Negotiable
Undetermined
Undetermined
Coventry, England, United Kingdom
Summary: The Application Security Architect role focuses on designing a Software Bill of Materials (SBOM) framework and implementing Zero Trust patterns for applications and workloads. The position involves leading architecture efforts, integrating security practices into development workflows, and establishing risk management processes. The architect will also produce threat models and support the adoption of modern security practices within the organization.
Key Responsibilities:
- Lead SBOM architecture, including inventory, component mapping, version governance and vulnerability correlation.
- Integrate SBOM with CI/CD, build tools, package repositories, code scanning and SOAR workflows.
- Establish supply chain risk processes, severity prioritisation and dependency management workflows.
- Produce threat models for application workloads and tie them into ZT data and segmentation controls.
- Define integration patterns with vulnerability databases, intelligence feeds and asset inventory.
- Support adoption of policy as code, IaC, automation and DevSecOps practices.
Key Skills:
- Strong application security background with SBOM, SCA, DevSecOps and CI/CD experience.
- Experience designing secure software supply chain controls.
- Knowledge of ZT workload segmentation and cloud workload security.
Salary (Rate): undetermined
City: Coventry
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Role Purpose To design SBOM framework and application/workload centric Zero Trust patterns including secure software supply chain visibility, DevSecOps integration, threat modelling and workload segmentation alignment.
Key Responsibilities
- Lead SBOM architecture, including inventory, component mapping, version governance and vulnerability correlation.
- Integrate SBOM with CI/CD, build tools, package repositories, code scanning and SOAR workflows.
- Establish supply chain risk processes, severity prioritisation and dependency management workflows.
- Produce threat models for application workloads and tie them into ZT data and segmentation controls.
- Define integration patterns with vulnerability databases, intelligence feeds and asset inventory.
- Support adoption of policy as code, IaC, automation and DevSecOps practices.
Skills & Experience
- Strong application security background with SBOM, SCA, DevSecOps and CI/CD experience.
- Experience designing secure software supply chain controls.
- Knowledge of ZT workload segmentation and cloud workload security.