- Company Name
- Sony Pictures Entertainment
- Job Title
- Executive Director, Application Security Architect
- Job Description
-
**Job Title:** Executive Director, Application Security Architect
**Role Summary:** Lead strategic application security architecture and engineering for enterprise applications, data, and cloud environments. Drive secure-by-design practices, evaluate emerging threats, and ensure compliance with global standards. Requires hands-on technical expertise combined with leadership to align security with business goals.
**Expectations:** Senior-level leadership in security architecture with proven experience in application security, DevSecOps, cloud, and data security. Demonstrated success in defining security strategies, fostering cross-functional collaboration, and mitigating cyber risks.
**Key Responsibilities**
- Define and execute a holistic application security strategy aligned with organizational objectives.
- Architect, implement, and optimize security solutions for applications, data, and cloud ecosystems.
- Conduct risk assessments, threat modeling, and vulnerability mitigation for new and existing systems.
- Evaluate and integrate advanced security tools and technologies (e.g., SAST/DAST, IAM, DevSecOps).
- Promote secure coding practices and governance across development lifecycles (S-SDLC).
- Collaborate with IT, DevOps, and business stakeholders to embed security in deployment pipelines.
- Ensure compliance with standards (NIST, ISO 27001, OWASP, GDPR) and regulatory frameworks.
**Required Skills**
- Expertise in application security (Full Stack WebApp/API, API gateways, SAST/DAST, WAFs).
- Deep knowledge of cloud security (AWS/Azure, IaaS/PaaS/SaaS, encryption, PAM, compliance).
- Mastery of DevSecOps, CI/CD pipeline hardening, container security, and IaC (Infrastructure as Code).
- Strong grasp of network security (firewalls, IDS/IPS, NAC, DDoS mitigation).
- Proficiency in threat modeling, AI security, product security, and GDPR/privacy frameworks.
- Experience with secure coding standards (OWASP Top 10, SANS Top 25) and secure design patterns.
**Required Education & Certifications**
- Bachelor’s degree in cybersecurity, computer science, or related field.
- Advanced certifications (e.g., CISSP, CISA, CCSK, CISM, AWS/Azure security specialties).
- Familiarity with industry frameworks (NIST, ISO 27001, PCI DSS, SAFECode).
Culver city, United states
On site
08-10-2025