Senior Application Security Architect

8 Months ago • 5 Years + • Cyber Security

Job Summary

Job Description

Senior Application Security Architect with 5+ years of experience in development or security, strong understanding of software development, architecture, and application security. Must have experience in threat modeling, security architecture reviews, and secure coding guidelines.
Must have:
  • Application Security
  • Threat Modeling
  • Security Architecture
  • Secure Coding
Good to have:
  • Authentication Models
  • Cloud Environments
  • Vulnerability Management
  • Development Experience
Perks:
  • Hybrid Work
  • Global Collaboration

Job Details

The Team:

The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity, and availability of Morningstar information. The security team offers guidance and technical expertise in areas like application security, infrastructure and cloud security, policies and procedures, disaster recovery and compliance/regulation. We analyze emerging security threats and conduct risk and vulnerability assessments to ensure that our information remains secure.

The Role:
The Senior Application Security Architect will be part of the central information security team and act as a subject matter expert to all of Morningstar’s product teams by provide security guidance and creating application security standards and patterns. The successful candidate will contribute to maintaining Morningstar’s security posture by performing threat modeling, security architecture reviews of Morningstar products and ensure that major projects receive appropriate architectural security guidance, requirements setting, and review. The Application Security Architect will also partner with the Director of Product Security to define the direction of the application security program as well as on improving security processes and tooling. The position will be based in our Chicago or Toronto office.

We follow a hybrid policy of 3 days onsite and 2 days remote work.

Job Responsibilities:

  • Collaborate with development teams across the organization to secure products
  • Contribute to secure reference architectures and patterns for all product teams to leverage
  • Develop, maintain, and communicate future and current product security initiatives
  • Develop and enhance internal security processes, programs, and procedures
  • Conduct risk assessments, threat modeling, and product security reviews on Morningstar systems
  • Work directly with internal business units to communicate risk, provide security remediation advice, and deliver education as needed.
  • Document secure coding guidelines and assist execution by internal development personnel
  • Identify web/mobile/api application security vulnerabilities and offer remediation advice

Qualifications:

  • A bachelor’s degree and 5+ years’ experience in a development or software security / penetration testing role, or equivalent experience
  • We are looking for someone who enjoys breaking code, solving puzzles, and diagnosing problems
  • Excellent communication skills and a strong understanding of software development, architecture, and application security
  • An ability to improve system development security across diverse technical teams and technologies
  • Strong understanding of risk management and the real-world impacts of architectural decisions
  • Experience architecting and deploying applications securely in cloud environments

Nice to have:

  • Strong understanding of common authentication models and protocols (SAML, OAuth, OpenID, etc.) preferred
  • Prior development experience preferred
  • Vulnerability management experience preferred

 

100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity

Morningstar’s hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We’ve found that we’re at our best when we’re purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you’ll have tools and resources to engage meaningfully with your global colleagues.

Similar Jobs

Varonis  - Cloud Security Research Team Leader

Varonis

Herzliya, Tel Aviv District, Israel (On-Site)
7 Months ago
Palo Alto Networks - Customer Success Manager

Palo Alto Networks

London, England, United Kingdom (On-Site)
3 Weeks ago
Ethos Life - Senior Security Engineer

Ethos Life

San Francisco, California, United States (Hybrid)
1 Month ago
Zscaler - Sr. Director, Product Marketing - Platform

Zscaler

San Jose, California, United States (Hybrid)
1 Week ago
Zscaler - Account Executive, Commercial

Zscaler

Tokyo, Japan (Hybrid)
2 Weeks ago
PhonePe - Product Security Engineer

PhonePe

Bengaluru, Karnataka, India (On-Site)
6 Months ago
bytedance - Senior Software Engineer, Global Payment Security

bytedance

San Jose, California, United States (On-Site)
7 Months ago
PwC - Salesforce Technical Lead (Manager)

PwC

Makati, Metro Manila, Philippines (Hybrid)
8 Months ago
Ion - Security Architect, Italy

Ion

Italy (Hybrid)
7 Months ago
GoMotive - Information Security Analyst II

GoMotive

Pakistan (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Stone Search - HRIS Manager - Oracle HCM Cloud

