Senior Application Security Architect

ADP

$135K — $160K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in Application Security, Security Architecture, or similar roles.
  • Expertise in secure coding, API security, microservices, and DevSecOps.
  • Deep understanding of GenAI/LLM security, including data governance and model threats.
  • Familiarity with cloud security across platforms like AWS, Azure, and GCP.
  • Strong knowledge of security frameworks, including OWASP and NIST standards.
  • Hands-on experience with threat modeling tools and risk assessment methodologies.
  • Excellent communication and stakeholder engagement skills.

Responsibilities

  • Partner with global teams to design secure application architectures.
  • Conduct thorough security architecture reviews and provide actionable requirements.
  • Advise on GenAI and AI/ML application security risks and controls.
  • Perform security assessments for cloud services to meet security standards.
  • Influence adoption of secure-by-design principles among technical leaders.
  • Support threat modeling efforts and risk identification activities.
  • Develop secure architecture patterns and application security standards.

Benefits

  • Opportunity to work in a strategic role within ADP's Global Security Organization.
  • Engage in thought leadership to elevate overall security posture.
  • Collaborate closely with product, engineering, and cloud architecture teams.
  • Educate teams on best practices in secure development.
  • Flexible hybrid work arrangement available.
Full Job Description
Position Summary:

We are seeking a highly skilled and experienced Senior Application Security Architect to join our team. In this role, you will be part of the Product Security organization within ADP's Global Security Organization (GSO), which plays a strategic role in enabling secure development and supporting the delivery of trusted products, solutions, and services across the entire ADP ecosystem.

As a Senior Application Security Architect, you will partner closely with product, engineering, and cloud architecture teams to design and guide the implementation of secure application architectures. You will leverage your deep expertise in application security architecture, Cloud security, and AI/GenAI security, to influence design decisions, reduce risk, and champion secure-by-design principles across the organization.

This role is instrumental in helping teams build secure applications, integrate third-party and SaaS solutions responsibly, and elevate ADP's overall security posture through thought leadership, architectural oversight, and proactive engagement throughout the SDLC.

Key Responsibilities:

  • Partner with global product and engineering teams to design, review, and evolve secure application architectures across multi-country environments.
  • Conduct in-depth security architecture reviews and provide clear, actionable security requirements, design guidance, and validation throughout the entire solution lifecycle.
  • Advise on GenAI, LLM, and AI/ML application security, including data protection, model security, prompt injection mitigation, dependency controls, secure model integration, and risk evaluation of AI-driven components.
  • Perform security assessments of Cloud Services (AWS, Azure, GCP, OCI) to confirm required security requirements to enable Cloud services at ADP.
  • Influence technical leaders-solution architects, security champions, engineering managers, and developers-to adopt secure-by-design principles and continuously improve security maturity.
  • Support Threat Modeling activities, leveraging tools such as IriusRisk to help teams create architecture diagrams, identify security risks, define countermeasures, and validate threat coverage.
  • Develop and maintain secure architecture patterns, reference architectures, and application security standards, ensuring alignment with industry frameworks (e.g., NIST, OWASP, CIS).
  • Embed security across the SDLC, educating product teams on integrating secure coding practices, secure API design, CI/CD security controls, and automated security testing.
  • Support secure integration of third-party platforms, SaaS solutions, and cloud-native services, ensuring vendor risk and architecture risks are understood and mitigated.
  • Partner with Cloud Architecture teams to ensure consistent application of cloud security controls across AWS, Azure, and hybrid environments.
  • Communicate complex security concepts to both technical and non-technical stakeholders, enabling informed decision-making at all levels.


To Succeed in This Role:
  • You'll have a bachelor's degree in computer science, Information Security, Engineering, or a related field (or equivalent experience).


Qualifications:
  • 8+ years of experience in Application Security, Security Architecture, or related technical security roles.
  • Deep expertise in Application Security practices, including secure coding, API security, microservices, cloud application security, DevSecOps, and security scanning tools.
  • Strong understanding of GenAI / LLM / Agentic AI security, including data governance, retrieval-augmented generation (RAG), model threats, prompt injection risks, and secure integration patterns.
  • Strong knowledge of cloud platform (such as AWS, Azure, OCI, and/or GCP) security capabilities and controls.
  • Strong knowledge of security frameworks and standards (e.g., OWASP ASVS, SAMM, NIST 800-53, NIST CSF, ISO 27001, CIS Controls).
  • Hands-on experience with Threat Modeling methodologies, tools (e.g., IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool), and risk assessment techniques.
  • Knowledge of identity and access management, OAuth2/OIDC, JWT security, secrets management, key management, and zero-trust design principles.
  • Experience with CI/CD pipeline security and infrastructure-as-code security.
  • Strong understanding of data security, encryption, privacy-by-design, and secure logging and monitoring practices.
  • Excellent communication, collaboration, and stakeholder engagement skills, with the ability to influence and drive security adoption.
  • Relevant security certifications are a plus: CISSP, CISM, CCSP, CSSLP, CEH, SANS/GIAC certifications, or cloud security certifications such as Google Professional Cloud Security Engineer.


#LI-SD4

#LI-Hybrid

Similar Jobs

More Jobs at ADP

More Information Technology Jobs

Find similar Senior Application Security Architect jobs: