At a Glance
- Tasks: Lead and innovate Arrive's global application security strategy and standards.
- Company: Join a mission-driven company transforming urban mobility for brighter futures.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on innovation and career advancement.
- Why this job: Be a key player in shaping the future of application security with cutting-edge technology.
- Qualifications: 10+ years in tech, with 7+ years in application security and a strong understanding of modern practices.
The predicted salary is between 80000 - 100000 £ per year.
We’ve signed up for an ambitious journey. Join us! As Arrive, we guide customers and communities towards brighter futures and more livable cities. Our people and our values help us make it happen. We Arrive Curious, Focused and Together.
Role Summary
The Application Security Architect is a senior, influential role responsible for orchestrating and leading Arrive’s global application security strategy. As a core member of the Global Security Architecture & Engineering team, you will act as the central driver for how we securely design, build, and deploy software across the company.
Your primary focus is to unite our efforts by creating, standardizing, and scaling our Secure Software Development Lifecycle (SSDLC) globally. This involves building upon the expertise and best practices that already exist within our teams and forging a powerful partnership with the Platform Security team in Engineering. You will lead by unifying—setting global standards that empower our developers and security engineers and ensuring the security of our next generation of products and platforms.
Your Mission
To elevate and unify our application security program at Arrive. Your mission is to be a force-multiplier for our engineering teams, fostering a secure development culture that is built on a foundation of clear global standards, strong partnerships, and modern security practices. You will ensure that security is a shared goal and a collective achievement.
Key Responsibilities
- Application Security Strategy & Standards: Champion and orchestrate the definition of Arrive’s global Secure Software Development Lifecycle (SSDLC), from threat modeling to secure release, in close partnership with key stakeholders across Engineering and IT. Develop and maintain a comprehensive set of global security standards, baselines, and guidelines for secure coding, vulnerability management, and secure architecture. Create and champion the strategy for our application security tooling, including SAST, DAST, IAST, and Software Composition Analysis (SCA). Define and manage the application security standards for Mergers & Acquisitions, establishing clear requirements and guiding the architectural integration of acquired technologies.
- Technical Partnership & Enablement: Act as a lead security consultant and strategic partner for product and engineering teams, providing expert guidance on secure design patterns and vulnerability remediation. Forge a dynamic partnership with the Platform Security team: co-design the security tooling roadmap, consume their platforms where they meet global standards, and introduce new architectural patterns where needed. Lead security architecture reviews and threat modeling sessions for new applications and high-risk features. Act as a senior mentor and advocate for security engineers and champions across the organization, helping to grow our security talent.
- Emerging Threats & Innovation: Stay at the forefront of emerging application security threats, with a particular focus on the risks associated with AI/ML systems. Collaborate with Data & AI teams to develop security principles and architectural patterns for securely integrating AI into our products. Drive innovation in our security practices, continuously seeking opportunities to automate and improve the effectiveness of our AppSec program. Lead the strategy for leveraging AI within the AppSec program, both to mature the SSDLC and to establish the secure-by-design principles required for our AI-first engineering landscape.
What You Bring
- Deep AppSec Expertise: Extensive, hands-on experience in application security, with mastery of the SSDLC, secure coding principles, and common vulnerability classes (OWASP Top 10, etc.).
- A Builder of Standards: Proven experience creating, documenting, and rolling out security standards, patterns, and best practices in a complex engineering environment.
- A Unifier and Partner: Exceptional ability to foster collaboration and influence engineering teams without direct authority. You build bridges, operate 'together', and break down silos.
- Strategic Thinker: Ability to see the big picture, define a long-term strategy for application security, and translate it into an actionable plan.
- Modern Technologist: Strong understanding of modern software development practices, including cloud-native architectures, CI/CD pipelines, containerization, and Infrastructure as Code.
Qualifications
- 10+ years of experience in technology, with at least 7 years in a dedicated application security or product security role.
- Demonstrated experience designing and implementing a Secure SDLC in a cloud-native environment (GCP, AWS).
- Hands-on experience with the architecture and strategy of AppSec tools (e.g., Snyk, Checkmarx, Veracode).
- Experience with securing microservices architectures, APIs, and modern web/mobile applications.
- Experience with securing AI/ML systems.
- A Bachelor’s degree in a relevant field or equivalent professional experience.
Why Join Arrive
Be the global leader and define the future of application security at a mission-driven, transformative company. Operate as a senior expert within a strategic architecture team, with a broad mandate to influence security across all of Arrive’s products. Work at the cutting edge of securing technology, including multi-cloud and AI-driven mobility solutions.
Lead Application Security Architect in London employer: Parkopedia
At Arrive, we are not just shaping the future of urban mobility; we are cultivating a vibrant work culture that thrives on curiosity, collaboration, and innovation. As a Lead Application Security Architect, you will have the opportunity to influence global security strategies while working alongside passionate professionals in a supportive environment that prioritises employee growth and development. Join us in our mission to create safer, smarter cities and enjoy the unique advantage of being part of a forward-thinking team dedicated to making a meaningful impact.
StudySmarter Expert Advice🤫
We think this is how you could land Lead Application Security Architect in London
✨Tip Number 1
Network like a pro! Attend industry meetups, conferences, or webinars related to application security. It's a great way to connect with potential employers and learn about job openings that might not be advertised.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, especially those related to secure software development. This can really set you apart when you're chatting with hiring managers.
✨Tip Number 3
Don’t just apply—engage! When you find a role that excites you, reach out to current employees on LinkedIn. Ask them about their experiences and get insider tips on the application process.
✨Tip Number 4
Keep it real! During interviews, be honest about your experiences and how you can contribute to Arrive’s mission. Show your passion for application security and how you can help elevate their program.
We think you need these skills to ace Lead Application Security Architect in London
Some tips for your application 🫡
Show Your Passion:Let us see your enthusiasm for application security! Share your journey, what drives you, and how you align with our mission to transform urban mobility. A personal touch can make your application stand out.
Tailor Your Application:Make sure to customise your CV and cover letter to reflect the specific skills and experiences that match the Lead Application Security Architect role. Highlight your expertise in SSDLC and secure coding principles to show us you're the right fit.
Be Clear and Concise:We appreciate clarity! Keep your application straightforward and to the point. Use bullet points where necessary to make it easy for us to see your qualifications and achievements at a glance.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for this exciting opportunity. We can’t wait to hear from you!
How to prepare for a job interview at Parkopedia
✨Know Your Stuff
Make sure you brush up on your application security knowledge, especially around the Secure Software Development Lifecycle (SSDLC) and common vulnerabilities like the OWASP Top 10. Be ready to discuss your hands-on experience with AppSec tools and how you've implemented security standards in previous roles.
✨Show Your Strategic Side
Prepare to talk about your long-term vision for application security. Think about how you can align security practices with engineering goals and how you’ve successfully influenced teams in the past. They’ll want to see that you can think big and translate that into actionable plans.
✨Collaboration is Key
Since this role involves uniting various teams, be ready to share examples of how you've fostered collaboration in previous positions. Highlight any partnerships you've built with engineering or product teams and how you’ve broken down silos to achieve shared goals.
✨Stay Ahead of the Game
Demonstrate your awareness of emerging threats, particularly in AI/ML systems. Be prepared to discuss how you would approach integrating security principles into these technologies. Showing that you’re proactive about innovation in security practices will set you apart.