{"schemaVersion":"jobsearcher.job.v1","id":"fe8a962d0fcbc9a1ddb665fc","url":"https://jobsearcher.com/jobs/fe8a962d0fcbc9a1ddb665fc","canonicalUrl":"https://jobsearcher.com/jobs/fe8a962d0fcbc9a1ddb665fc","title":"Java Security Architect","description":"Role: Java Security ArchitectLocation: Austin, TX or Sunnyvale, CA (Onsite)Duration: 6+ MonthsRole SummaryWe are looking for a Security Architect to own the security architecture and design assurance of enterprise web applications and services. You will review and define application security architecture, identify design-level weaknesses, specify the correct target-state design, and establish reusable secure-design patterns and assurance standards that engineering teams build to.This is a design-authority role. The emphasis is on architectural judgement — trust boundaries, identity and authorization models, and data-protection design — rather than on tool operation or test execution.Key ResponsibilitiesSecurity architecture and design review• Review the security architecture of enterprise applications and services: trust boundaries, identity and tenancy models, authorization models, and sensitive-data flows• Conduct threat modelling (STRIDE or equivalent) with engineering teams and derive prioritized, testable review plans from the model• Identify design-level weaknesses that automated tooling does not surface — perimeter and gateway bypass, internal-trust assumptions that fail under external exposure, loss of end-user identity across service-to-service hops, and client-side-enforced tenant isolation• Review authentication and authorization architecture: OAuth2/OIDC usage, token validation completeness, service-to-service authentication, and object- and function-level authorization across roles and tenants• Review data-protection design: encryption in transit and at rest, key management, secrets handling, and logging hygiene for sensitive data• Review platform architecture: container and Kubernetes security posture, infrastructure-as-code, and cloud IAM least privilegeTarget-state design and patterns• Specify target-state designs for architectural weaknesses, not problem statements alone• Develop and publish reusable secure-design patterns and reference architectures for adoption across engineering teams• Act as the design authority engineering teams consult before implementing security remediation• Feed systemic recommendations into SDLC and CI/CD controls to prevent recurrenceAssurance and standards• Define security review standards, assessment criteria and scoring or rating models, and defend them under challenge• Assess applications against those standards and produce the resulting assurance findings and ratings• Provide technical direction and quality assurance for a small security review team, including offshore members• Mentor engineers in architecture-level security reviewStakeholder engagement• Partner with central information security functions on assessment scope, coverage and findings• Advise application owners and engineering leads on remediation design and prioritization• Escalate risks and blockers clearly and earlyRequired Skills and Experience• 10+ years in application or product security, including time in a named security architect or design authority role on enterprise systems• Demonstrable track record of identifying design-level security weaknesses and specifying target-state designs that were adopted• Experience authoring reference architectures or secure-design patterns used by multiple engineering teams• Experience on, or running, an architecture or design review board or equivalent design gate• Threat modelling at architecture level, including facilitating sessions with teams new to the practice• Java and Spring Boot secure design and code review, including Spring Security and API gateway layers; awareness of reactive/non-blocking codebases• Identity and access architecture — OAuth2/OIDC, JWT validation, federated enterprise identity providers, service-to-service authentication (HMAC-signed requests, app-to-app token exchange), session and token lifecycle• Multi-tenant authorization architecture — broken object- and function-level authorization, tenant isolation design and verification• Cloud and container security architecture — Kubernetes and Helm, container hardening, infrastructure-as-code review, cloud IAM across at least two major providers• Working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, and CVSS v4.0• Experience handling confidential or regulated data under a formal classification scheme• Ability to build the security model of a proprietary or undocumented internal framework from its source code• Strong written communication — designs, findings and rationale must be actionable by engineers• Ability to influence without direct authority, and to work credibly with both central security functions and delivery teamsPreferred:• AI / LLM application security architecture — retrieval-augmented generation design, tenant isolation on retrieval, prompt and template provenance, treating model output as untrusted, agent and tool credential scope, Model Context Protocol (MCP) exposure• Hands-on security testing or penetration testing background, sufficient to validate and demonstrate a finding• API security architecture and authorization-matrix testing• Software supply chain, SBOM and dependency risk management• Experience establishing a security assurance programme where no formal process previously existed• Familiarity with enterprise CI/CD security gates (SAST, SCA, secrets scanning)CertificationsDemonstrable architectural depth is weighted above certification. One or more of the following is expected:• CISSP, CSSLP, CISSP-ISSAP, or SABSA• Valuable additions: CCSP, CKS, OSCP, GWAPT, or a recognized threat-modelling credential","company":"Flexon Technologies Talent360","rawCompany":"flexon technologies talent360ai","city":"Austin","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-09-14T07:58:13.358Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Java Security Architect","description":"Role: Java Security ArchitectLocation: Austin, TX or Sunnyvale, CA (Onsite)Duration: 6+ MonthsRole SummaryWe are looking for a Security Architect to own the security architecture and design assurance of enterprise web applications and services. You will review and define application security architecture, identify design-level weaknesses, specify the correct target-state design, and establish reusable secure-design patterns and assurance standards that engineering teams build to.This is a design-authority role. The emphasis is on architectural judgement — trust boundaries, identity and authorization models, and data-protection design — rather than on tool operation or test execution.Key ResponsibilitiesSecurity architecture and design review• Review the security architecture of enterprise applications and services: trust boundaries, identity and tenancy models, authorization models, and sensitive-data flows• Conduct threat modelling (STRIDE or equivalent) with engineering teams and derive prioritized, testable review plans from the model• Identify design-level weaknesses that automated tooling does not surface — perimeter and gateway bypass, internal-trust assumptions that fail under external exposure, loss of end-user identity across service-to-service hops, and client-side-enforced tenant isolation• Review authentication and authorization architecture: OAuth2/OIDC usage, token validation completeness, service-to-service authentication, and object- and function-level authorization across roles and tenants• Review data-protection design: encryption in transit and at rest, key management, secrets handling, and logging hygiene for sensitive data• Review platform architecture: container and Kubernetes security posture, infrastructure-as-code, and cloud IAM least privilegeTarget-state design and patterns• Specify target-state designs for architectural weaknesses, not problem statements alone• Develop and publish reusable secure-design patterns and reference architectures for adoption across engineering teams• Act as the design authority engineering teams consult before implementing security remediation• Feed systemic recommendations into SDLC and CI/CD controls to prevent recurrenceAssurance and standards• Define security review standards, assessment criteria and scoring or rating models, and defend them under challenge• Assess applications against those standards and produce the resulting assurance findings and ratings• Provide technical direction and quality assurance for a small security review team, including offshore members• Mentor engineers in architecture-level security reviewStakeholder engagement• Partner with central information security functions on assessment scope, coverage and findings• Advise application owners and engineering leads on remediation design and prioritization• Escalate risks and blockers clearly and earlyRequired Skills and Experience• 10+ years in application or product security, including time in a named security architect or design authority role on enterprise systems• Demonstrable track record of identifying design-level security weaknesses and specifying target-state designs that were adopted• Experience authoring reference architectures or secure-design patterns used by multiple engineering teams• Experience on, or running, an architecture or design review board or equivalent design gate• Threat modelling at architecture level, including facilitating sessions with teams new to the practice• Java and Spring Boot secure design and code review, including Spring Security and API gateway layers; awareness of reactive/non-blocking codebases• Identity and access architecture — OAuth2/OIDC, JWT validation, federated enterprise identity providers, service-to-service authentication (HMAC-signed requests, app-to-app token exchange), session and token lifecycle• Multi-tenant authorization architecture — broken object- and function-level authorization, tenant isolation design and verification• Cloud and container security architecture — Kubernetes and Helm, container hardening, infrastructure-as-code review, cloud IAM across at least two major providers• Working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, and CVSS v4.0• Experience handling confidential or regulated data under a formal classification scheme• Ability to build the security model of a proprietary or undocumented internal framework from its source code• Strong written communication — designs, findings and rationale must be actionable by engineers• Ability to influence without direct authority, and to work credibly with both central security functions and delivery teamsPreferred:• AI / LLM application security architecture — retrieval-augmented generation design, tenant isolation on retrieval, prompt and template provenance, treating model output as untrusted, agent and tool credential scope, Model Context Protocol (MCP) exposure• Hands-on security testing or penetration testing background, sufficient to validate and demonstrate a finding• API security architecture and authorization-matrix testing• Software supply chain, SBOM and dependency risk management• Experience establishing a security assurance programme where no formal process previously existed• Familiarity with enterprise CI/CD security gates (SAST, SCA, secrets scanning)CertificationsDemonstrable architectural depth is weighted above certification. One or more of the following is expected:• CISSP, CSSLP, CISSP-ISSAP, or SABSA• Valuable additions: CCSP, CKS, OSCP, GWAPT, or a recognized threat-modelling credential","datePosted":"2026-09-14T07:58:13.358Z","dateModified":"2026-09-14T07:58:13.358Z","hiringOrganization":{"@type":"Organization","name":"Flexon Technologies Talent360","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Austin","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fe8a962d0fcbc9a1ddb665fc"},"url":"https://jobsearcher.com/jobs/fe8a962d0fcbc9a1ddb665fc"}}