Application & Platform Security Architect
AbbVie
August 29, 2026
Remote friendly (Atlanta, GA)
United States
$141,500 - $268,500 USD yearly
IT
Responsibilities:
- Define reusable security architecture patterns and guardrails for high-risk applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle.
- Represent security architecture in design authority boards and technical review councils; advocate risk-based controls.
- Partner with application/infrastructure teams to design application controls aligned to enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Develop reusable guidance/patterns to scale secure implementation.
- Work with security leadership to enforce security requirements and remediate identified infrastructure/application risks.
- Serve as a security architecture liaison to IT delivery and engineering teams; embed principles into delivery and reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research/evaluate/test/recommend and plan new/updated security technologies.
- Advise on application development/acquisition projects; ensure controls are implemented and gaps remediated.
- Research and assess new threats; recommend remedial actions.
- Foster security culture through education and effective security processes.
- Adhere to corporate policies (code of conduct, GxP, data security, SDLC).
- Design application security architecture; integrate security into SDLC with DevOps/operations.
- Lead application threat modeling and propose design changes to mitigate risks.
Qualifications (Required):
- Bachelorโs +9 years OR Masterโs +8 years OR PhD +4 years in information security/security architecture or related (IT Audit, Risk Mgmt).
- Strong ability to assess/communicate security concepts to business and IT stakeholders.
- In-depth SDLC knowledge and secure application development.
- Application security expertise (OWASP Top 10, SANS/CWE Top 25, secure coding).
- Secure session management, token handling, authentication (OAuth, SAML, OpenID Connect).
- Cryptographic practices, encryption protocols, PKI management.
- Containerization (Docker, Kubernetes) and cloud (AWS, Azure, GCP).
- Code analysis/vulnerability scanning tools (e.g., SonarQube, Veracode; Burp Suite, Nessus).
- DevSecOps and CI/CD pipeline security.
- Self-starter; manage multiple projects independently.
- Analytical/problem-solving; identify risks and propose solutions.
- Cross-functional collaboration and influence.
- Cloud risk management and security areas (IAM, network, auditing, encryption, secrets, CI/CD).
- Identity security (least privilege, separation of duties, Zero Trust).
- Federation and encryption technologies (WS-Fed, OAuth, OIDC, SAML; encryption standards/protocols).
- Experience developing/documenting security architecture and plans (strategic/tactical/project).
- Significant SOX/HIPAA experience with ITGC via hands-on audit/remediation/validation.
- Knowledge of security/architecture trends and frameworks (e.g., ISO, NIST).
Qualifications (Preferred):
- CISSP.
- Plus: identity management/federated identity services, incident management, access control, app vulnerability testing, PKI, Windows/Unix-Linux, and public cloud services.
Benefits (explicitly stated):
- Paid time off (vacation, holidays, sick), medical/dental/vision insurance, 401(k); eligible for long-term incentive programs.
Application Instructions:
- None stated.
- Define reusable security architecture patterns and guardrails for high-risk applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle.
- Represent security architecture in design authority boards and technical review councils; advocate risk-based controls.
- Partner with application/infrastructure teams to design application controls aligned to enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Develop reusable guidance/patterns to scale secure implementation.
- Work with security leadership to enforce security requirements and remediate identified infrastructure/application risks.
- Serve as a security architecture liaison to IT delivery and engineering teams; embed principles into delivery and reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research/evaluate/test/recommend and plan new/updated security technologies.
- Advise on application development/acquisition projects; ensure controls are implemented and gaps remediated.
- Research and assess new threats; recommend remedial actions.
- Foster security culture through education and effective security processes.
- Adhere to corporate policies (code of conduct, GxP, data security, SDLC).
- Design application security architecture; integrate security into SDLC with DevOps/operations.
- Lead application threat modeling and propose design changes to mitigate risks.
Qualifications (Required):
- Bachelorโs +9 years OR Masterโs +8 years OR PhD +4 years in information security/security architecture or related (IT Audit, Risk Mgmt).
- Strong ability to assess/communicate security concepts to business and IT stakeholders.
- In-depth SDLC knowledge and secure application development.
- Application security expertise (OWASP Top 10, SANS/CWE Top 25, secure coding).
- Secure session management, token handling, authentication (OAuth, SAML, OpenID Connect).
- Cryptographic practices, encryption protocols, PKI management.
- Containerization (Docker, Kubernetes) and cloud (AWS, Azure, GCP).
- Code analysis/vulnerability scanning tools (e.g., SonarQube, Veracode; Burp Suite, Nessus).
- DevSecOps and CI/CD pipeline security.
- Self-starter; manage multiple projects independently.
- Analytical/problem-solving; identify risks and propose solutions.
- Cross-functional collaboration and influence.
- Cloud risk management and security areas (IAM, network, auditing, encryption, secrets, CI/CD).
- Identity security (least privilege, separation of duties, Zero Trust).
- Federation and encryption technologies (WS-Fed, OAuth, OIDC, SAML; encryption standards/protocols).
- Experience developing/documenting security architecture and plans (strategic/tactical/project).
- Significant SOX/HIPAA experience with ITGC via hands-on audit/remediation/validation.
- Knowledge of security/architecture trends and frameworks (e.g., ISO, NIST).
Qualifications (Preferred):
- CISSP.
- Plus: identity management/federated identity services, incident management, access control, app vulnerability testing, PKI, Windows/Unix-Linux, and public cloud services.
Benefits (explicitly stated):
- Paid time off (vacation, holidays, sick), medical/dental/vision insurance, 401(k); eligible for long-term incentive programs.
Application Instructions:
- None stated.