Application Security Architect
Mettler Toledo is seeking a Principal Application Security Architect to own end-to-end security delivery for critical global applications. This hands-on leadership role involves threat modelling, code reviews, and enforcing security gates across modern and legacy stacks. The candidate will guide local security SMEs and serve as the final authority on AppSec decisions in a hybrid model. This position is ideal for an experienced architect looking to drive secure-by-design outcomes in a complex, multi-national technical environment.
50k new jobs listed every day. Install TAL to find more jobs like this.

Experience
12-15 years
Function
Engineering
Work mode
Hybrid, India
Company
Tier 2
What you will work on
Mettler Toledo is seeking a Principal Application Security Architect to own end-to-end security delivery for critical global applications. This hands-on leadership role involves threat modelling, code reviews, and enforcing security gates across modern and legacy stacks. The candidate will guide local security SMEs and serve as the final authority on AppSec decisions in a hybrid model. This position is ideal for an experienced architect looking to drive secure-by-design outcomes in a complex, multi-national technical environment.
TAL's take
Senior architectural role at a large, stable global company offering clear impact and domain-specific challenges.
Very well-defined role with specific architectural responsibilities, security domains, and clear expectations for a principal-level lead.
Must haves
- 12-15+ years in software engineering, application security, or architecture
- Expertise in Secure SDLC, OWASP Top 10, API Security, and Threat Modelling
- Strong experience securing cloud, microservices, and legacy monoliths
- Deep experience integrating security into CI/CD pipelines
- Understanding of OAuth2, OIDC, SAML, and cryptography
Tools and skills
Nice to have: penetration testing, applied cryptography.
About the company
Established global industrial instrument company, while respected, it is not a tier-1 software-native enterprise.