Johnson Controls

Application Security Architect

Johnson Controls Budapest, Central Hungary, Hungary

Industrial Machinery Manufacturing · 10,001+ employees

19 h ago
security Mid (2-5 yrs) Full-time Hungary
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Application Security Architect will partner with engineering and product teams to embed security and privacy throughout the product lifecycle. They will lead security activities such as architecture reviews, threat modeling, and vulnerability management to ensure resilient product delivery.

What they look for

Application Security Cybersecurity Risk Assessment Threat Modeling Security Architecture Secure SDLC Vulnerability Management Compliance NIST 800-53 ISO 27001 SOC 2 Stakeholder Management Cloud Security IoT Security Security-by-design

Requirements

Candidates must have at least 3 years of experience in cybersecurity, governance, risk, or compliance, along with knowledge of frameworks like NIST 800-53 and ISO 27001. Strong stakeholder management skills and the ability to translate security requirements into technical guidance are essential.

Full description

What you will do

At Johnson Controls, you'll help secure the technologies behind intelligent buildings, connected products, and smart cities. As an Application Security Architect, you'll partner with engineering, product, and business teams to embed security and privacy throughout the product lifecycle, shape security strategy, lead risk assessments, and drive continuous improvements that strengthen cybersecurity resilience and customer trust.

Working as a trusted security advisor, you'll guide teams on secure software development, threat modeling, security architecture, and security-by-design practices across cloud, mobile, embedded, and connected products. You'll lead key security activities including architecture reviews, security testing, vulnerability management, and compliance support while translating security requirements into practical solutions that help teams deliver secure, resilient products.

How you will do it

  • Act as a trusted security advisor throughout the software development lifecycle.
  • Guide development teams on secure coding, threat modeling, security architecture, and security-by-design principles.
  • Lead secure SDLC activities, including security requirements definition, architecture reviews, code reviews, security testing, and remediation planning.
  • Translate regulatory, customer, and cybersecurity requirements into practical security controls and development practices.
  • Collaborate with security champions, architects, engineers, and product leaders to balance security, usability, and business objectives.
  • Partner with teams across cloud, mobile, embedded, and connected product environments to address evolving security challenges.
  • Stay current with emerging threats, vulnerabilities, and industry best practices, sharing knowledge and recommendations across the organization.

What we look for

Required

  • Minimum 3 years in cybersecurity, governance, risk, compliance, product security, or a related security function.
  • Experience working with cybersecurity and compliance frameworks NIST 800-53 and also ISO 27001 or SOC 2.
  • Experience evaluating cybersecurity risks and implementing or recommending appropriate security controls.
  • Ability to translate security requirements into actionable technical guidance.
  • Strong stakeholder management skills, with the ability to build trusted relationships and establish credibility with customers, engineering teams, business leaders, and other key stakeholders.

Preferred

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related technical discipline.
  • Professional cybersecurity certifications such as CISSP, GSEC, Security+, or equivalent.
  • Knowledge of compliance frameworks such as ISA/IEC 62443, GDPR, EU CRA, or similar.
  • Experience utilizing AI technologies and ensuring the secure design, implementation, and operation of AI capabilities within products.
  • Familiarity with Operational Technology (OT), industrial controls, building management systems, or IoT ecosystems.
  • Overview of SD Elements, FiniteState, ArmorCode, jFrog and Jira.

About Us

Johnson Controls, a global leader in thermal management, mission-critical building systems, energy efficiency, and decarbonization, helps customers use energy more productively, reduce carbon emissions, and operate with the precision and resilience required in rapidly expanding industries such as data centers, healthcare, pharmaceuticals, advanced manufacturing, and higher education.

For more than 140 years, Johnson Controls has delivered performance where it really matters. Backed by advanced technology, lifecycle services and an industry-leading field organization, we elevate customer performance, turn goals into real-world results and help move society forward.

We are committed to diversity and inclusion and believe that different perspectives make us stronger. By encouraging open dialogue and valuing individuality, we strive to be one of the most desirable places to work.

#LI-BB1

#LI-Hybrid

Similar roles