Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Security Application Solution Architect (Remote) image - Rise Careers
Job details

Security Application Solution Architect (Remote) - job 1 of 5

Company Description

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas – immunology, oncology, neuroscience, and eye care – and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on TwitterFacebookInstagramYouTube and LinkedIn

Job Description

The Information Security Application Solution Architect is a member of the Information Security team and works closely with other members of the team to develop and implement a comprehensive information security program.  This includes defining security policies, processes, and standards.  We are seeking a highly skilled architect to collaborate with application development teams, ensuring secure design, coding, configuration, and deployment of technology solutions. The architect will not only focus on common security mechanisms like encryption and authentication but will also dive into application-level risks, session management, securing configuration files, secrets management, and risk identification in system configurations. This role requires a deep understanding of secure application development practices, including the security of API interactions and cloud application environments. 

This position can be virtually from anywhere in the U.S.

Major Duties and Responsibilities: 

  • Work with in-business IT customers, including application architects and engineers to evaluate application software and infrastructure designs, for the purpose of defining/designing application controls aligned with enterprise standards. 
  • Generate detailed application specific security controls design and documentation for each business application under review 
  • Develop re-usable implementation guidance and design patterns based on previous engagements to scale the service 
  • Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure and applications. 
  • Establish collaborative working relations with business application architecture staff to ensure that solutions align with security architecture and business strategy. 
  • Support security aspects of business & IT initiatives by assisting in architecture, design, implementation, deployment, and operational transition of innovative & secure technology solutions. 
  • Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure. 
  • Research, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies. 
  • Establish collaborative working relations with the Information Technology functions to ensure that solutions align with security architecture and business strategy. 
  • Play an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned.  Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed. 
  • Research and assess new information security threats and recommend remedial actions. 
  • Foster an information security culture through education, skill development, and implementation of effective information security processes and practices. 
  • Understand and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety, GxP compliance, data security, and the software development lifecycle 
  • Matures and leverages relationships with affiliates, subsidiaries, vendors, and industry peers in accordance with Abbvie Values, Vendor Management Office, and Purchasing to further the mission, vision and goals of the organization. 

Specifically, we’re looking for experience: 

  • Design the security architecture for applications, ensuring all components meet best practices and regulatory compliance. 
  • Work closely with software development, DevOps, and operations teams to integrate security into the software development lifecycle (SDLC). 
  • Lead efforts in identifying potential threats through application threat modeling and propose design changes to mitigate risks. 
  • Understanding the following concepts is a plus; identity management, federated identity services, incident management, access control, , application vulnerability testing, public key infrastructure, Windows, and Unix/Linux, public cloud infrastructure and services 
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project. 
  • Significant SOX and HIPAA experience in dealing with IT general controls (ITGC), demonstrated through hands-on audit, remediation, and/or computer system validation.   
  • Excellent understanding of current Information Security & Architecture trends and their impact on business strategies including: key Information Security vendors and solutions, audit organizations and influential market research firms. 
  • Excellent communications and influencing skills with strong ability to balance differing stakeholder interests through sound analysis and persuasion. 
  • Strong people skills, collaborative ability to work with IT stakeholders inside and outside of the organization, able to mentor team members with diverse backgrounds. 
  • Ability to formulate network security architecture vision and translate vision into execution. 
  • Thorough understanding of Information Security frameworks and good practices (e.g. ISO, NIST), and proven ability to strike a balance between an academic and pragmatic approach. 

Qualifications

  • Bachelor’s degree and 9 years of experience OR Master’s Degree and 8 years of experience OR PhD and 4 years of experience in information security and/or related functions (IT Audit, Risk Management or Security Architecture).
  • During recent history, candidate must have demonstrated exceptional ability to assess and communicate information security concepts and practices, with both business and IT stakeholders. 
  • Requires in-depth knowledge of the systems development life cycle, client area’s functions and systems, and systems applications programs development technological alternatives. 
  •  Proven implementation of creative technology solutions that advance the business.
  • Relevant work experience is important for successful performance of this role due to the complexity of our global IT Security environment.   
  • Information security qualification such as CISSP is preferred.  
  • Strong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices. 
  • Expertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect). 
  • Knowledge of cryptographic practices, encryption protocols, and PKI management. 
  • Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP). 
  • Familiarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus). 
  • Understanding of DevSecOps practices, including securing CI/CD pipelines 
  • Self-starter with the ability to work independently and manage multiple projects simultaneously. 
  • Strong problem-solving and analytical skills with the ability to identify security risks and propose effective solutions. 
  • Ability to work collaboratively in cross-functional teams and influence technical teams towards secure implementations. 

