Sr Application Security Architect at SAS
Cary HQ, NC
—
Jul 22, 2026
Cary HQ, NC
Jul 24, 2026
What this job asks for AI summary
A senior security role embedded within a product-focused division, responsible for improving the security posture of multi-tier software solutions across legacy, hybrid, and public cloud environments. Day-to-day work spans threat modeling, secure design reviews, code assessments, and integrating security practices throughout the development pipeline. The role suits an experienced application security professional comfortable advising engineering teams, mentoring security champions, and working across architecture, development, and cloud operations.
Senior level · 8+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 3 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 5,400 people nationally plausibly meet what this posting asks for (information security analysts). range 1,100–8,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The role is posted as hybrid in Cary, NC or Glasgow, Scotland, or fully remote within EST or GMT time zones. Because the primary US location is Cary, NC (Raleigh-Cary CBSA), that metro is used; the US-based flag of true since the role is open to US-based candidates. The Glasgow, Scotland option makes this a genuinely international posting, but US benchmarks apply to the US-eligible portion.
SOC classification is a genuine judgment call: the role is titled 'Application Security Architect' and is primarily security analysis, threat modeling, and secure SDLC work (15-1212), but it also requires hands-on code review and software development depth, which overlaps with 15-1252. 15-1212 was chosen as the primary because security assessment, architecture, and compliance are the dominant day-to-day activities.
The degree requirement (Bachelor's in CS, EE, or related) is listed under Required Qualifications but is immediately followed by 'Equivalent combination of related education, training and experience may be considered in place of the above qualifications,' so the degree requirement is set to None.
Security certifications (SANS/GIAC, ISACA CEH, CCSP, CSSLP, CISM, CISSP) are listed as required but name no single specific tool or technology — they are professional credentials rather than concrete named technologies and are therefore not emitted as skills.
Programming languages (C/C++, Java, Python, JavaScript, PHP, Golang) are listed as a single interchangeable requirement in the Required section; C/C++ is used as the primary skill name with the others as alternatives.
Cloud platforms (Azure, AWS, GCP) and SAST/DAST tools appear under 'Additional competencies, knowledge and skills,' which functions as a preferred/nice-to-have section rather than a hard gate.
Agentic AI is mentioned in the required section as an example of modern R&D security context but names no specific tool or platform, so it is not emitted as a standalone skill.
No compensation figures are provided in the posting.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secure software development, software security best practices, Microsoft Cloud Security Benchmark.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.