AbbVie logo

Application & Platform Security Architect

AbbVie
August 08, 2026
Remote friendly (Waco, TX)
United States
$141,500 - $268,500 USD yearly
IT
Application & Platform Security Architect (Information Security)

Responsibilities:
- Define reusable security architecture patterns and guardrails for high-risk applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle.
- Advocate for risk-based security controls in design authority boards and technical review councils.
- Evaluate application software and infrastructure designs and define application controls aligned with enterprise standards.
- Produce application-specific security control architectures and design artifacts for business-critical systems.
- Develop reusable implementation guidance and design patterns.
- Partner with security leadership to enforce security requirements and remediate identified infrastructure/application risks.
- Serve as a security architecture liaison to IT delivery and engineering; embed security in delivery and architecture reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition of secure solutions.
- Research, evaluate, design, test, recommend, and plan implementation of updated/new security technologies.
- Advise on application development/acquisition projects; ensure security controls are implemented and gaps remediated.
- Research and assess new security threats and recommend remedial actions.
- Foster an information security culture through education and effective security processes.
- Lead application threat modeling and propose design changes to mitigate risks.

Qualifications (Required):
- Bachelorโ€™s + 9 years OR Masterโ€™s + 8 years OR PhD + 4 years in information security or related (IT Audit, Risk Mgmt, Security Architecture).
- Strong application security knowledge (OWASP Top 10, SANS/CWE Top 25, secure coding).
- Expertise: secure session management, token handling, authentication (OAuth, SAML, OpenID Connect).
- Cryptography/encryption/PKI knowledge.
- Containerization and cloud experience (Docker, Kubernetes; AWS/Azure/GCP).
- Code analysis and vulnerability scanning tools (e.g., SonarQube/Veracode; Burp Suite/Nessus).
- DevSecOps and securing CI/CD pipelines.
- Strong problem-solving/communication; ability to work cross-functionally and influence teams.
- Cloud/IAM/security understanding, including zero trust/least privilege.
- Framework knowledge (e.g., ISO, NIST) and ability to balance academic and pragmatic approaches.
- Significant SOX and HIPAA experience with IT general controls (ITGC) via audit/remediation/validation.

Preferred:
- CISSP or similar.
- Knowledge of identity management, federated identity services, incident management, access control, vulnerability testing, PKI, Windows/Unix-Linux, and public cloud services.

Benefits:
- Paid time off; medical/dental/vision insurance; 401(k) (eligible employees).
- Eligible for long-term incentive programs.

Application instructions: Not provided in the excerpt.