and leverages relationships with affiliates, subsidiaries, vendors, and industry peers in accordance with AbbVie Values, Vendor Management Office, and Purchasing to further the mission, vision, and goals of the organization.\r\nDesign the security architecture for applications, ensuring all components meet best practices and regulatory compliance.\r\nWork closely with software development, DevOps, and operations teams to integrate security into the software development lifecycle (SDLC).\r\nLead efforts inidentifyingpotential threats through application threat modeling and propose design changes to mitigate risks.\r\nRequired Qualifications\r\nBachelors degree and 9 years ofexperienceOR Masters Degree and 8 years ofexperienceOR PhD and 4 years of experience in information security and/or related functions (IT Audit, Risk Management or Security Architecture).\r\nMust havedemonstratedexceptional ability to assess and communicate information security concepts and practices, with both business and IT stakeholders.\r\nRequires in-depth knowledge of the systems development life cycle, clientareasfunctions and systems, and systems applications programs development technological alternatives.\r\nProven implementation of creative technology solutions that advance the business.\r\nRelevant work experience is important for successful performance of this role due to the complexity of our global IT Security environment.\r\nStrong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices.\r\nExpertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect).\r\nKnowledge of cryptographic practices, encryption protocols, and PKI management.\r\nExperience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP).\r\nFamiliarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus).\r\nUnderstanding ofDevSecOpspractices, including securing CI/CD pipelines.\r\nSelf-starter with the ability to work independently and manage multiple projects simultaneously.\r\nStrong problem-solving and analytical skills with the ability toidentifysecurity risks andpropose effective solutions.\r\nAbility to work collaboratively in cross-functional teams and influence technical teams towards secure implementations.\r\nUnderstanding of cloud computing principles, including virtualization, containerization, microservices, and serverless computing; Risk Management, container security, Kubernetes security, IAM security, network security, auditing, encryption, secrets management and data protection, securing CI/CD.\r\nAdvanced knowledge of Identity Security concepts, least-privilege, separation of duties, and Zero trust design principles.\r\nUnderstanding of federation technologies (WS-Fed, OAuth, OpenID connect, SAML ) and of encryption technologies (encryption types and protocols/standards).\r\nKnowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project.\r\nSignificant SOX and HIPAA experience in dealing with IT general controls (ITGC),demonstratedthrough hands-on audit, remediation, and/or computer system validation.\r\nExcellent understanding of current Information Security & Architecture trends and their impact on business strategiesincludingkey Information Security vendors and solutions, auditorganizations,and influential market research firms.\r\nExcellent communications and influencing skills withstrongability to balance differing stakeholder interests through sound analysis and persuasion.\r\nStrong people skills, collaborative ability to work with IT stakeholders inside and outside of the organization, able to mentor team members with diverse backgrounds.\r\nThorough understanding of Information Security frameworks and good practices (e.g.,ISO, NIST), and proven ability to strike a balance between an academic and pragmatic approach.\r\nPreferred Qualifications\r\nInformation securityqualificationssuch as CISSParepreferred but notrequired.\r\nUnderstanding the following concepts is a plus; identity management, federated identity services, incident management, access control, application vulnerability testing, public key infrastructure, Windows, and Unix/Linux, public cloud infrastructure, and services.\r\nAdditional Information\r\nApplicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:\r\nThe compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.\r\nWe offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.\r\nThis job is eligible to participate in our long-term incentive programs.\r\nNote: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinate. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employer remains in the Company's sole and absolute discretion until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law.\r\nEqual Opportunity Employer\r\nAbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.\r\nUS & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html\r\nUS & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: https://www.abbvie.com/join-us/reasonable-accommodations.html\r\nJ-18808-Ljbffr","company":"BioSpace","rawCompany":"biospace","city":"North Chicago","state":"IL","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:30:04.551Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application & Platform Security Architect","description":"Job Description\r\nThe Application & Platform Security Architecti is a member of the Information Security team and works closely with other members of the team to develop and implement a comprehensive information security program. This includes defining security policies, processes, and standards. We areseekinga highly skilled architect to collaborate with application development teams, ensuring secure design, coding, configuration, and deployment of technology solutions. The architect will not only focus on common security mechanisms like encryption and authentication but will also dive into application-level risks, session management, securing configuration files, and risk identification in system configurations. This role requires a deep understanding of secure application development practices, including the security of API interactions and cloud application environments.\r\nResponsibilities\r\nDefine reusable security architecture patterns and guardrails to enable consistent, secure implementation across high-risk business applications.\r\nDrive secure-by-design initiatives by integrating security considerations early in the software architecture lifecycle and influencing enterprise architecture direction.\r\nRepresent security architecture in design authority boards and technical review councils, advocating for risk-based security controls.\r\nWork with in-business IT customers, including application architects and engineers to evaluate application software and infrastructure designs, for the purpose of defining/designing application controls aligned with enterprise standards.\r\nDefine application-specific security control architectures and produce design artifacts to guide secure implementation of business-critical systems.