Morningstar Logo

Morningstar

Lead Application Security Architect

Reposted 6 Days Ago
Hybrid
Toronto, ON
Senior level
Hybrid
Toronto, ON
Senior level
The Senior Application Security Architect will guide product teams on application security, conduct risk assessments, and enhance security processes.
The summary above was generated by AI
The Team:
The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity, and availability of Morningstar information. The security team offers guidance and technical expertise in areas like application security, infrastructure and cloud security, policies and procedures, disaster recovery and compliance/regulation. We analyze emerging security threats and conduct risk and vulnerability assessments to ensure that our information remains secure.
The Role:
The Lead Application Security Architect will be part of the central information security team and act as a subject matter expert to all of Morningstar's product teams by provide security guidance and creating application security standards and patterns. The successful candidate will contribute to maintaining Morningstar's security posture by performing threat modeling, security architecture reviews of Morningstar products and ensure that major projects receive appropriate architectural security guidance, requirements setting, and review. The Application Security Architect will also partner with the Director of Product Security to define the direction of the application security program as well as on improving security processes and tooling. This position is based in our Chicago office. We follow a hybrid policy of at least 4 days onsite.
Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
Job Responsibilities:
  • Collaborate with development teams across the organization to secure products
  • Contribute to secure reference architectures and patterns for all product teams to leverage
  • Develop, maintain, and communicate future and current product security initiatives
  • Develop and enhance internal security processes, programs, and procedures
  • Conduct risk assessments, threat modeling, and product security reviews on Morningstar systems
  • Work directly with internal business units to communicate risk, provide security remediation advice, and deliver education as needed.
  • Document secure coding guidelines and assist execution by internal development personnel
  • Identify web/mobile/api application security vulnerabilities and offer remediation advice

Qualifications:
  • A bachelor's degree and 5+ years' experience in a development or software security / penetration testing role, or equivalent experience
  • We are looking for someone who enjoys breaking code, solving puzzles, and diagnosing problems
  • Excellent communication skills and a strong understanding of software development, architecture, and application security
  • An ability to improve system development security across diverse technical teams and technologies
  • Strong understanding of risk management and the real-world impacts of architectural decisions
  • Experience architecting and deploying applications securely in cloud environments

Nice to have:
  • Strong understanding of common authentication models and protocols (SAML, OAuth, OpenID, etc.) preferred
  • Prior development experience preferred
  • Vulnerability management experience preferred

Base Salary Compensation Range
$101,422.00-148,755.33
Incentive Target Percentage
12.5% Annual
Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity

Top Skills

Application Security
Cloud Security
Oauth
Openid
SAML
Secure Coding

Morningstar Toronto, Ontario, CAN Office

181 University Avenue, Toronto, ON, Canada, M5H 3M7

Morningstar Toronto, Ontario, CAN Office

1 Toronto Street, Toronto, Ontario, Canada, M5C 2W4

Similar Jobs at Morningstar

Yesterday
Hybrid
Toronto, ON, CAN
Senior level
Senior level
Enterprise Web • Fintech • Financial Services
The Senior Front-End Software Engineer will develop full-stack web applications, maintain existing systems, lead technical discussions, and mentor junior engineers.
Top Skills: AWSCSSHTMLJavaScriptNode.jsNuxt.JsRestful ApisTypescriptVue
2 Days Ago
Hybrid
Toronto, ON, CAN
Mid level
Mid level
Enterprise Web • Fintech • Financial Services
The Senior Site Reliability Engineer will enhance system reliability, lead automation projects, and optimize cloud solutions in a collaborative environment.
Top Skills: Ci/CdCloud-Based SolutionsCloudFormationContainersDevOpsDistributed ApplicationsDockerInfrastructure As CodeMicroservicesPlsqlServerless TechnologySQLTerraform
2 Days Ago
Hybrid
Toronto, ON, CAN
Expert/Leader
Expert/Leader
Enterprise Web • Fintech • Financial Services
The Principal Software Engineer will lead the Toronto engineering team, mentoring engineers and overseeing core architectural decisions for full-stack JavaScript applications.
Top Skills: AWSJavaScriptNode.jsNuxt 3Restful ApisTypescriptViteVueWebpack

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account