Alarm.com
Application Security Architect
Tysons, Virginia
Sponsorship not specifiedDetected 2 days ago
JavaScriptPythonC#GitKubernetesCI/CDMachine LearningLLMsCybersecurityIncident ResponseSupply ChainElectrical EngineeringFirewallLeadershipCommunicationProblem Solving
About the role
- Do you love diving deep into complex systems?
- Are you passionate about helping engineering teams ship secure, high‑quality software?
- Do you get energy from solving practical security problems at scale and partnering closely with developers, architects, and product teams?
Responsibilities
- Secure SDLC Integration: Partner with engineering and platform leadership to embed security practices throughout the development lifecycle.
- Threat Modeling & Design Reviews: Lead threat modeling and participate in feature-team design reviews to ensure security best practices are applied across new features and architectural changes.
- Collaborate early with engineers, architects, and tech leads during design sessions to identify risks, guide secure design decisions, and embed security into system architecture.
- AI & LLM Security: Partner with teams adopting AI and LLM-based systems-both internal tooling and production features-to ensure secure design, model and data protection, prompt/input validation, and safe integration patterns.
- Automation & Tooling: Build and maintain security automation integrated into CI/CD pipelines. Automate detection, validation, and developer‑friendly remediation workflows to improve signal quality and reduce friction.
- Developer Guidance & Training: Serve as a domain expert and partner to engineering teams. Deliver workshops, provide secure coding guidance, and help teams adopt effective security controls and testing practices.
- Security Policy & Compliance: Translate policy and compliance requirements into practical guidance for developers. Contribute to policy evolution and support audit activities as needed.
- Incident Response: Collaborate with InfoSec during security incidents and investigations. Maintain and evolve runbooks and contribute to post‑incident reviews to drive systemic improvements.
- Code & Application Reviews: Perform deep, targeted reviews of high‑risk code paths, APIs, authentication/authorization flows, and sensitive components.
Requirements
- Required Skills & Experience
Nice to have
- 10+ years of experience in application security, software engineering, or related technical security roles (8+ acceptable for exceptionally strong candidates).
- Bachelor's in Computer Science, Computer Engineering, Electrical Engineering, or related field, or equivalent work experience
- Proficiency in at least one programming language (e.g., Python, JavaScript, C#) and ability to navigate large, complex codebases.
- Knowledge of application security best practices across both cloud and on‑prem environments, including cloud‑hosted Kubernetes and related cloud services.
- Hands‑on experience with AppSec tooling and techniques (SAST, DAST, SCA, IAST, WAF, etc.).
- Strong understanding of vulnerabilities, exploitability, and security principles (e.g., OWASP Top 10, secure design patterns).
- Experience with CI/CD pipelines and DevSecOps practices.
- Strong analytical thinking, practical problem‑solving skills, and a balanced approach to technical risk.
Skills
- Triage and track inbound findings from SAST, DAST, IAST, SCA tools, and external sources (bug bounty, penetration tests).
- Maintain strong awareness of vulnerability trends and exploitability.
- Prioritize remediation using a risk-based approach, partnering directly with engineering teams.
- New employees can expect to be given real responsibility for bringing new technologies to the marketplace.
- Alarm.com values working together and collaborating in person. Our employees work from the office 4 days a week.
Benefits
- Paid maternity and bonding leave, company-paid disability and life insurance, FSAs, well-being resources and activities, and a casual dress work environment are also part of our outstanding total rewards package!
- Coordinate with Penetration Testers, Red Teams, and Compliance teams to ensure holistic coverage.
Equal opportunity
- Equal Opportunity Employer
Visa & Work Authorization
- Please note that sponsorship of new applicants for employment authorization, or any other immigration-related support, is not available for this position at this time.
Apply directly at Alarm.com →Create a free account for alerts like thisView Alarm.com immigration profile
This listing is sourced directly from Alarm.com's careers page and normalized into a canonical job model.