Application & Platform Security Architect
AbbVie
August 29, 2026
Remote friendly (Miami, FL)
United States
$141,500 - $268,500 USD yearly
IT
Responsibilities:
- Define reusable security architecture patterns and guardrails for secure implementation.
- Drive secure-by-design initiatives by integrating security early in the software architecture lifecycle.
- Advocate for risk-based security controls in design authority boards/technical review councils.
- Partner with IT application/infrastructure teams to define application controls aligned with enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Create reusable implementation guidance and design patterns to scale.
- Develop strategies/plans to enforce security requirements and address risks in infrastructure and applications.
- Serve as a security architecture liaison to embed security into delivery and architecture reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research and recommend implementation of new/updated security technologies.
- Provide advisory support for application development/acquisition projects; drive remediation/compliance gaps.
- Conduct application threat modeling and propose design changes to mitigate risks.
- Foster security culture through education and effective security processes.
Qualifications:
Required:
- Bachelorโs + 9 years, or Masterโs + 8 years, or PhD + 4 years in information security/security architecture/risk management/IT audit.
- In-depth SDLC knowledge; strong application security expertise (OWASP Top 10, SANS/CWE Top 25) and secure coding.
- Expertise in secure session management, token handling, and auth (OAuth, SAML, OpenID Connect).
- Knowledge of cryptography, encryption protocols, and PKI.
- Containerization and cloud: Docker/Kubernetes; AWS/Azure/GCP.
- Code analysis and vulnerability scanning (e.g., SonarQube, Veracode, Burp Suite, Nessus).
- DevSecOps and CI/CD pipeline security.
- Ability to work independently and manage multiple projects; strong analytical/problem-solving skills.
- Knowledge of cloud security and Identity Security (least privilege, separation of duties, Zero Trust), federation and encryption standards.
- Experience with security architecture planning/documentation (strategic/tactical/project).
- Significant SOX and HIPAA experience with IT general controls (ITGC) via audit/remediation/validation.
- Strong communications/influencing skills; ability to mentor.
- Framework knowledge (e.g., ISO, NIST).
Preferred:
- CISSP.
- Plus: identity management/federated identity, incident management, access control, application vulnerability testing, PKI, Windows/Unix/Linux, public cloud services.
Benefits:
- Paid time off; medical/dental/vision insurance; 401(k) to eligible employees.
Application instructions:
- None stated.
- Define reusable security architecture patterns and guardrails for secure implementation.
- Drive secure-by-design initiatives by integrating security early in the software architecture lifecycle.
- Advocate for risk-based security controls in design authority boards/technical review councils.
- Partner with IT application/infrastructure teams to define application controls aligned with enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Create reusable implementation guidance and design patterns to scale.
- Develop strategies/plans to enforce security requirements and address risks in infrastructure and applications.
- Serve as a security architecture liaison to embed security into delivery and architecture reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research and recommend implementation of new/updated security technologies.
- Provide advisory support for application development/acquisition projects; drive remediation/compliance gaps.
- Conduct application threat modeling and propose design changes to mitigate risks.
- Foster security culture through education and effective security processes.
Qualifications:
Required:
- Bachelorโs + 9 years, or Masterโs + 8 years, or PhD + 4 years in information security/security architecture/risk management/IT audit.
- In-depth SDLC knowledge; strong application security expertise (OWASP Top 10, SANS/CWE Top 25) and secure coding.
- Expertise in secure session management, token handling, and auth (OAuth, SAML, OpenID Connect).
- Knowledge of cryptography, encryption protocols, and PKI.
- Containerization and cloud: Docker/Kubernetes; AWS/Azure/GCP.
- Code analysis and vulnerability scanning (e.g., SonarQube, Veracode, Burp Suite, Nessus).
- DevSecOps and CI/CD pipeline security.
- Ability to work independently and manage multiple projects; strong analytical/problem-solving skills.
- Knowledge of cloud security and Identity Security (least privilege, separation of duties, Zero Trust), federation and encryption standards.
- Experience with security architecture planning/documentation (strategic/tactical/project).
- Significant SOX and HIPAA experience with IT general controls (ITGC) via audit/remediation/validation.
- Strong communications/influencing skills; ability to mentor.
- Framework knowledge (e.g., ISO, NIST).
Preferred:
- CISSP.
- Plus: identity management/federated identity, incident management, access control, application vulnerability testing, PKI, Windows/Unix/Linux, public cloud services.
Benefits:
- Paid time off; medical/dental/vision insurance; 401(k) to eligible employees.
Application instructions:
- None stated.