Alarm.com

Alarm.com

Application Security Architect

Tysons, Virginia

Sponsorship not specifiedDetected 2 days ago
JavaScriptPythonC#GitKubernetesCI/CDMachine LearningLLMsCybersecurityIncident ResponseSupply ChainElectrical EngineeringFirewallLeadershipCommunicationProblem Solving

About the role

  • Do you love diving deep into complex systems?
  • Are you passionate about helping engineering teams ship secure, high‑quality software?
  • Do you get energy from solving practical security problems at scale and partnering closely with developers, architects, and product teams?

Responsibilities

  • Secure SDLC Integration: Partner with engineering and platform leadership to embed security practices throughout the development lifecycle.
  • Threat Modeling & Design Reviews: Lead threat modeling and participate in feature-team design reviews to ensure security best practices are applied across new features and architectural changes.
  • Collaborate early with engineers, architects, and tech leads during design sessions to identify risks, guide secure design decisions, and embed security into system architecture.
  • AI & LLM Security: Partner with teams adopting AI and LLM-based systems-both internal tooling and production features-to ensure secure design, model and data protection, prompt/input validation, and safe integration patterns.
  • Automation & Tooling: Build and maintain security automation integrated into CI/CD pipelines. Automate detection, validation, and developer‑friendly remediation workflows to improve signal quality and reduce friction.
  • Developer Guidance & Training: Serve as a domain expert and partner to engineering teams. Deliver workshops, provide secure coding guidance, and help teams adopt effective security controls and testing practices.
  • Security Policy & Compliance: Translate policy and compliance requirements into practical guidance for developers. Contribute to policy evolution and support audit activities as needed.
  • Incident Response: Collaborate with InfoSec during security incidents and investigations. Maintain and evolve runbooks and contribute to post‑incident reviews to drive systemic improvements.
  • Code & Application Reviews: Perform deep, targeted reviews of high‑risk code paths, APIs, authentication/authorization flows, and sensitive components.

Requirements

  • Required Skills & Experience

Nice to have

  • 10+ years of experience in application security, software engineering, or related technical security roles (8+ acceptable for exceptionally strong candidates).
  • Bachelor's in Computer Science, Computer Engineering, Electrical Engineering, or related field, or equivalent work experience
  • Proficiency in at least one programming language (e.g., Python, JavaScript, C#) and ability to navigate large, complex codebases.
  • Knowledge of application security best practices across both cloud and on‑prem environments, including cloud‑hosted Kubernetes and related cloud services.
  • Hands‑on experience with AppSec tooling and techniques (SAST, DAST, SCA, IAST, WAF, etc.).
  • Strong understanding of vulnerabilities, exploitability, and security principles (e.g., OWASP Top 10, secure design patterns).
  • Experience with CI/CD pipelines and DevSecOps practices.
  • Strong analytical thinking, practical problem‑solving skills, and a balanced approach to technical risk.

Skills

  • Triage and track inbound findings from SAST, DAST, IAST, SCA tools, and external sources (bug bounty, penetration tests).
  • Maintain strong awareness of vulnerability trends and exploitability.
  • Prioritize remediation using a risk-based approach, partnering directly with engineering teams.
  • New employees can expect to be given real responsibility for bringing new technologies to the marketplace.
  • Alarm.com values working together and collaborating in person. Our employees work from the office 4 days a week.

Benefits

  • Paid maternity and bonding leave, company-paid disability and life insurance, FSAs, well-being resources and activities, and a casual dress work environment are also part of our outstanding total rewards package!
  • Coordinate with Penetration Testers, Red Teams, and Compliance teams to ensure holistic coverage.

Equal opportunity

  • Equal Opportunity Employer

Visa & Work Authorization

  • Please note that sponsorship of new applicants for employment authorization, or any other immigration-related support, is not available for this position at this time.

This listing is sourced directly from Alarm.com's careers page and normalized into a canonical job model.