Senior Application Security Architect

State Street

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Quincy, MAPrinceton, NJBerwyn, PAClifton, NJAustin, TX
Salary
$120,000–$202,500 / yr
Posted
66 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $184k
This role $161k
$107k most similar roles pay here $244k

This role pays less than 68% of similar roles. Most pay $151,475–$216,000 — the shaded band above. At the midpoint, this role pays about $161k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About State Street

State Street Corporation is one of the world''s largest custodian banks and asset managers, providing investment servicing, investment management, and investment research to institutional investors. Industry: Financial Services & Asset Custody

State Street currently has 186 open roles on FindRole.

Listed pay typically runs $120,000–$202,500 across 182 roles with salary data.

Most-posted roles

View all roles at State Street

At a glance

TL;DR · Senior Application Security Architect

As a Senior Application Security Architect within the Security Architecture organization, you will design, review, and govern security architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems. You will partner with software engineering, data science, and cybersecurity teams to embed secure-by-design principles throughout the development lifecycle. Your daily responsibilities include conducting threat modeling, defining security standards, and assessing risks associated with LLMs, agentic AI systems, and training data. You will utilize a technical toolkit including Kubernetes, containers, CI/CD pipelines, Infrastructure as Code, and DevSecOps practices while performing SAST, DAST, and IAST testing. The role focuses on securing complex infrastructure in hybrid environments, addressing specific challenges like prompt injection and model misuse to protect digital platforms and data within highly regulated industries through robust authentication, authorization, and proactive risk management.

What you'll do

  • Design and review secure architectures for enterprise applications, APIs, cloud-native platforms, and AI-enabled systems.
  • Define and maintain application security standards, architecture patterns, and specific requirements for AI technologies.
  • Conduct threat modeling exercises and design assessments for various software and AI solutions.
  • Embed security controls throughout the software and AI development lifecycles in partnership with engineering teams.
  • Assess security risks associated with AI models, training data, prompts, agents, and third-party services.
  • Drive the adoption of Zero Trust, DevSecOps, and secure-by-design principles across the enterprise.
  • Evaluate emerging security threats and industry standards related to application and AI technologies.

What we're looking for

  • Degree in Computer Science, Cybersecurity, Information Technology, Engineering, Data Science, or a related discipline.
  • 14 years or more of experience in application security, software engineering, security architecture, AI security, or related technology disciplines.
  • At least 8 years of hands-on cybersecurity experience is preferred.
  • Expertise in secure software development lifecycle (SSDLC), OWASP Top 10, API security, and application security testing methodologies.
  • Deep knowledge of AI/ML security risks, including LLMs, RAG, agentic systems, prompt injection, and model security.
  • Experience with cloud-native technologies, containers, Kubernetes, CI/CD pipelines, DevSecOps, and Infrastructure as Code (IaC).
  • Proficiency in threat modeling, architecture reviews, penetration test remediation, and risk assessments for AI-enabled solutions.
  • Professional certifications such as CISSP, CSSLP, CCSP, TOGAF, SABSA, or cloud-specific security certifications are highly desirable.

More like this

Similar roles

Application Security Senior Manager

Booz Allen Hamilton

Annapolis Junction, MD +3 47 days ago $125,300$233,000
Application Security SAST DAST IAST SCA CI/CD Threat Modeling OWASP Top 10 NIST Vulnerability Management SDLC AI Scanning Mythos Frontier AI Code Scanning
10+ yrs exp

Senior Data Security Architect

State Street

Quincy, MA +4 66 days ago $120,000$202,500
Data Security Encryption Tokenization Masking KMS PKI Secrets Management AWS Microsoft Azure Google Cloud Platform SaaS Data Governance Threat Modeling Risk Assessment CISSP CCSP CDPSE CIPP SABSA TOGAF
10+ yrs exp Hybrid

Lead Architect, Application Security

F5 Inc

Remote (San Jose, CA) 54 days ago $297,600$446,400
WAAP WAF DDoS Mitigation API Security TLS Kubernetes Istio Envoy SaaS OAuth2 OIDC SAML Zero Trust Policy-as-Code HTTP/2 HTTP/3 WebSockets gRPC NIST CSF OWASP Top 10 FIPS FedRAMP ISO 27001 GDPR
10+ yrs exp Remote

Cloud Security Architect

State Street

Quincy, MA +4 65 days ago $90,000$157,500
AWS Microsoft Azure Google Cloud Platform Kubernetes Containers Identity and Access Management Network Security Data Protection Encryption DevSecOps CI/CD Infrastructure as Code Zero Trust SaaS Cloud-Native Architecture Security Automation
8+ yrs exp Hybrid

Senior Threat Modeler

State Street

Boston, MA +4 66 days ago $120,000$202,500
Threat Modeling STRIDE MITRE ATT&CK AWS Azure Google Cloud Platform Kubernetes CI/CD DevSecOps OWASP Top 10 API Security Microservices Containers Secure Software Development Lifecycle Risk Assessment Security Architecture
10+ yrs exp Hybrid

Application Security Engineer

State Street

Quincy, MA +3 47 days ago $120,000$202,500
AppSec ADR DevSecOps SAST DAST SCA RASP WAAP API Security OWASP Top 10 Java Python .NET Node.js AWS Azure Ansible Terraform Kubernetes CI/CD Infrastructure as Code
6+ yrs exp