Principal Advisor Cyber Security Architecture (Application Security)
Remote · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We seek an experienced Principal Advisor in Cyber Security Architecture specializing in Application Security to lead the domain across Rio Tinto. This position is responsible for developing and maintaining the strategy, standards, architecture, and roadmap to ensure secure software development and application security services enterprise-wide.
Key Responsibilities
- Drive the enterprise Application Security strategy, including standards, reference architectures, and service planning.
- Lead continual enhancements to Secure SDLC, DevSecOps processes, threat modeling, and secure application development methodologies.
- Collaborate with development, architecture, and platform teams to integrate practical security requirements into engineering standards, delivery workflows, and CI/CD pipelines.
- Manage Application Security tools and platforms such as Snyk, integrating with systems like GitHub, Azure DevOps, and Artifactory to improve service adoption and effectiveness.
- Provide guidance on identifying, prioritizing, and addressing application and dependency vulnerabilities and enhance vulnerability management processes.
- Develop reusable security patterns and define requirements for securing applications, APIs, cloud-native workloads, containers, secrets, and AI-enabled technologies.
- Conduct security reviews for high-risk projects, providing clear advice to development teams and project stakeholders.
- Build strong collaborative relationships across Cybersecurity, IS&T, and development teams, while mentoring architects and elevating Application Security maturity throughout the organization.
About the Employer
Rio Tinto is a global leader in mining and materials with a rich history spanning 150 years, delivering essential minerals worldwide. The Information Systems and Technology (IS&T) function supports diverse operations globally by providing integrated IT services that power innovation, safety, and productivity.
Inclusion and Diversity
Rio Tinto values a diverse and inclusive workplace, actively encouraging applications from Aboriginal and Torres Strait Islander peoples, women, LGBTQ+ individuals, mature workers, people with disabilities, and culturally diverse backgrounds. The company fosters an environment where all voices are respected and every individual is treated with dignity.
Qualifications and Experience
- Strong expertise in Application Security architecture, Secure SDLC, DevSecOps, threat modeling, vulnerability management, and security-by-design principles.
- Proven ability to create and implement security standards, patterns, and guidance tailored for large, complex organizations.
- Experience managing Application Security tooling, particularly platforms like Snyk, including developer onboarding and integrating with development workflows.
- Demonstrated capability to communicate effectively and build productive partnerships across Cybersecurity, architecture, engineering, and business teams.
- Relevant certifications or qualifications in cybersecurity, information security, software engineering, or equivalent substantial experience.
Preferred Skills
- Familiarity with GitHub, Azure DevOps, Artifactory integrations, CI/CD pipeline security, API security, secrets management, container security, and software supply chain security.
- Experience supporting security in cloud-native and AI-enabled software development environments.
- Knowledge of security frameworks such as OWASP, NIST, ISO 27001, CIISec, or OFIA and exposure to other domains like identity, cloud, OT, or infrastructure security architecture.
Work Environment and Benefits
- A workplace where safety is the utmost priority.
- Permanent employment with Rio Tinto offering a competitive base salary complemented by an annual incentive program.
- Comprehensive health benefits including subsidized private health insurance covering employees and their immediate families.
- Access to an attractive share ownership scheme and company-provided insurance.
- Flexible salary sacrifice and packaging options.
- Career development and education support to advance technical and leadership skills.
- Family-friendly health and medical wellbeing support.
- Generous leave policies covering vacation, parental, sick, and cultural leave.
- Exclusive employee discounts spanning banking, retail, automotive, and accommodation sectors.
Industry
Mining