Application Security Architect

Alarm.com - Tysons Corner, VA

Hiring: Application Security Architect Company: Alarm.com Location: Tysons Corner, VA Job Posted Time: 2026-09-03 10:43:57 Target Skills & Keywords : C#, CI/CD, DAST, GitHub, JavaScript, Kubernetes, LLM, Machine Learning, OWASP, Python, SAST, SCA, WAF About the job Experience: •10+ years of experience in application security, software engineering, or related technical security roles (8+ acceptable for exceptionally strong candidates). •Proficiency in at least one programming language (e.g., Python, JavaScript, C#) and ability to navigate large, complex codebases. •Knowledge of application security best practices across both cloud and on‑prem environments, including cloud‑hosted Kubernetes and related cloud services. •Hands‑on experience with AppSec tooling and techniques. •In-depth knowledge of vulnerabilities, exploitability, and security principles (e.g., OWASP Top 10, secure design patterns). Required Skills: •Vulnerability Management: Triage and track inbound findings from SAST, DAST, IAST, SCA tools, and external sources (bug bounty, penetration tests). Maintain strong awareness of vulnerability trends and exploitability. Prioritize remediation using a risk-based approach, partnering directly with engineering teams. •Secure SDLC Integration: Partner with engineering and platform leadership to embed security practices throughout the development lifecycle. Influence and evolve the AppSec tooling and automation roadmap—including emerging AI-assisted capabilities—through prototyping, evaluation, and feedback. •Code & Application Reviews: Perform deep, targeted reviews of high‑risk code paths, APIs, authentication/authorization flows, and sensitive components. Coordinate with Penetration Testers, Red Teams, and Compliance teams to ensure holistic coverage. •AI & LLM Security: Partner with teams adopting AI and LLM-based systems—both internal tooling and production features—to ensure secure design, model and data protection, prompt/input validation, and safe integration patterns. Assess and mitigate risks related to data leakage, model behavior, supply chain concerns, and emerging AI security threats. •Automation & Tooling: Build and maintain security automation integrated into CI/CD pipelines. Automate detection, validation, and developer‑friendly remediation workflows to improve signal quality and reduce friction. •Developer Guidance & Training: Serve as a domain expert and partner to engineering teams. Deliver workshops, provide secure coding guidance, and help teams adopt effective security controls and testing practices. •Cloud Application Security: Advise on application‑layer security in cloud-native environments, including identity, secrets management, network exposure, and service‑to‑service authentication. •IoT Device & Platform Security: Provide security guidance for IoT devices and platform components, including OSS dependency risk analysis and security considerations for legacy or constrained devices. Qualifications: •Bachelor's in Computer Science, Computer Engineering, Electrical Engineering, or related field, or equivalent work experience Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!