landing_page-logo
Corebridge Financial Inc. logo

Application Security Architect

Corebridge Financial Inc.Durham, NC
Apply

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

Who We Are

At Corebridge Financial, we believe action is everything. That's why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.

We align to a set of Values that are the core pillars that define our culture and help bring our brand purpose to life:

  • We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners
  • We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders
  • We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future
  • We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work

Who You'll Work With

The Information Technology organization is the technological foundation of our business and works in collaboration with our partners from across the company. The team drives technology and digital transformation, partners with business leaders to design and execute new strategies through IT and operations services and ensures the necessary IT risk management and security measures are in place and aligned with enterprise architecture standards and principles.

About The Role

The Application Security Architect to lead the design, implementation, and oversight of secure application architectures across our organization. This role focuses on integrating security into software development processes, collaborating with developers and application security teams, and building scalable, secure application frameworks. The ideal candidate will bring deep expertise in application security, strong communication skills, and the ability to work independently or collaboratively to drive security initiatives and foster a security-first culture.

Responsibilities

  • Design, document, and maintain secure architecture patterns, diagrams, and reference architectures for Web, API, and Mobile applications.
  • Conduct security reviews of application designs, APIs, and development pipelines, identifying vulnerabilities and recommending secure design strategies.
  • Perform threat modeling and risk assessments to identify vulnerabilities and recommend appropriate mitigating controls.
  • Recommend and oversee the implementation of security controls in CI/CD pipelines, ensuring governance and standardization of tools such as SAST, DAST, and IAST.
  • Collaborate closely with application security teams, developers, application owners, cloud teams, and engineering teams to integrate security into the SDLC and organizational workflows.
  • Communicate risks effectively to developers, application owners, and senior executives, tailoring technical risks into actionable insights for both technical and non-technical audiences.
  • Guide the adoption and implementation of OWASP standards, including ASVS, OWASP Top 10, and API Security Top 10.
  • Demonstrate strong knowledge and understanding of microservices driven architecture, ensuring secure integration into overall system design.
  • Maintain familiarity with APIs, API gateways, service mesh, and API-related security tooling and practices to secure API designs and integrations.
  • Provide expertise in container security, advising on the use of immutable operating systems and secure deployment practices.
  • Partner with developers and engineering teams to promote secure coding practices and ensure security is a natural part of their workflows.
  • Stay informed of emerging application security threats and technologies, and proactively recommend improvements to enhance the security posture.
  • Foster a security-first culture by mentoring development teams, promoting secure coding practices, and embedding security in organizational workflows.

Skills and Qualifications

  • 7+ years of hands-on experience in application security, secure coding, and software development practices for Web, API, and Mobile applications.
  • Strong ability to create and review application designs, diagrams, and reference architectures.
  • Expertise in secure software development life cycle (SDLC) and DevSecOps processes.
  • Proficiency in SaaS, PaaS, and IaaS environments, including platforms like AWS, Azure, M365 and Saleforce.
  • Experience with various application security tools, such as SonarQube, Veracode, Codacy and familiarity with integrating security into CI/CD pipelines.
  • Knowledge of common CI/CD pipeline and development tools, such as Jenkins, GitHub, Artifactory, Terraform, Vault.
  • Knowledge of containerization and orchestration technologies like Docker, Kubernetes, EKS, ECS and OCP, including container security practices and the use of immutable containers.
  • Working knowledge of regulatory requirements and compliance standards such as NYDFS, CCPA, PCI-DSS, HIPAA, SOX, and GDPR.
  • Relevant certifications such as CISSP, CSSLP, OSCP or equivalent.
  • Ability to work independently or collaboratively in a team-oriented environment.
  • Bachelor's degree in a relevant field or proven record of experience in Information Technology and Cyber Security roles.

Technical Skills

  • Knowledge of OWASP ASVS, OWASP Top 10, API Security Top 10, and secure coding practices.
  • Proficiency in designing, implementing, and securing API gateways (e.g., Kong, Apigee, AWS API Gateway) and service mesh (e.g., Istio, Linkerd) for secure communication and service management.
  • Expertise in implementing security controls in CI/CD pipelines, ensuring alignment with security standards and best practices using tools such as Jenkins, GitHub, and Terraform.
  • Knowledge of securing containerized environments, including securing images, leveraging immutable OSes, and applying best practices in orchestration security.
  • Expertise in designing processes for patching vulnerabilities and implementing resilient deployment strategies (e.g., blue-green deployments).
  • Expertise in encryption (e.g., TLS, AES, RSA) and secure data management practices.

Common Security and Architecture Frameworks

  • OWASP ASVS (Application Security Verification Standard)
  • NIST Cybersecurity Framework (CSF)
  • ISO 27001 and 27002
  • CIS Controls
  • SABSA (Sherwood Applied Business Security Architecture)
  • TOGAF (The Open Group Architecture Framework)
  • AWS Well-Architected Framework

Preferred Certifications

  • Certified Secure Software Lifecycle Professional (CSSLP)
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer (GSSP)
  • AWS Certified Solutions Architect- Associate or Professional
  • AWS Certified Security- Specialty
  • Microsoft Certified: Azure Solutions Architect Expert
  • TOGAF (The Open Group Architecture Framework)
  • SABSA Foundation or Practitioner

Soft Skills

  • Strong analytical and problem-solving abilities.
  • Excellent interpersonal and collaboration skills.
  • Proven ability to communicate complex ideas to technical and non-technical audiences.
  • Strong organizational and time management skills.
  • Adaptability and a commitment to continuous learning of new technologies and methodologies.
  • Attention to detail and dedication to delivering high-quality results.
  • High level of integrity and ethical conduct.

Industry-Specific Experience:

  • Experience in financial services, insurance, or other regulated environments.
  • Proven ability to design and implement application security controls that align with industry regulations and standards.
  • Experience conducting application security assessments and audits in regulated industries.
  • Familiarity with industry-specific application threats and vulnerabilities to tailor security solutions.

Compensation

The anticipated salary range for this position is $140,000 to $165,000 at the commencement of employment. Not all candidates will be eligible for the upper end of the salary range. The actual compensation offered will ultimately be dependent on multiple factors, which may include the candidate's geographic location, skills, experience and other qualifications.

In addition, the position is eligible for a discretionary bonus in accordance with the terms of the applicable incentive plan.

Corebridge also offers a range of competitive benefits as part of the total compensation package, as detailed below.

Work Location

This position is based in Corebridge Financial's Jersey City, NC, Houston, TX, or Durham, NC office and is subject to our hybrid working policy, which gives colleagues the benefits of working both in an office and remotely.

#LI-SAFG #LI-CW1 #LI-Hybrid

Why Corebridge?

At Corebridge Financial, we prioritize the health, well-being, and work-life balance of our employees. Our comprehensive benefits and wellness program is designed to support employees both personally and professionally, ensuring that they have the resources and flexibility needed to thrive.

Benefit Offerings Include:

  • Health and Wellness: We offer a range of medical, dental and vision insurance plans, as well as mental health support and wellness initiatives to promote overall well-being.
  • Retirement Savings: We offer retirement benefits options, which vary by location. In the U.S., our competitive 401(k) Plan offers a generous dollar-for-dollar Company matching contribution of up to 6% of eligible pay and a Company contribution equal to 3% of eligible pay (subject to annual IRS limits and Plan terms). These Company contributions vest immediately.
  • Employee Assistance Program: Confidential counseling services and resources are available to all employees.
  • Matching charitable donations: Corebridge matches donations to tax-exempt organizations 1:1, up to $5,000.
  • Volunteer Time Off: Employees may use up to 16 volunteer hours annually to support activities that enhance and serve communities where employees live and work.
  • Paid Time Off: Eligible employees start off with at least 24 Paid Time Off (PTO) days so they can take time off for themselves and their families when they need it.

Eligibility for and participation in employer-sponsored benefit plans and Company programs will be subject to applicable law, governing Plan document(s) and Company policy.

We are an Equal Opportunity Employer

Corebridge Financial, is committed to being an equal opportunity employer and we comply with all applicable federal, state, and local fair employment laws. All applicants will be considered for employment based on job-related qualifications and without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, neurodivergence, age, veteran status, or any other protected characteristic. The Company is also committed to compliance with all fair employment practices regarding citizenship and immigration status. At Corebridge Financial, we believe that diversity and inclusion are critical to building a creative workplace that leads to innovation, growth, and profitability. Through a wide variety of programs and initiatives, we invest in each employee, seeking to ensure that our colleagues are respected as individuals and valued for their unique perspectives.

Corebridge Financial is committed to working with and providing reasonable accommodations to job applicants and employees, including any accommodations needed on the basis of physical or mental disabilities or sincerely held religious beliefs. If you believe you need a reasonable accommodation in order to search for a job opening or to complete any part of the application or hiring process, please send an email to TalentandInclusion@corebridgefinancial.com. Reasonable accommodations will be determined on a case-by-case basis, in accordance with applicable federal, state, and local law.

We will consider for employment qualified applicants with criminal histories, consistent with applicable law.

To learn more please visit: www.corebridgefinancial.com

Functional Area:

IT - Information Technology

Estimated Travel Percentage (%): Up to 25%

Relocation Provided: No

American General Life Insurance Company