Additional Information

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: ​

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.​

  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.​

  • This job is eligible to participate in our short-term incentive programs. ​

  • This job is eligible to participate in our long-term incentive programs​

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law. 

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.  Equal Opportunity Employer/Veterans/Disabled. 

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

AbbVie Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
AbbVie DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of AbbVie
AbbVie CEO photo
Richard A. Gonzalez
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Application Solution Architect (Remote), AbbVie

Join AbbVie as a Security Application Solution Architect and help shape the future of our secure technology initiatives! As a valued member of our Information Security team, you’ll play a crucial role in fostering a comprehensive information security program. Your expertise will be vital as you work closely with application development teams to ensure the design and deployment of secure solutions. At AbbVie, you will find yourself diving deep into various application-level risks, including session management, configuration file security, and secrets management, all while leveraging your understanding of secure application development practices. Remote work means you can collaborate with colleagues across the U.S. while contributing to meaningful projects that impact the healthcare landscape. You’ll have the opportunity to develop re-usable implementation guidance and design patterns, review application software designs, and take the lead in identifying potential application threats. If you have extensive experience in security architecture and a passion for making a difference in people's lives through technology, we want you on our team. This is not just a job; it's a chance to be part of something bigger and to make a real difference in the world of healthcare technology. Discover the challenge and excitement of working at AbbVie, where innovation meets compassion!

Frequently Asked Questions (FAQs) for Security Application Solution Architect (Remote) Role at AbbVie
What are the main responsibilities of a Security Application Solution Architect at AbbVie?

As a Security Application Solution Architect at AbbVie, you'll be responsible for collaborating with application architects and engineers to define security standards and controls in application software and infrastructure designs. Your role includes generating detailed security controls documentation, supporting the design and implementation of secure technology solutions, and leading initiatives to identify and address security risks. You will also work with information security leadership to enforce security requirements and foster an information security culture across the organization.

Join Rise to see the full answer
What qualifications are required to be a Security Application Solution Architect at AbbVie?

To become a Security Application Solution Architect at AbbVie, candidates need a bachelor’s degree and at least 9 years of experience in information security or related functions. Alternatively, a master’s degree with 8 years of experience or a PhD with 4 years is also acceptable. The ideal candidate should possess strong knowledge in application security principles, secure coding practices, and experience with security frameworks such as ISO or NIST. Holding an information security qualification like CISSP is preferred.

Join Rise to see the full answer
How does AbbVie ensure a culture of information security within the organization?

AbbVie fosters an information security culture by focusing on education, skill development, and implementing effective information security processes. As a Security Application Solution Architect, you will play an advisory role in application development projects, ensuring security considerations are integral to all technology solutions. Additionally, you'll collaborate with various teams to promote best practices and provide training to enhance security awareness throughout the organization.

Join Rise to see the full answer
What kind of technologies and practices should a Security Application Solution Architect at AbbVie be familiar with?

A Security Application Solution Architect at AbbVie should be well-versed in secure session management, authentication mechanisms (like OAuth and SAML), and cryptographic practices. Familiarity with containerization technologies like Docker and Kubernetes, as well as cloud platforms such as AWS, Azure, and GCP, is also essential. Additionally, understanding DevSecOps practices, tools for code analysis, and vulnerability scanning is highly beneficial in this role.

Join Rise to see the full answer
What is the work environment like for a Security Application Solution Architect at AbbVie?

The work environment for a Security Application Solution Architect at AbbVie is collaborative and flexible, as the position is remote-friendly. You'll work with cross-functional teams across various locations in the U.S., engaging with talented professionals who are passionate about securing technology solutions. AbbVie encourages open communication and fosters a culture where ideas and innovative solutions are welcomed, allowing you to effectively contribute to the company's mission of transforming lives through healthcare.

