Hiring.Camp

Lead Application Security Architect

JLL employee

·

Yesterday

Location
ESP-CORP Barcelona-JLL Barcelona, Spain
Workplace
Remote
Type
Full-time
Department
Engineering
Seniority
Lead
Experience
7+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

JLL empowers you to shape a brighter way.  

Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong.  Whether you’ve got deep experience in commercial real estate, skilled trades or technology, or you’re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward.   

JLL es una empresa comprometida con la igualdad de oportunidades entre hombres y mujeres / JLL as a company is committed to equal opportunities for men and women.

Senior Application Security Architect 

Overview 

At JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. The Application Security Architect is a senior individual contributor responsible for bridging application security engineering and enterprise security architecture at JLL.

This role designs and owns security architectures for application ecosystems, integrates security into the software development lifecycle (SDLC), and serves as a technical authority on secure design patterns, threat modeling, and DevSecOps practices. Operating at the Senior level, this position independently leads application security initiatives, mentors junior engineers and developers, and partners across engineering, architecture, and business teams to reduce risk and enable secure digital transformation. 

If you’re a strategic thinker with application security expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you. 

Essential Duties and Responsibilities:

Security Architecture & Design 

  • Design and maintain security architecture standards, policies, and patterns for enterprise applications, platforms, and cloud-native environments, ensuring alignment with JLL's technology strategy and risk posture. 
  • Develop and enforce secure design patterns, reference architectures, and architecture decision records (ADRs) for application security across development teams. 
  • Lead security architecture reviews for new and existing applications, evaluating designs against frameworks such as OWASP, NIST, and SANS. 
  • Integrate zero-trust principles and defense-in-depth strategies into application architecture to reduce attack surface and support enterprise risk management goals. 

DevSecOps & Secure Development Lifecycle 

  • Define and maintain a standardized set of enterprise application security requirements and produce metrics to report performance against those requirements. 
  • Lead threat modeling sessions for new application features and system integrations, producing actionable remediation guidance for development teams. 
  • Champion secure coding standards and developer security enablement programs in collaboration with platform and application engineering teams. 

Risk, Compliance & Stakeholder Engagement 

  • Analyze complex security requirements across multiple technology domains and design comprehensive security solutions that address enterprise risk and regulatory compliance obligations. 
  • Communicate security architecture designs, risk assessments, and remediation recommendations to technical and non-technical stakeholders across business units. 
  • Coordinate security design reviews and approval processes, facilitating alignment between security, engineering, and enterprise architecture teams. 
  • Contribute to JLL's application security strategy roadmap, identifying emerging threats and recommending enhancements to the secure development and architecture programs. 

Mentorship & Team Leadership 

  • Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards. 
  • Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams. 
  • Support secure development training and awareness programs to build security competency across engineering organizations. 

Required Knowledge, Skills, and Abilities:

Technical Knowledge 

  • Comprehensive knowledge of application security methodologies, including OWASP Top 10, SANS/CWE, secure development frameworks, and security architecture design patterns. 
  • Demonstrated experience designing security architectures for cloud-native environments (AWS, Azure, GCP), microservices, APIs, and containerized workloads. 
  • Strong proficiency in DevSecOps practices and tooling: SAST, DAST, SCA, container image scanning, secrets management, and CI/CD security integration. 
  • Experience with enterprise security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and zero-trust architecture principles. 
  • Working knowledge of identity and access management (IAM), OAuth 2.0/OIDC, and application-layer authentication and authorization controls. 
  • Understanding of cryptography, data protection, encryption, and Public Key Infrastructure 
  • Familiarity with threat modeling methodologies (STRIDE, PASTA, or equivalent) and their application to complex distributed application architectures. 
  • Knowledge of OWASP: GenAi, LLM Top 10, Security Exchange, Ai Exchange a plus 

Skills & Abilities 

  • Ability to analyze complex application architectures and translate security requirements into practical, implementable design solutions. 
  • Strong communication skills with the ability to convey technical security risks and architectural recommendations to diverse stakeholders including development teams, business leaders, and enterprise architects. 
  • Demonstrated ability to lead security assessments, architecture reviews, and cross-functional security initiatives independently. 
  • Proven capability to mentor and guide junior security professionals and developers on secure design practices and security engineering standards. 
  • Analytical and problem-solving skills applied to sophisticated security integration challenges with enterprise-wide implications. 
  • Ability to balance security rigor with development velocity, enabling secure delivery of digital applications and services. 

Education & Experience 

  • Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field; equivalent experience considered. 
  • 7+ years of experience in information security with a focus on application security engineering, secure software development, or security architecture. 
  • Relevant certifications preferred: CSSLP, CISSP, AWS/Azure Security Specialty, OSCP, or equivalent application security or architecture credentials. 

Location:

Remote –Barcelona, ESP

If this job description resonates with you, we encourage you to apply even if you don’t meet all of the requirements.  We’re interested in getting to know you and what you bring to the table!

