ADP

Senior Application Security Architect

ADP Alpharetta, Georgia, United States

Human Resources Services · 10,001+ employees

6 h ago
security Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Application Security Architect will partner with product and engineering teams to design secure application architectures and guide the implementation of secure-by-design principles. They will also conduct security architecture reviews, perform threat modeling, and provide expertise on AI/ML and cloud security across the SDLC.

What they look for

Application Security Security Architecture Cloud Security GenAI Security Threat Modeling DevSecOps API Security Microservices Identity and Access Management OAuth2 Infrastructure-as-Code Data Protection Risk Assessment Secure Coding Cloud Platforms

Requirements

Candidates must have 8+ years of experience in application security or related technical security roles, with deep expertise in cloud platforms and security frameworks. A bachelor's degree in computer science, information security, or engineering is required, along with strong communication and stakeholder engagement skills.

Full description

ADP is Hiring a Senior Application Security Architect:

 

Unlock Your Career Potential: Global Security Organization at ADP.

Do you have a passion for going on the offensive to safeguard critical information? As ADP's Global Security Organization (GSO), we know that our clients rely on us for human capital management solutions, but beyond that, they entrust us with one of their most valuable assets -- their employee data.

 

We are honored by this trust and are laser focused on securing data at every step in the information lifecycle, ensuring integrity, confidentiality and compliance with industry and government regulations at all times.

 

From the cloud to the data center and across every emerging device, you'll join a team of experts in the GSO who are always staying one step ahead in this ever-changing world of data by continually evolving our strategies and technologies to protect ADP and our clients.

  

Like what you see?  Apply now!

Learn more about ADP at tech.adp.com/careers

 

 

Position Summary:

 

We are seeking a highly skilled and experienced Senior Application Security Architect to join our team. In this role, you will be part of the Product Security organization within ADP’s Global Security Organization (GSO), which plays a strategic role in enabling secure development and supporting the delivery of trusted products, solutions, and services across the entire ADP ecosystem.

 

As a Senior Application Security Architect, you will partner closely with product, engineering, and cloud architecture teams to design and guide the implementation of secure application architectures. You will leverage your deep expertise in application security architecture, Cloud security, and AI/GenAI security, to influence design decisions, reduce risk, and champion secure-by-design principles across the organization.

This role is instrumental in helping teams build secure applications, integrate third-party and SaaS solutions responsibly, and elevate ADP’s overall security posture through thought leadership, architectural oversight, and proactive engagement throughout the SDLC.

        Key Responsibilities:

  • Partner with global product and engineering teams to design, review, and evolve secure application architectures across multi-country environments.
  • Conduct in-depth security architecture reviews and provide clear, actionable security requirements, design guidance, and validation throughout the entire solution lifecycle.
  • Advise on GenAI, LLM, and AI/ML application security, including data protection, model security, prompt injection mitigation, dependency controls, secure model integration, and risk evaluation of AI-driven components.
  • Perform security assessments of Cloud Services (AWS, Azure, GCP, OCI) to confirm required security requirements to enable Cloud services at ADP.
  • Influence technical leaders—solution architects, security champions, engineering managers, and developers—to adopt secure-by-design principles and continuously improve security maturity.
  • Support Threat Modeling activities, leveraging tools such as IriusRisk to help teams create architecture diagrams, identify security risks, define countermeasures, and validate threat coverage.
  • Develop and maintain secure architecture patterns, reference architectures, and application security standards, ensuring alignment with industry frameworks (e.g., NIST, OWASP, CIS).
  • Embed security across the SDLC, educating product teams on integrating secure coding practices, secure API design, CI/CD security controls, and automated security testing.
  • Support secure integration of third-party platforms, SaaS solutions, and cloud-native services, ensuring vendor risk and architecture risks are understood and mitigated.
  • Partner with Cloud Architecture teams to ensure consistent application of cloud security controls across AWS, Azure, and hybrid environments.
  • Communicate complex security concepts to both technical and non-technical stakeholders, enabling informed decision-making at all levels.

 

To Succeed in This Role:

  • You'll have a bachelor’s degree in computer science, Information Security, Engineering, or a related field (or equivalent experience).

 

          Qualifications:

  • 8+ years of experience in Application Security, Security Architecture, or related technical security roles.
  • Deep expertise in Application Security practices, including secure coding, API security, microservices, cloud application security, DevSecOps, and security scanning tools.
  • Strong understanding of GenAI / LLM / Agentic AI security, including data governance, retrieval-augmented generation (RAG), model threats, prompt injection risks, and secure integration patterns.
  • Strong knowledge of cloud platform (such as AWS, Azure, OCI, and/or GCP) security capabilities and controls.
  • Strong knowledge of security frameworks and standards (e.g., OWASP ASVS, SAMM, NIST 800-53, NIST CSF, ISO 27001, CIS Controls).
  • Hands-on experience with Threat Modeling methodologies, tools (e.g., IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool), and risk assessment techniques.
  • Knowledge of identity and access management, OAuth2/OIDC, JWT security, secrets management, key management, and zero-trust design principles.
  • Experience with CI/CD pipeline security and infrastructure-as-code security.
  • Strong understanding of data security, encryption, privacy-by-design, and secure logging and monitoring practices.
  • Excellent communication, collaboration, and stakeholder engagement skills, with the ability to influence and drive security adoption.
  • Relevant security certifications are a plus: CISSP, CISM, CCSP, CSSLP, CEH, SANS/GIAC certifications, or cloud security certifications such as Google Professional Cloud Security Engineer.

 

What are you waiting for?  Apply today!

Find out why people come to ADP and why they stay: https://youtu.be/ODb8lxBrxrY

(ADA version: https://youtu.be/IQjUCA8SOoA )

 

Qualifications

#LI-SD4

#LI-Hybrid

Similar roles