\r\nDevelop re-usable implementation guidance and design patterns based onpreviousengagements to scale the service.\r\nWork with information security leadership to develop strategies and plans to enforce security requirements and addressidentifiedrisks in the infrastructure and applications.\r\nAct as a security architecture liaison to IT delivery and engineering teams, embeddingsecurity principles into technical delivery and architecture review forums.\r\nSupport security aspects of business & IT initiatives byassistingin architecture, design, implementation, deployment, and operational transition of innovative & secure technology solutions.\r\nWork with information security leadership to develop strategies and plans to enforce security requirements and addressidentifiedrisks in the infrastructure.\r\nResearch, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies.\r\nEstablishcollaborative working relations with the Information Technology functions to ensure that solutions align with security architecture and business strategy.\r\nPlay an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned. Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed.\r\nResearch and assessnew informationsecurity threats and recommend remedial actions.\r\nFoster an information security culture through education, skill development, and implementation of effective information security processes and practices.\r\nUnderstand and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety,GxPcompliance, data security, and the software development lifecycle.\r\nMatures and leverages relationships with affiliates, subsidiaries, vendors, and industry peers in accordance with AbbVie Values, Vendor Management Office, and Purchasing to further the mission, vision, and goals of the organization.\r\nDesign the security architecture for applications, ensuring all components meet best practices and regulatory compliance.\r\nWork closely with software development, DevOps, and operations teams to integrate security into the software development lifecycle (SDLC).\r\nLead efforts inidentifyingpotential threats through application threat modeling and propose design changes to mitigate risks.\r\nRequired Qualifications\r\nBachelors degree and 9 years ofexperienceOR Masters Degree and 8 years ofexperienceOR PhD and 4 years of experience in information security and/or related functions (IT Audit, Risk Management or Security Architecture).\r\nMust havedemonstratedexceptional ability to assess and communicate information security concepts and practices, with both business and IT stakeholders.\r\nRequires in-depth knowledge of the systems development life cycle, clientareasfunctions and systems, and systems applications programs development technological alternatives.\r\nProven implementation of creative technology solutions that advance the business.\r\nRelevant work experience is important for successful performance of this role due to the complexity of our global IT Security environment.\r\nStrong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices.\r\nExpertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect).\r\nKnowledge of cryptographic practices, encryption protocols, and PKI management.\r\nExperience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP).\r\nFamiliarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus).\r\nUnderstanding ofDevSecOpspractices, including securing CI/CD pipelines.\r\nSelf-starter with the ability to work independently and manage multiple projects simultaneously.\r\nStrong problem-solving and analytical skills with the ability toidentifysecurity risks andpropose effective solutions.\r\nAbility to work collaboratively in cross-functional teams and influence technical teams towards secure implementations.\r\nUnderstanding of cloud computing principles, including virtualization, containerization, microservices, and serverless computing; Risk Management, container security, Kubernetes security, IAM security, network security, auditing, encryption, secrets management and data protection, securing CI/CD.\r\nAdvanced knowledge of Identity Security concepts, least-privilege, separation of duties, and Zero trust design principles.\r\nUnderstanding of federation technologies (WS-Fed, OAuth, OpenID connect, SAML ) and of encryption technologies (encryption types and protocols/standards).\r\nKnowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project.\r\nSignificant SOX and HIPAA experience in dealing with IT general controls (ITGC),demonstratedthrough hands-on audit, remediation, and/or computer system validation.\r\nExcellent understanding of current Information Security & Architecture trends and their impact on business strategiesincludingkey Information Security vendors and solutions, auditorganizations,and influential market research firms.\r\nExcellent communications and influencing skills withstrongability to balance differing stakeholder interests through sound analysis and persuasion.\r\nStrong people skills, collaborative ability to work with IT stakeholders inside and outside of the organization, able to mentor team members with diverse backgrounds.\r\nThorough understanding of Information Security frameworks and good practices (e.g.,ISO, NIST), and proven ability to strike a balance between an academic and pragmatic approach.\r\nPreferred Qualifications\r\nInformation securityqualificationssuch as CISSParepreferred but notrequired.\r\nUnderstanding the following concepts is a plus; identity management, federated identity services, incident management, access control, application vulnerability testing, public key infrastructure, Windows, and Unix/Linux, public cloud infrastructure, and services.\r\nAdditional Information\r\nApplicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:\r\nThe compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.\r\nWe offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.\r\nThis job is eligible to participate in our long-term incentive programs.\r\nNote: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinate. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employer remains in the Company's sole and absolute discretion until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law.\r\nEqual Opportunity Employer\r\nAbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.\r\nUS & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html\r\nUS & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: https://www.abbvie.com/join-us/reasonable-accommodations.html\r\nJ-18808-Ljbffr","datePosted":"2026-08-08T01:30:04.551Z","dateModified":"2026-08-08T01:30:04.551Z","hiringOrganization":{"@type":"Organization","name":"BioSpace","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"North Chicago","addressRegion":"IL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fb2d6c077d99bab0c6ea839e"},"url":"https://jobsearcher.com/jobs/fb2d6c077d99bab0c6ea839e"}}