Join Rise to see the full answer
Common Interview Questions for Security Application Solution Architect (Remote)
Can you describe your experience with secure application development practices?

In answering this question, highlight specific experiences where you implemented secure coding practices. Discuss methodologies you've used, such as OWASP Guidelines, and provide examples of how these practices mitigated security risks in past projects.

Join Rise to see the full answer
What strategies do you use to assess and manage application-level risks?

Explain your approach to risk assessment, including threat modeling and vulnerability assessments. Mention tools and frameworks you've used, and illustrate how you developed strategies to address identified risks effectively.

Join Rise to see the full answer
What is your experience with encryption protocols and cryptographic practices?

Detail your knowledge of various encryption protocols (like AES, RSA) and experience with implementing cryptographic practices. Share instances where you've secured sensitive data through these mechanisms, demonstrating their effectiveness.

Join Rise to see the full answer
How do you ensure collaboration with development teams on security initiatives?

Discuss your communication and collaboration techniques. Describe how you've successfully worked with development teams, shared security requirements, and provided guidance on integrating security measures into the software development lifecycle.

Join Rise to see the full answer
What is your approach to staying current with security threats and trends?

Outline your strategies for continuous learning, such as following industry publications, attending conferences, or participating in relevant online communities. Mention how you incorporate this knowledge into your work to enhance security measures.

Join Rise to see the full answer
Explain a time when you identified a significant security risk and the steps you took to address it.

Share a concrete example that outlines the risk, the impact it could have had, and the actions you took. Detail how you collaborated with others to remediate the risk and what changes were implemented to prevent future issues.

Join Rise to see the full answer
How do you evaluate the security posture of an application?

Discuss your methodology for evaluating application security, such as conducting assessments or employing security tools. Explain how you utilize the data gathered to recommend remediation steps to improve the overall security posture.

Join Rise to see the full answer
What tools have you used for code analysis and vulnerability scanning?

Mention specific tools you're experienced with, such as SonarQube for code analysis and Nessus for vulnerability scanning. Provide insights into how you’ve used these tools to identify and remediate issues in applications.

Join Rise to see the full answer
Describe your experience with incident management and response.

Outline your involvement in incident management processes, including detection, response, and post-incident analysis. Illustrate how your actions helped improve response times and security measures in the organization.

Join Rise to see the full answer
How do you communicate security concerns to non-technical stakeholders?

Explain your strategies for translating complex security concepts into understandable language for non-technical stakeholders. Share examples of how you successfully gained buy-in on security initiatives and the importance of security compliance.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Become a pivotal part of AbbVie's mission by driving sales and customer relationships in the Psychiatry specialty division.

Photo of the Rise User
Posted 3 days ago

Join AbbVie as a Manager in their Safety Operations, where you'll play a critical role in improving patient lives through compliance and process excellence.

Photo of the Rise User
Supabase Remote No location specified
Posted yesterday

As a Security Operations Engineer at Supabase, you'll be the frontline defender of a dynamic cloud platform, ensuring security measures are effective and responsive.

Photo of the Rise User
Posted 5 days ago

Join Maveris as a Cyber Threat & Research Project Technical Manager, where your expertise will support critical missions in cybersecurity for the U.S. Treasury.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Seeking a Director of Data Controls Design and Enablement at American Express to lead innovative data governance solutions in a hybrid environment.

Photo of the Rise User

Perrigo is looking for an experienced Sr. Digital Business Analyst/Product Owner to optimize its digital landscape and support strategic initiatives.

Join DMV IT Service LLC as an Integrations Software Engineer III to lead the development of innovative data integration solutions.

Photo of the Rise User

Join Kimley-Horn as a ProjectWise Administrator and play a pivotal role in enhancing our enterprise-level applications in a dynamic team environment.

Posted 3 days ago

Join Blue River Technology as a Cloud Infrastructure Administrator to drive innovation in intelligent machinery and support sustainable solutions.

Photo of the Rise User
Avaloq Remote Strada Regina 40, Bioggio, Canton Ticino, Switzerland
Posted 16 hours ago

Join Avaloq as a skilled IT Systems Support Engineer and help optimize our applications in a collaborative, hybrid work environment.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

AbbVie’s mission is to discover and deliver innovative medicines that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas: i...

2910 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 23, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!