Company Description Accion Labs is an AI-first, platform-led innovation engineering company headquartered in Pittsburgh, focused on transforming businesses through next-generation technologies. With a global presence across 23 locations and a team of over 5,000 professionals, including more than 1,000 trained in AI and GenAI, Accion Labs helps organizations modernize and scale through engineering excellence and proprietary IP. The company delivers digital engineering, cloud and platform engineering, data and AI solutions, enterprise system automation, and agentic AI services to clients across multiple industries. Backed by a strong operational framework and mature governance model, Accion Labs emphasizes partnership, joint ownership, and measurable outcomes. Recognized by leading analyst firms and business publications for innovation and growth, Accion Labs offers a dynamic environment for professionals who want to work on advanced AI-powered products and large-scale transformation initiatives.
Role Description The Senior Application Security Architect will lead the design, implementation, and ongoing enhancement of secure application architectures across Accion Labs’ client engagements. This remote, contract role involves defining security standards, patterns, and controls for web, mobile, cloud, and API-based applications, as well as reviewing solution designs and code for security risks. The architect will conduct threat modeling, risk assessments, and security design reviews, collaborating closely with engineering, DevOps, product, and compliance teams to embed security into the development lifecycle. Day-to-day responsibilities include evaluating security tools and frameworks, guiding secure coding practices, supporting vulnerability management and remediation, and producing clear technical documentation and security guidelines. The individual will also mentor development teams on security best practices and contribute to continuous improvement of security architecture and governance across projects.
Qualifications
- Strong expertise in application security architecture, including threat modeling, secure design patterns, and security controls for web, mobile, microservices, and API-based systems.
- Hands-on experience with secure SDLC practices, including code review, integration of security tools (SAST, DAST, SCA), and collaboration with development and DevOps teams.
- Proficiency in modern application and cloud technologies (e.g., microservices, containers, CI/CD pipelines, REST/GraphQL APIs, and major cloud platforms such as AWS, Azure, or GCP).
- Solid understanding of security standards and frameworks such as OWASP, NIST, ISO 27001, PCI DSS, and common authentication/authorization protocols (OAuth 2.0, OIDC, SAML).
- Experience with identity and access management, encryption and key management, secrets management, and secure configuration of application and platform components.
- Ability to analyze complex systems, identify security gaps, propose pragmatic solutions, and communicate clearly with both technical and non-technical stakeholders.
- Track record of working in distributed, remote teams; strong documentation