Lead Application Security Architect
Hace 4 días
barcelona, província de barcelona, España
Jones Lang LaSalle
Jornada completa
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Al continuar, aceptas nuestros Términos & Política de Privacidad.
JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong. Whether you’ve got deep experience in commercial real estate, skilled trades or technology, or you’re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. JLL es una empresa comprometida con la igualdad de oportunidades entre hombres y mujeres / JLL as a company is committed to equal opportunities for men and women.
Senior Application Security Architect Overview At JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. The Application Security Architect is a senior individual contributor responsible for bridging application security engineering and enterprise security architecture at JLL. This role designs and owns security architectures for application ecosystems, integrates security into the software development lifecycle (SDLC), and serves as a technical authority on secure design patterns, threat modeling, and DevSecOps practices. Operating at the Senior level, this position independently leads application security initiatives, mentors junior engineers and developers, and partners across engineering, architecture, and business teams to reduce risk and enable secure digital transformation. If you’re a strategic thinker with application security expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you. Essential Duties and
Responsibilities:
Security Architecture & Design Design and maintain security architecture standards, policies, and patterns for enterprise applications, platforms, and cloud-native environments, ensuring alignment with JLL's technology strategy and risk posture. Develop and enforce secure design patterns, reference architectures, and architecture decision records (ADRs) for application security across development teams. Lead security architecture reviews for new and existing applications, evaluating designs against frameworks such as OWASP, NIST, and SANS. Integrate zero-trust principles and defense-in-depth strategies into application architecture to reduce attack surface and support enterprise risk management goals. DevSecOps & Secure Development Lifecycle Define and maintain a standardized set of enterprise application security requirements and produce metrics to report performance against those requirements. Lead threat modeling sessions for new application features and system integrations, producing actionable remediation guidance for development teams. Champion secure coding standards and developer security enablement programs in collaboration with platform and application engineering teams. Risk, Compliance & Stakeholder Engagement Analyze complex security requirements across multiple technology domains and design comprehensive security solutions that address enterprise risk and regulatory compliance obligations. Communicate security architecture designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders across business units. Coordinate security design reviews and approval processes, facilitating alignment between security, engineering, and enterprise architecture teams. Contribute to JLL's application security strategy roadmap, identifying emerging threats and recommending enhancements to the secure development and architecture programs. Mentorship & Team Leadership Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards. Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams. Support secure development training and awareness programs to build security competency across engineering organizations. Required Knowledge, Skills, and Abilities:Technical Knowledge Comprehensive knowledge of application security methodologies, including OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns. Demonstrated experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads. Strong proficiency in DevSecOps practices and tooling: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration. Experience with enterprise security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles. Working knowledge of identity and access management (IAM), OAuth 2.0/OIDC, and application-layer authentication and authorization
Senior Application Security Architect Overview At JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. The Application Security Architect is a senior individual contributor responsible for bridging application security engineering and enterprise security architecture at JLL. This role designs and owns security architectures for application ecosystems, integrates security into the software development lifecycle (SDLC), and serves as a technical authority on secure design patterns, threat modeling, and DevSecOps practices. Operating at the Senior level, this position independently leads application security initiatives, mentors junior engineers and developers, and partners across engineering, architecture, and business teams to reduce risk and enable secure digital transformation. If you’re a strategic thinker with application security expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you. Essential Duties and
Responsibilities:
Security Architecture & Design Design and maintain security architecture standards, policies, and patterns for enterprise applications, platforms, and cloud-native environments, ensuring alignment with JLL's technology strategy and risk posture. Develop and enforce secure design patterns, reference architectures, and architecture decision records (ADRs) for application security across development teams. Lead security architecture reviews for new and existing applications, evaluating designs against frameworks such as OWASP, NIST, and SANS. Integrate zero-trust principles and defense-in-depth strategies into application architecture to reduce attack surface and support enterprise risk management goals. DevSecOps & Secure Development Lifecycle Define and maintain a standardized set of enterprise application security requirements and produce metrics to report performance against those requirements. Lead threat modeling sessions for new application features and system integrations, producing actionable remediation guidance for development teams. Champion secure coding standards and developer security enablement programs in collaboration with platform and application engineering teams. Risk, Compliance & Stakeholder Engagement Analyze complex security requirements across multiple technology domains and design comprehensive security solutions that address enterprise risk and regulatory compliance obligations. Communicate security architecture designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders across business units. Coordinate security design reviews and approval processes, facilitating alignment between security, engineering, and enterprise architecture teams. Contribute to JLL's application security strategy roadmap, identifying emerging threats and recommending enhancements to the secure development and architecture programs. Mentorship & Team Leadership Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards. Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams. Support secure development training and awareness programs to build security competency across engineering organizations. Required Knowledge, Skills, and Abilities:Technical Knowledge Comprehensive knowledge of application security methodologies, including OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns. Demonstrated experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads. Strong proficiency in DevSecOps practices and tooling: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration. Experience with enterprise security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles. Working knowledge of identity and access management (IAM), OAuth 2.0/OIDC, and application-layer authentication and authorization