Senior Application Security Architect
State Street
- Location
- Quincy
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 11, 2026
Skills
About this role
Who We Are
Looking For We are looking for a Senior Application Security Architect. You will be responsible for designing, reviewing, and governing security architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems. You will partner with software engineering, data science, cloud engineering, cybersecurity, and business teams to ensure security is embedded throughout the software and AI development lifecycles. Why This Role Is Important To Us The team you will be joining is part of the Security Architecture organization, a function that is critical to protecting the firm's applications, AI capabilities, data, and digital platforms. As applications increasingly leverage AI and machine learning technologies, this role is responsible for ensuring secure-by-design principles are applied consistently across traditional applications, cloud-native services, APIs, and AI-powered solutions. What You Will Be Responsible For As a Senior Application Security Architect, you will: Design and review secure architectures for enterprise applications, APIs, cloud-native platforms, AI-enabled systems, and emerging technologies. Define and maintain application security and AI security standards, architecture patterns, and security requirements. Conduct security architecture reviews, threat modeling exercises, and design assessments for applications, APIs, and AI solutions. Partner with application development, cloud engineering, AI engineering, and cybersecurity teams to embed security controls throughout the software and AI development lifecycles. Provide subject matter expertise in secure coding, application security testing, API security, authentication, authorization, AI security, and data protection. Assess security risks associated with applications, AI models, training data, prompts, agents, integrations, and third-party AI services. Drive adoption of secure-by-design, Zero Trust, DevSecOps, and AI security best practices across the enterprise. Evaluate emerging application security and AI security threats, technologies, and industry standards.
What We Value
These skills will help you succeed in this role: Deep expertise in application security, secure software development, and modern application architectures. Strong understanding of AI/ML security risks, Large Language Models (LLMs), agentic AI systems, prompt injection, model misuse, and AI supply chain security. Experience securing cloud-native applications, APIs, microservices, containers, Kubernetes, and AI-enabled platforms. Strong analytical, problem-solving, and risk assessment skills with the ability to evaluate both traditional and AI-specific security threats. Strong communication and stakeholder management skills with the ability to collaborate across architecture, engineering, cybersecurity, cloud, and data science teams. Education & Preferred Qualifications Degree in Computer Science, Cybersecurity, Information Technology, Engineering, Data Science, or a related discipline. 14 years or more of experience in application security, software engineering, security architecture, AI security, or related technology disciplines with at least 8 years of hands-on cybersecurity experience preferred. Demonstrated experience designing and securing enterprise-scale applications across cloud, SaaS, hybrid, and on-premises environments. Deep expertise in secure software development lifecycle (SSDLC), OWASP Top 10, API security, secure coding practices, and application security testing methodologies. Strong understanding of AI/ML architectures, LLMs, Retrieval-Augmented Generation (RAG), agentic systems, model security, prompt security, and responsible AI principles. Experience with cloud-native technologies, containers, Kubernetes, CI/CD pipelines, DevSecOps practices, and Infrastructure as Code (IaC). Experience conducting threat modeling, architecture reviews, penetration test remediation, and risk assessments for applications and AI-enabled solutions.