At a Glance
- Tasks: Lead security architecture for applications, ensuring compliance and risk management.
- Company: Atrium UK is a forward-thinking company focused on healthcare solutions.
- Benefits: Enjoy remote work flexibility with occasional office visits in London.
- Why this job: Join a dynamic team making a real impact in healthcare security.
- Qualifications: Extensive experience in application security and knowledge of GDPR, HIPAA & PCI frameworks required.
- Other info: This role offers opportunities for professional growth and development in a regulated environment.
The predicted salary is between 48000 - 72000 £ per year.
Atrium UK are looking for an accomplished Application Security Architect to work closely with all levels of engineering and solution architecture teams to produce technical requirements and ensure solutions work together and fulfil business needs. This is a remote role with occasional visits to the London office. You must be based within the UK and be able to travel to the London Office when needed.
Responsibilities:
- Investigate and resolve complex and high-priority incidents.
- Communicate to senior management on risk management concepts, as well as specific project risks and risk mitigation options/scenarios.
- Manage a portfolio of applications and projects from inception to completion, ensuring the correct security controls are put in place.
- Maintain a deep understanding of the business, our patients and healthcare-delivery models.
- Ensure Information Security policies and procedures are up to date, relevant and adhered to, including security and technical standards.
- Perform vulnerability testing, risk analysis, and security architecture assessments.
- Relate well to constraints experienced by business partners and find practical, win-win solutions.
- Analyse customer needs; ensure solutions meet business and security requirements.
- Hold self and others accountable for meeting customer needs and expectations in a timely, professional manner.
- Maintain high personal accountability; take ownership of issues, develop effective remediation approaches, and drive for results.
- Employ business acumen to develop appropriate solutions and solve problems - understand business risks and business objectives.
- Translate business needs into information security requirements.
- Communicate technical security risks in a manner that resonates with business leaders.
- Establish and manage to a planned set of related activities with a focus on hitting deadlines.
- Stay up to date with industry trends, best practices and regulatory standards that may impact product implementations.
Essential:
- Extensive experience of Application security architecture.
- Experience working in large and highly regulated organizations and agile environments.
- Experience with practical interpretation and application of policy and standards.
- Subject matter expert knowledge of the technology aspects of security.
- Experience with implementation of Security within development pipelines and DevOps with a good understanding of customer centric design principles and software development.
- Experience with GDPR, HIPAA & PCI frameworks.
- Technical security certification like CISSP, CCSP, CEH, Microsoft Azure or AWS or equivalent.
- Thorough understanding of Development and Architecture roles such as DevOps, SRE, Solution/Technical Architect and Senior Developer.
- Working knowledge of secure development practices and standards such as OWASP and MITRE especially on cloud providers.
- Excellent written and verbal communication skills with Stakeholder management and interpersonal skills at both a technical and non-technical level as well as at various levels of seniority.
- Identifying the need for new, or changes to existing, security patterns for UI, API, and microservices.
- Threat Modelling and dynamic security testing experience, to identify any security risks before live deployment.
- Development experience in .NET and/or Java. Experience with scripting (e.g. python, PowerShell, bash). Experience of web application and API development (Typescript, React, HTTP, PHP).
- Demonstrable Understanding of cryptography concepts.
- Business analysis experience such as requirements gathering and modelling use cases and scenarios.
- Knowledge of information security concepts and technologies such as IDS, email gateways and desktop security products, SIEM and SOAR platforms, web application firewalls and vulnerability management tools.
Click Apply now to be considered for the Application Security Architect role.
Application Security Architect – London/Remote employer: Atrium
Contact Detail:
Atrium Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Application Security Architect – London/Remote
✨Tip Number 1
Familiarise yourself with the specific security frameworks mentioned in the job description, such as GDPR, HIPAA, and PCI. Understanding these regulations will not only help you in interviews but also demonstrate your commitment to compliance and security best practices.
✨Tip Number 2
Network with professionals in the application security field, especially those who have experience in large, regulated organisations. Engaging with industry peers can provide insights into the role and may even lead to referrals or recommendations.
✨Tip Number 3
Stay updated on the latest trends and technologies in application security. Follow relevant blogs, attend webinars, and participate in forums to enhance your knowledge and show your passion for the field during discussions with potential employers.
✨Tip Number 4
Prepare to discuss your experience with secure development practices and how you've implemented security within development pipelines. Be ready to share specific examples that highlight your problem-solving skills and ability to work collaboratively with engineering teams.
We think you need these skills to ace Application Security Architect – London/Remote
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your extensive experience in application security architecture and your familiarity with large, regulated organisations. Emphasise your technical certifications and relevant skills that align with the job description.
Craft a Compelling Cover Letter: In your cover letter, express your passion for application security and how your background makes you a perfect fit for the role. Mention specific experiences that demonstrate your ability to communicate technical risks to business leaders and your understanding of healthcare delivery models.
Showcase Relevant Projects: Include examples of past projects where you implemented security within development pipelines or conducted vulnerability testing. Highlight your problem-solving skills and how you managed to meet customer needs effectively.
Highlight Communication Skills: Since excellent written and verbal communication skills are essential for this role, provide examples of how you've successfully communicated complex security concepts to both technical and non-technical stakeholders in previous positions.
How to prepare for a job interview at Atrium
✨Showcase Your Technical Expertise
Be prepared to discuss your extensive experience in application security architecture. Highlight specific projects where you've implemented security controls and how you navigated complex incidents. This will demonstrate your capability to manage a portfolio of applications effectively.
✨Communicate Clearly with Stakeholders
Since the role requires interaction with both technical and non-technical stakeholders, practice explaining technical security risks in simple terms. Use examples from your past experiences to illustrate how you've successfully communicated these concepts to senior management.
✨Demonstrate Business Acumen
Understand the healthcare delivery model and be ready to discuss how your security solutions align with business objectives. Show that you can translate business needs into information security requirements, which is crucial for this role.
✨Stay Updated on Industry Trends
Research current trends and regulatory standards in application security, especially those relevant to healthcare. Being knowledgeable about GDPR, HIPAA, and PCI frameworks will not only impress your interviewers but also show your commitment to staying informed in a rapidly evolving field.