Architect, Information Security - DevSecOps/Application Security

JobgetherBrussels (Firmensitz, recherchiert)leverpublished 08/14/2026
Must-have:CloudDevOpsCI/CDAISecurity

Accountabilities: Partner with application, development, solution architecture, DevOps, and security teams to assess and manage application security risks across design, development, testing, and deployment.

Conduct and support threat modeling, secure design assessments, and architecture reviews for applications, APIs, and cloud-native environments.

Define, document, and promote secure architecture patterns, guardrails, reusable controls, and security requirements aligned with organizational AppSec standards.

Guide teams in integrating and effectively using application security testing technologies, including SAST, DAST, and SCA, within CI/CD pipelines.

Support the implementation and enforcement of security requirements, standards, and control gates throughout the software development lifecycle.

Identify application and software supply chain security gaps and collaborate with engineering teams to develop practical, prioritized risk mitigation strategies.

Track vulnerabilities, security exceptions, and risk acceptances in accordance with established governance and risk management processes.

Collaborate with Security Champions and development teams to increase application security awareness, adoption, and overall maturity.

Contribute to AppSec education, training, awareness, and enablement programs that strengthen secure development practices.

Serve as a subject matter expert on application security, secure software development, and DevSecOps practices, providing guidance across technology initiatives.

Requirements:

3+ years of professional experience in application security, software security, DevSecOps, or a closely related discipline.

Strong knowledge of secure SDLC methodologies, threat modeling, secure architecture, and secure-by-design principles.

Hands-on familiarity with application security testing tools and methodologies, including SAST, DAST, and software composition analysis (SCA).

Solid understanding of the OWASP Top 10, API security vulnerabilities, application security risks, and secure coding practices.

Familiarity with CI/CD pipelines, DevOps practices, and common development and deployment tooling.

Ability to assess technical security issues and clearly translate risks, potential business impact, and remediation options for both technical and non-technical stakeholders.

Strong analytical, problem-solving, communication, and collaboration skills, with the ability to influence development teams and security stakeholders.

Experience working within governance frameworks and translating security standards into practical engineering controls is highly valuable.

Preferred certifications include CISSP, CISM, CCSP, or an equivalent information security credential.

Experience implementing or aligning application security programs with frameworks such as OWASP SAMM or NIST SSDF is preferred.

Experience leading AppSec or DevSecOps transformation initiatives, security maturity programs, or enterprise-wide security improvements is an advantage.

Benefits:

Competitive annual compensation range of $72,370.82–$156,803.45 , with actual compensation varying based on geographic location, experience, education, and skill level.

Comprehensive benefits and compensation package.

Full-time opportunity with a U.S.-based position.

Opportunity to influence application security architecture, governance, and DevSecOps practices across a complex technology environment.

Exposure to modern application security, cloud-native technologies, APIs, CI/CD, software supply chain security, and secure development practices.

Opportunity to collaborate with engineering, architecture, DevOps, and cybersecurity professionals while contributing to enterprise-wide security maturity.

Equal opportunity workplace committed to fair consideration of qualified candidates.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1