At JLL, we harness the power of artificial intelligence (AI) to efficiently accelerate meaningful connections between candidates and opportunities. Using AI capabilities, we analyze your application for relevant skills, experiences, and qualifications to generate valuable insights about how your unique profile aligns with the specific requirements of the role you're pursuing.

JLL Privacy Notice

Jones Lang LaSalle (JLL), together with its subsidiaries and affiliates, is a leading global provider of real estate and investment management services. We take our responsibility to protect the personal information provided to us seriously. Generally the personal information we collect from you are for the purposes of processing in connection with JLL’s recruitment process. We endeavour to keep your personal information secure with appropriate level of security and keep for as long as we need it for legitimate business or legal reasons. We will then delete it safely and securely.

For more information about how JLL processes your personal data, please view our Candidate Privacy Statement.

For additional details please see our career site pages for each country.

Jones Lang LaSalle (“JLL”) is an Equal Opportunity Employer and is committed to working with and providing reasonable accommodations to individuals with disabilities.  If you need a reasonable accommodation because of a disability for any part of the employment process – including the online application and/or overall selection process – you may email us at [email protected]. This email is only to request an accommodation. Please direct any other general recruiting inquiries to our Contact Us page > I want to work for JLL.

Skills

AWSAzureGCPCI/CDOAuthMicroservicesRisk ManagementComplianceISO 27001CISSP

Similar Jobs

30

Application Security Lead

Slihrms · AtkinsRéalis - Corporate Office Bangalore, India

1 week ago

Lead Application Security

Chevron Corporation is one of · Houston 1500 Louisiana Street, United States of America

2 months ago

Application Security Lead

Hightouch · Remote (North America) · Remote

4 months ago

Lead, Application Security

Pru · Wash, 213 Washington St., Newark, NJ, United States of America

5 months ago

Application Security Lead

CENSUS SA · worldwide · Remote

1+ year ago

Tech Lead | Application Security

Insside · Buenos Aires

1 week ago

SAP Application Security Lead

Accenture Federal Services · Washington, DC +1 · Remote

3 weeks ago

Lead Application Security Engineer

Advatix, Inc. · (Multiple States) · Remote

3 weeks ago

Lead Application Security Engineer, IT Security

Raymond James · FL - Saint Petersburg - 880 Carillon Pkwy Tower 2, United States of America · Hybrid

4 weeks ago

Lead Application Security Eng

Morgan Stanley · Alpharetta, GA,US, US

1 month ago

Lead Application Security Eng

Ms · Alpharetta GA 3, United States of America

1 month ago

Lead Application Security Engineer

Cais · London, England +1

1 month ago

Senior Lead Application Security Engineer

IFS · Vancouver, British Columbia, Canada · Hybrid

2 months ago

Lead Application Security Engineer

Encora · Kuala Lumpur

2 months ago

DevSecOps & Application Security Lead

JustMarkets · Remote, Europe · Remote

2 months ago

Team Lead - Application Security

METRO/MAKRO · Maharashtra, PUNE, India

1+ year ago

Lead Security Architect (Application Security)

Wells Fargo · 142019-NC-300 South Brevard, Charlotte, United States of America +3 · Hybrid

1 week ago

Application Security Engineering Lead

Athene · West Des Moines 7700 Mills Civic Parkway, United States of America

1 month ago

Lead Architect – Application Security

Ffive · San Jose, United States of America +1 · Hybrid

1 month ago

Application Security Engineer, Lead

Booz Allen Hamilton · USA, CO, Colorado Springs (1050 Stewart Ave), United States of America

1 month ago

Application Security Team Lead

Gongio · Tel Aviv +1

1 month ago

Application & Cloud Security Lead

Spgi · IN - HYDERABAD SKYVIEW, India +2

1 month ago

Application & Cloud Security Lead

Spgi · IN - HYDERABAD SKYVIEW, India +2

1 month ago

Application Security & IAM Lead

Slihrms · IN.TN.Chennai.IndiQube Alpine, Jawaharlal Nehru Road, Block No. 4, SIDCO Industrial Estate.Guindy, India

2 months ago

Senior/Lead/Principal Application Security Researcher

Salesforce · Israel - Tel Aviv · Onsite

6 months ago

Senior ICAM architect and Application Security Integration Lead

Amyx · , US

1+ year ago

Product, Application and Offensive Security Lead

Wpp · United Kingdon

1 month ago

Lead Product Marketing Manager – Application Security

Thales · BELFAST ARNOTT HOUSE, United Kingdom · Remote

Yesterday

Lead Strategic Services Consultant (Application Security)

"Black Duck Software, Inc." · Burlington, MA (Remote) · Remote

1 week ago

Security Product and Application Dev Lead

Criteo · Paris, France · Hybrid

2 months ago