Application & Platform Security Architect at AbbVie | Austin, Texas | Rezi

Application & Platform Security Architect at AbbVie

Application & Platform Security Architect

AbbVie · Austin, Texas

1 months ago

Application & Platform Security Architect

AbbVie · Austin, Texas

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

AbbVie is seeking a highly skilled Application & Platform Security Architect to join the Information Security team. This role involves developing and implementing a comprehensive information security program, defining security policies, processes, and standards. The architect will collaborate with application development teams to ensure secure design, coding, configuration, and deployment of technology solutions, focusing on application-level risks and secure development practices, including API interactions and cloud environments.

Responsibilities

  • Define reusable security architecture patterns and guardrails for consistent, secure implementation across high-risk business applications.
  • Drive secure-by-design initiatives by integrating security early in the software architecture lifecycle.
  • Represent security architecture in design authority boards and technical review councils.
  • Evaluate application software and infrastructure designs to define/design application controls aligned with enterprise standards.
  • Define application-specific security control architectures and produce design artifacts.
  • Develop re-usable implementation guidance and design patterns.
  • Develop strategies and plans to enforce security requirements and address identified risks.
  • Act as a security architecture liaison to IT delivery and engineering teams.
  • Support security aspects of business & IT initiatives.
  • Research, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies.
  • Establish collaborative working relations with IT functions to ensure solutions align with security architecture and business strategy.
  • Assess security requirements and controls in application development or acquisition projects.
  • Complete remediation activities and initiate actions to address compliance and security gaps.
  • Research and assess new information security threats and recommend remedial actions.
  • Foster an information security culture through education and process implementation.
  • Adhere to corporate standards regarding applicable Corporate and Divisional Policies.
  • Mature and leverage relationships with affiliates, subsidiaries, vendors, and industry peers.
  • Design the security architecture for applications, ensuring all components meet best practices and regulatory compliance.
  • Work closely with software development, DevOps, and operations teams to integrate security into the SDLC.
  • Lead efforts in identifying potential threats through application threat modeling and propose design changes to mitigate risks.

Requirements

  • Bachelor’s degree and 9 years of experience OR Master’s Degree and 8 years of experience OR PhD and 4 years of experience in information security and/or related functions (IT Audit, Risk Management or Security Architecture).
  • Demonstrated exceptional ability to assess and communicate information security concepts and practices.
  • In-depth knowledge of the systems development life cycle, client area’s functions and systems, and systems applications programs development technological alternatives.
  • Proven implementation of creative technology solutions that advance the business.
  • Strong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices.
  • Expertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect).
  • Knowledge of cryptographic practices, encryption protocols, and PKI management.
  • Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP).
  • Familiarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus).
  • Understanding of DevSecOps practices, including securing CI/CD pipelines.
  • Self-starter with the ability to work independently and manage multiple projects simultaneously.
  • Strong problem-solving and analytical skills.
  • Ability to work collaboratively in cross-functional teams and influence technical teams.
  • Understanding of cloud computing principles, including virtualization, containerization, microservices, and serverless computing.
  • Advanced knowledge of Identity Security concepts, least-privilege, separation of duties, and Zero trust design principles.
  • Understanding of federation technologies (WS-Fed, OAuth, OpenID connect, SAML) and of encryption technologies (encryption types and protocols/standards).
  • Knowledge of and experience in developing and documenting security architecture and plans.
  • Significant SOX and HIPAA experience in dealing with IT general controls (ITGC).
  • Excellent understanding of current Information Security & Architecture trends.
  • Excellent communications and influencing skills.
  • Strong people skills and collaborative ability.
  • Thorough understanding of Information Security frameworks and good practices (e.g., ISO, NIST).

Skills

  • Application Security
  • OWASP Top 10
  • SANS/CWE Top 25
  • Secure Coding Practices
  • Session Management
  • Token Handling
  • Authentication Mechanisms
  • OAuth
  • SAML
  • OpenID Connect
  • Cryptographic Practices
  • Encryption Protocols
  • PKI Management
  • Containerization
  • Docker
  • Kubernetes
  • Cloud Platforms
  • AWS
  • Azure
  • GCP
  • Code Analysis Tools
  • SonarQube
  • Veracode
  • Vulnerability Scanning Tools
  • Burp Suite
  • Nessus
  • DevSecOps
  • CI/CD Pipelines
  • Cloud Computing Principles
  • Virtualization
  • Microservices
  • Serverless Computing
  • Identity Security
  • Least-privilege
  • Separation of Duties
  • Zero Trust Design Principles
  • Federation Technologies
  • WS-Fed
  • Information Security Frameworks
  • NIST
  • ISO

Location

  • US

Work Type

  • Full-time
  • Hybrid

Experience Level

  • Senior

Education Level

  • Bachelor's Degree
  • Master's Degree
  • PhD

Salary/Compensations

  • USD 141500 - USD 268500 - yearly

Benefits

  • Paid time off (vacation, holidays, sick)
  • Medical/dental/vision insurance
  • 401(k)
  • Long-term incentive programs

About the Company

  • AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow.
  • We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio.
  • For more information about AbbVie, please visit us at www.abbvie.com.
  • Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.

Equal Opportunity

  • AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.
  • Equal Opportunity Employer/Veterans/Disabled.
  • US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
  • US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: https://www.abbvie.com/join-us/reasonable-accommodations.html