Stone Search

Irvine, California, United States (On-Site)
1 Year ago
reversing labs  - Principal Infrastructure & Cloud Optimization Engineer

reversing labs

Zagreb, Grad Zagreb, Croatia (Hybrid)
1 Month ago
RoofStack - Senior Cyber Security Engineer

RoofStack

Istanbul, İstanbul, Türkiye (Remote)
5 Months ago
SingleStore - Senior/Staff Product Manager, Cloud Security

SingleStore

Hyderabad, Telangana, India (On-Site)
1 Month ago
GoDaddy - Senior Cloud Engineer

GoDaddy

(Remote)
2 Weeks ago
Zscaler - Sr Staff, Cybersecurity Training And Awareness

Zscaler

Costa Rica (Remote)
2 Weeks ago
Zscaler - Sales Engineer

Zscaler

Tokyo, Japan (Hybrid)
1 Week ago
Boomi  - Software Engineer 1 – DevSecOps

Boomi

India (On-Site)
2 Days ago
Zscaler - Technical Account Manager -APAC

Zscaler

Bengaluru, Karnataka, India (Hybrid)
2 Weeks ago
NCR Voyix - Information Security Engineer II

NCR Voyix

Chennai, Tamil Nadu, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Chicago, Illinois, United States

PlayStation Global - Principal Multiplayer Systems Designer

PlayStation Global

United States (Remote)
1 Month ago
WME IMG - Senior Coordinator, eCommerce

WME IMG

Raleigh, North Carolina, United States (On-Site)
1 Year ago
IGT - Senior Vulnerability Management Engineer

IGT

Providence, Rhode Island, United States (On-Site)
3 Weeks ago
Microsoft - Member of Technical Staff, AI Platform Engineer

Microsoft

Mountain View, California, United States (Hybrid)
1 Month ago
bytedance - Software Development Engineer (SDN Traffic Intelligence & Control)

bytedance

Seattle, Washington, United States (On-Site)
1 Month ago
Kavalirio - Workstation Technician

Kavalirio

La Crosse, Wisconsin, United States (On-Site)
4 Weeks ago
bytedance - Student Researcher (Doubao (Seed) - Foundation Model - MultiModal Generative Model)

bytedance

San Jose, California, United States (On-Site)
1 Month ago
SBM Management - Bilingual HR Generalist

SBM Management

St. Louis, Missouri, United States (On-Site)
2 Months ago
Illumination - Graphic Design Intern, Consumer Products – Summer 2025

Illumination

Santa Monica, California, United States (Hybrid)
3 Months ago
AI Fund - Senior Operations Manager

AI Fund

United States (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

bytedance - Senior Software Engineer, Global Payment Security

bytedance

San Jose, California, United States (On-Site)
7 Months ago
Ion - Junior Cyber Security Analyst

Ion

Pisa, Tuscany, Italy (Hybrid)
7 Months ago
Ion - IT Internal Auditor, Italy

Ion

Italy (Hybrid)
7 Months ago
PwC - Information Protection Consultant (Doorlopend)

PwC

Amsterdam, North Holland, Netherlands (On-Site)
5 Months ago
seedify - Cyber Security Specialist

seedify

(On-Site)
1 Year ago
Google - Security Engineer, Hardware Security, Cloud CISO

Google

Zürich, Zurich, Switzerland (On-Site)
1 Month ago
PwC - Senior Associate - Data Engineer - D&AT IFS

PwC

Bengaluru, Karnataka, India (On-Site)
8 Months ago
Google - Strategic Security Consultant

Google

Toronto, Ontario, Canada (On-Site)
1 Month ago
Penumbra - Sr Manager Cybersecurity

Penumbra

Alameda, California, United States (On-Site)
7 Months ago
PwC - ETIC, Cybersecurity Graduate Program

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
7 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Chicago, Illinois, United States (Hybrid)

Mumbai, Maharashtra, India (Hybrid)

New York, New York, United States (Hybrid)

Chicago, Illinois, United States (Hybrid)

Mumbai, Maharashtra, India (Hybrid)

Mumbai, Maharashtra, India (Hybrid)

View All Jobs

Get notified when new jobs are added by Morning Star

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug