Skip to main content
AbbVie logo

Application & Platform Security Architect

AbbVie
August 31, 2026
Remote friendly (North Chicago, IL)
United States
$141,500 - $268,500 USD yearly
IT
Responsibilities:
- Define reusable security architecture patterns and guardrails for high-risk applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle and influencing enterprise architecture.
- Represent security architecture in design authority/technical review forums and advocate for risk-based controls.
- Collaborate with IT customers to evaluate designs and define aligned application controls.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Develop reusable implementation guidance and design patterns.
- Partner with security leadership to enforce security requirements and address infrastructure/application risks.
- Serve as a security architecture liaison to IT delivery and engineering teams; embed security into delivery and reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research, evaluate, design, test, recommend, and plan new/updated security technologies.
- Advise on application development/acquisition projects; assess requirements/controls and ensure planned implementation; complete remediation.
- Perform threat assessments via application threat modeling and propose mitigations.
- Foster security culture through education and effective processes.
- Ensure architecture meets best practices and regulatory compliance; integrate security into SDLC with DevOps/operations.

Qualifications (Required):
- Bachelorโ€™s (9 yrs) or Masterโ€™s (8 yrs) or PhD (4 yrs) in information security or related (IT Audit, Risk Management, Security Architecture).
- Deep knowledge of SDLC and secure application development; strong application security (OWASP Top 10, SANS/CWE Top 25, secure coding).
- Expertise in secure session management, tokens, authentication (OAuth, SAML, OpenID Connect).
- Cryptography/encryption/PKI knowledge.
- Experience with Docker/Kubernetes and AWS/Azure/GCP.
- Code analysis and vulnerability scanning tools (e.g., SonarQube, Veracode; Burp Suite, Nessus).
- DevSecOps and CI/CD pipeline security.
- Ability to work independently and manage multiple projects; strong analytical/problem-solving skills.
- Cloud security breadth (IAM, network security, auditing, encryption, secrets management, CI/CD).
- Identity security (least privilege, separation of duties, zero trust).
- Federation/encryption technologies knowledge; security architecture planning/documentation.
- Significant SOX/HIPAA experience with ITGC (audit/remediation/validation).
- Strong communication and influence; collaboration and mentoring.
- Framework knowledge (ISO, NIST) with pragmatic approach.

Preferred:
- CISSP (preferred, not required).
- Plus: identity management, federated identity services, incident management, access control, application vulnerability testing, PKI, Windows/Unix/Linux, public cloud services.

Benefits:
- Paid time off; medical/dental/vision insurance; 401(k); eligible for long-term incentive programs.

Application instructions: