Demo

Application Security Architect

Corebridge Financial
Houston, TX Full Time
POSTED ON 4/17/2025
AVAILABLE BEFORE 5/15/2025
Who We Are

At Corebridge Financial, we believe action is everything. That’s why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.

We Align To a Set Of Values That Are The Core Pillars That Define Our Culture And Help Bring Our Brand Purpose To Life

  • We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners
  • We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders
  • We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future
  • We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work

About The Role

The Application Security Architect to lead the design, implementation, and oversight of secure application architectures across our organization. This role focuses on integrating security into software development processes, collaborating with developers and application security teams, and building scalable, secure application frameworks. The ideal candidate will bring deep expertise in application security, strong communication skills, and the ability to work independently or collaboratively to drive security initiatives and foster a security-first culture.

  • Design, document, and maintain secure architecture patterns, diagrams, and reference architectures for Web, API, and Mobile applications.
  • Conduct security reviews of application designs, APIs, and development pipelines, identifying vulnerabilities and recommending secure design strategies.
  • Perform threat modeling and risk assessments to identify vulnerabilities and recommend appropriate mitigating controls.
  • Recommend and oversee the implementation of security controls in CI/CD pipelines, ensuring governance and standardization of tools such as SAST, DAST, and IAST.
  • Collaborate closely with application security teams, developers, application owners, cloud teams, and engineering teams to integrate security into the SDLC and organizational workflows.
  • Communicate risks effectively to developers, application owners, and senior executives, tailoring technical risks into actionable insights for both technical and non-technical audiences.
  • Guide the adoption and implementation of OWASP standards, including ASVS, OWASP Top 10, and API Security Top 10.
  • Demonstrate strong knowledge and understanding of microservices driven architecture, ensuring secure integration into overall system design.
  • Maintain familiarity with APIs, API gateways, service mesh, and API-related security tooling and practices to secure API designs and integrations.
  • Provide expertise in container security, advising on the use of immutable operating systems and secure deployment practices.
  • Partner with developers and engineering teams to promote secure coding practices and ensure security is a natural part of their workflows.
  • Stay informed of emerging application security threats and technologies, and proactively recommend improvements to enhance the security posture.
  • Foster a security-first culture by mentoring development teams, promoting secure coding practices, and embedding security in organizational workflows.

Please note: The job can only be performed in the State location listed: Jersey City, NJ, Durham, NC, and Houston, TX.

Required Qualifications

What we are looking for

  • 7 years of hands-on experience in application security, secure coding, and software development practices for Web, API, and Mobile applications.
  • Strong ability to create and review application designs, diagrams, and reference architectures.
  • Expertise in secure software development life cycle (SDLC) and DevSecOps processes.
  • Proficiency in SaaS, PaaS, and IaaS environments, including platforms like AWS, Azure, M365 and Saleforce.
  • Experience with various application security tools, such as SonarQube, Veracode, Codacy and familiarity with integrating security into CI/CD pipelines.
  • Knowledge of common CI/CD pipeline and development tools, such as Jenkins, GitHub, Artifactory, Terraform, Vault.
  • Knowledge of containerization and orchestration technologies like Docker, Kubernetes, EKS, ECS and OCP, including container security practices and the use of immutable containers.
  • Working knowledge of regulatory requirements and compliance standards such as NYDFS, CCPA, PCI-DSS, HIPAA, SOX, and GDPR.
  • Relevant certifications such as CISSP, CSSLP, OSCP or equivalent.
  • Ability to work independently or collaboratively in a team-oriented environment.
  • Bachelor’s degree in a relevant field or proven record of experience in Information Technology and Cyber Security roles.

Technical Skills

  • Knowledge of OWASP ASVS, OWASP Top 10, API Security Top 10, and secure coding practices.
  • Proficiency in designing, implementing, and securing API gateways (e.g., Kong, Apigee, AWS API Gateway) and service mesh (e.g., Istio, Linkerd) for secure communication and service management.
  • Expertise in implementing security controls in CI/CD pipelines, ensuring alignment with security standards and best practices using tools such as Jenkins, GitHub, and Terraform.
  • Knowledge of securing containerized environments, including securing images, leveraging immutable OSes, and applying best practices in orchestration security.
  • Expertise in designing processes for patching vulnerabilities and implementing resilient deployment strategies (e.g., blue-green deployments).
  • Expertise in encryption (e.g., TLS, AES, RSA) and secure data management practices.

Common Security And Architecture Frameworks

  • OWASP ASVS (Application Security Verification Standard)
  • NIST Cybersecurity Framework (CSF)
  • ISO 27001 and 27002
  • CIS Controls
  • SABSA (Sherwood Applied Business Security Architecture)
  • TOGAF (The Open Group Architecture Framework)
  • AWS Well-Architected Framework

Preferred Certifications

  • Certified Secure Software Lifecycle Professional (CSSLP)
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer (GSSP)
  • AWS Certified Solutions Architect – Associate or Professional
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Solutions Architect Expert
  • TOGAF (The Open Group Architecture Framework)
  • SABSA Foundation or Practitioner

Soft Skills

  • Strong analytical and problem-solving abilities.
  • Excellent interpersonal and collaboration skills.
  • Proven ability to communicate complex ideas to technical and non-technical audiences.
  • Strong organizational and time management skills.
  • Adaptability and a commitment to continuous learning of new technologies and methodologies.
  • Attention to detail and dedication to delivering high-quality results.
  • High level of integrity and ethical conduct.

Industry-Specific Experience

  • Experience in financial services, insurance, or other regulated environments.
  • Proven ability to design and implement application security controls that align with industry regulations and standards.
  • Experience conducting application security assessments and audits in regulated industries.
  • Familiarity with industry-specific application threats and vulnerabilities to tailor security solutions.

For position based in Jersey City, NJ, the base salary range is $128,000 - $155,000 and the position is eligible for a bonus in accordance with the terms of the applicable incentive plan. In addition, we're proud to offer a range of competitive benefits.

This role is deemed a “covered associate” under SEC Rule 206(4)-5, 17 CFR

  • 275.206(4)-5, Political contributions by certain investment advisers, and other federal and state pay-to-play rules. Candidates for the role must not have made any political contributions that, under 17 CFR
  • 275.206(4)-5 or other federal or state pay-to-play regulations, would disqualify the candidate or Corebridge Financial from conducting Corebridge Financial’s business, or that would otherwise create a conflict of interest for Corebridge Financial. Applicants who are selected to move forward with the application process will be required to disclose all U.S. political contributions they and their household family members have made over the past two years.

Applications will be accepted for this position until a satisfactory candidate pool has been identified.

Why Corebridge?

At Corebridge Financial, we prioritize the health, well-being, and work-life balance of our employees. Our comprehensive benefits and wellness program is designed to support employees both personally and professionally, ensuring that they have the resources and flexibility needed to thrive.

Benefit Offerings Include

  • Health and Wellness: We offer a range of medical, dental and vision insurance plans, as well as mental health support and wellness initiatives to promote overall well-being
  • Retirement Savings: We offer retirement benefits options, which vary by location. In the U.S., our competitive 401(k) Plan offers a generous dollar-for-dollar Company matching contribution of up to 6% of eligible pay and a Company contribution equal to 3% of eligible pay (subject to annual IRS limits and Plan terms). These Company contributions vest immediately.
  • Employee Assistance Program: Confidential counseling services and resources are available to all employees
  • Matching charitable donations: Corebridge matches donations to tax-exempt organizations 1:1, up to $5,000
  • Volunteer Time Off: Employees may use up to 16 volunteer hours annually to support activities that enhance and serve communities where employees live and work
  • Paid Time Off: Eligible employees start off with at least 24 Paid Time Off (PTO) days so they can take time off for themselves and their families when they need it.

Eligibility for and participation in employer-sponsored benefit plans and Company programs will be subject to applicable law, governing Plan document(s) and Company policy.

We are an Equal Opportunity Employer

Corebridge Financial, is committed to being an equal opportunity employer and we comply with all applicable federal, state, and local fair employment laws. All applicants will be considered for employment based on job-related qualifications and without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, neurodivergence, age, veteran status, or any other protected characteristic. The Company is also committed to compliance with all fair employment practices regarding citizenship and immigration status. At Corebridge Financial, we believe that diversity and inclusion are critical to building a creative workplace that leads to innovation, growth, and profitability. Through a wide variety of programs and initiatives, we invest in each employee, seeking to ensure that our colleagues are respected as individuals and valued for their unique perspectives.

Corebridge Financial is committed to working with and providing reasonable accommodations to job applicants and employees, including any accommodations needed on the basis of physical or mental disabilities or sincerely held religious beliefs. If you believe you need a reasonable accommodation in order to search for a job opening or to complete any part of the application or hiring process, please send an email to TalentandInclusion@corebridgefinancial.com. Reasonable accommodations will be determined on a case-by-case basis, in accordance with applicable federal, state, and local law.

We will consider for employment qualified applicants with criminal histories, consistent with applicable law.

To learn more please visit: www.corebridgefinancial.com

Corebridge Financial is committed to working with and providing reasonable accommodations to job applicants and employees with physical or mental disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to complete any part of the application or hiring process, please send an email to TalentandInclusion@corebridgefinancial.com. Reasonable accommodations will be determined on a case-by-case basis.

Applications will be accepted for this position until a satisfactory candidate pool has been identified

Functional Area

IT - Information Technology

Estimated Travel Percentage (%): Up to 25%

Relocation Provided: No

American General Life Insurance Company

Salary : $128,000 - $155,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Architect?

Sign up to receive alerts about other jobs on the Application Security Architect career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$144,503 - $184,592
Income Estimation: 
$150,756 - $194,140
Income Estimation: 
$172,191 - $221,861
Income Estimation: 
$114,549 - $164,025
Income Estimation: 
$153,752 - $200,235
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$144,503 - $184,592
Income Estimation: 
$102,541 - $137,871
Income Estimation: 
$153,752 - $200,235
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Corebridge Financial

Corebridge Financial
Hired Organization Address Houston, TX Full Time
Who we areCorebridge Financial helps people make some of the most meaningful decisions they’re ever going to make. We he...
Corebridge Financial
Hired Organization Address King, WA Full Time
Who We Are Corebridge Financial helps people make some of the most meaningful decisions they’re ever going to make. We h...
Corebridge Financial
Hired Organization Address Los Angeles, CA Full Time
Who We Are At Corebridge Financial, we believe action is everything. That’s why every day we partner with financial prof...
Corebridge Financial
Hired Organization Address Los Angeles, CA Full Time
Who We Are Corebridge Financial helps people make some of the most meaningful decisions they’re ever going to make. We h...

Not the job you're looking for? Here are some other Application Security Architect jobs in the Houston, TX area that may be a better fit.

Application Architect

Marsh LLC, Houston, TX

Application Architect

Empower Pharmacy, Houston, TX

AI Assistant is available now!

Feel free to start your new journey!