📍United States
Security Application Solution Architect
AbbVie
📍Remote - United States
Please let AbbVie know you found this job on JobsCollider. Thanks! 🙏
Summary
Join AbbVie's Information Security team as an Application Solution Architect! You will collaborate with application development teams to design and implement secure technology solutions. This role requires expertise in secure application development, cloud environments, and security architecture. You will work with various stakeholders to define security policies, address risks, and ensure compliance. The position offers remote work flexibility within the U.S. and a comprehensive benefits package.
Requirements
- Bachelor’s degree and 9 years of experience OR Master’s Degree and 8 years of experience OR PhD and 4 years of experience in information security and/or related functions (IT Audit, Risk Management or Security Architecture)
- During recent history, candidate must have demonstrated exceptional ability to assess and communicate information security concepts and practices, with both business and IT stakeholders
- Requires in-depth knowledge of the systems development life cycle, client area’s functions and systems, and systems applications programs development technological alternatives
- Proven implementation of creative technology solutions that advance the business
- Relevant work experience is important for successful performance of this role due to the complexity of our global IT Security environment
- Design the security architecture for applications, ensuring all components meet best practices and regulatory compliance
- Work closely with software development, DevOps, and operations teams to integrate security into the software development lifecycle (SDLC)
- Lead efforts in identifying potential threats through application threat modeling and propose design changes to mitigate risks
- Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project
- Significant SOX and HIPAA experience in dealing with IT general controls (ITGC), demonstrated through hands-on audit, remediation, and/or computer system validation
- Excellent understanding of current Information Security & Architecture trends and their impact on business strategies including: key Information Security vendors and solutions, audit organizations and influential market research firms
- Excellent communications and influencing skills with strong ability to balance differing stakeholder interests through sound analysis and persuasion
- Strong people skills, collaborative ability to work with IT stakeholders inside and outside of the organization, able to mentor team members with diverse backgrounds
- Ability to formulate network security architecture vision and translate vision into execution
- Thorough understanding of Information Security frameworks and good practices (e.g. ISO, NIST), and proven ability to strike a balance between an academic and pragmatic approach
- Strong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices
- Expertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect)
- Knowledge of cryptographic practices, encryption protocols, and PKI management
- Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP)
- Familiarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus)
- Understanding of DevSecOps practices, including securing CI/CD pipelines
- Self-starter with the ability to work independently and manage multiple projects simultaneously
- Strong problem-solving and analytical skills with the ability to identify security risks and propose effective solutions
- Ability to work collaboratively in cross-functional teams and influence technical teams towards secure implementations
Responsibilities
- Work with in-business IT customers, including application architects and engineers to evaluate application software and infrastructure designs, for the purpose of defining/designing application controls aligned with enterprise standards
- Generate detailed application specific security controls design and documentation for each business application under review
- Develop re-usable implementation guidance and design patterns based on previous engagements to scale the service
- Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure and applications
- Establish collaborative working relations with business application architecture staff to ensure that solutions align with security architecture and business strategy
- Support security aspects of business & IT initiatives by assisting in architecture, design, implementation, deployment, and operational transition of innovative & secure technology solutions
- Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure
- Research, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies
- Establish collaborative working relations with the Information Technology functions to ensure that solutions align with security architecture and business strategy
- Play an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned. Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed
- Research and assess new information security threats and recommend remedial actions
- Foster an information security culture through education, skill development, and implementation of effective information security processes and practices
- Understand and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety, GxP compliance, data security, and the software development lifecycle
- Matures and leverages relationships with affiliates, subsidiaries, vendors, and industry peers in accordance with Abbvie Values, Vendor Management Office, and Purchasing to further the mission, vision and goals of the organization
Preferred Qualifications
- Understanding the following concepts is a plus; identity management, federated identity services, incident management, access control, application vulnerability testing, public key infrastructure, Windows, and Unix/Linux, public cloud infrastructure and services
- Information security qualification such as CISSP is preferred
Benefits
- Paid time off (vacation, holidays, sick)
- Medical/dental/vision insurance
- 401(k)
- Short-term incentive programs
- Long-term incentive programs
Share this job:
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.
Similar Remote Jobs
📍Croatia
💰$175k-$200k
📍United States
📍United Kingdom
📍Romania
Senior Software Solutions Architect, Financial Solutions
Christian Care Ministry
💰$130k-$160k
📍United States
📍United States
📍Canada
📍United States