Senior Application Security Architect
Company: Morningstar, Inc.
Location: Chicago
Posted on: April 6, 2025
Job Description:
The Team:The Information Security department is responsible for
setting enterprise security policies and standards that are
designed to protect the confidentiality, integrity, and
availability of Morningstar information. The security team offers
guidance and technical expertise in areas like application
security, infrastructure and cloud security, policies and
procedures, disaster recovery and compliance/regulation. We analyze
emerging security threats and conduct risk and vulnerability
assessments to ensure that our information remains secure.The
Role:The Senior Application Security Architect will be part of the
central information security team and act as a subject matter
expert to all of Morningstar's product teams by providing security
guidance and creating application security standards and patterns.
The successful candidate will contribute to maintaining
Morningstar's security posture by performing threat modeling,
security architecture reviews of Morningstar products and ensuring
that major projects receive appropriate architectural security
guidance, requirements setting, and review. The Application
Security Architect will also partner with the Director of Product
Security to define the direction of the application security
program as well as on improving security processes and tooling. The
position will be based in our Chicago or Toronto office.We follow a
hybrid policy of 3 days onsite and 2 days remote work.Job
Responsibilities:
- Collaborate with development teams across the organization to
secure products
- Contribute to secure reference architectures and patterns for
all product teams to leverage
- Develop, maintain, and communicate future and current product
security initiatives
- Develop and enhance internal security processes, programs, and
procedures
- Conduct risk assessments, threat modeling, and product security
reviews on Morningstar systems
- Work directly with internal business units to communicate risk,
provide security remediation advice, and deliver education as
needed.
- Document secure coding guidelines and assist execution by
internal development personnel
- Identify web/mobile/api application security vulnerabilities
and offer remediation adviceQualifications:
- A bachelor's degree and 5+ years' experience in a development
or software security / penetration testing role, or equivalent
experience
- We are looking for someone who enjoys breaking code, solving
puzzles, and diagnosing problems
- Excellent communication skills and a strong understanding of
software development, architecture, and application security
- An ability to improve system development security across
diverse technical teams and technologies
- Strong understanding of risk management and the real-world
impacts of architectural decisions
- Experience architecting and deploying applications securely in
cloud environmentsNice to have:
- Strong understanding of common authentication models and
protocols (SAML, OAuth, OpenID, etc.) preferred
- Prior development experience preferred
- Vulnerability management experience preferredCompensation and
BenefitsAt Morningstar we believe people are at their best when
they are at their healthiest. That's why we champion your wellness
through a wide range of programs that support all stages of your
personal and professional life. Here are some examples of the
offerings we provide:
- Financial Health
- 75% 401k match up to 7%
- Stock Ownership Potential
- Company provided life insurance - 1x salary + commission
- Physical Health
- Comprehensive health benefits (medical/dental/vision) including
potential premium discounts and company-provided HSA contributions
(up to $500-$2,000 annually) for specific plans and coverages
- Additional medical Wellness Incentives - up to $300-$600
annually
- Company-provided long- and short-term disability insurance
- Emotional Health
- Trust-Based Time Off
- 6-week Paid Sabbatical Program
- 6-Week Paid Family Caregiving Leave
- Competitive 8-24 Week Paid Parental Bonding Leave
- Adoption Assistance
- Leadership Coaching & Formal Mentorship Opportunities
- Annual Education Stipend
- Tuition Reimbursement
- Social Health
- Charitable Matching Gifts program
- Dollars for Doers volunteer program
- Paid volunteering days
- 15+ Employee Resource & Affinity GroupsBase Salary Compensation
Range: $93,978.00 - $159,761.00Total Cash Compensation Range:
$110,775.00 - 188,325.00 USD AnnualMorningstar's hybrid work
environment gives you the opportunity to work remotely and
collaborate in-person each week. While some positions are available
as fully remote, we've found that we're at our best when we're
purposely together on a regular basis, typically three days each
week. A range of other benefits are also available to enhance
flexibility as needs change. No matter where you are, you'll have
tools and resources to engage meaningfully with your global
colleagues.
#J-18808-Ljbffr
Keywords: Morningstar, Inc., Chicago , Senior Application Security Architect, Other , Chicago, Illinois
Didn't find what you're looking for? Search again!
Loading more jobs...