Johnson Controls logo

Application Security Architect

Johnson Controls

Hybrid
Prague, Czechia
Full-time
Mid Level
3+ yrs
Salary not listedPosted 4h ago

Real job — pulled straight from Johnson Controls’s careers page · Verified September 24, 2026 · No reposts.

Job description

Johnson Controls is hiring a Application Security Architect — a full-time, based in Prague, Czechia role. Apply directly on Johnson Controls's careers page below.

Application Security Architect

Location: Prague-Czechia-Czechia

Time Type: Full time

Job Description

What you will do

At Johnson Controls, you'll help secure the technologies behind intelligent buildings, connected products, and smart cities. As an Application Security Architect, you'll partner with engineering, product, and business teams to embed security and privacy throughout the product lifecycle, shape security strategy, lead risk assessments, and drive continuous improvements that strengthen cybersecurity resilience and customer trust.

Working as a trusted security advisor, you'll guide teams on secure software development, threat modeling, security architecture, and security-by-design practices across cloud, mobile, embedded, and connected products. You'll lead key security activities including architecture reviews, security testing, vulnerability management, and compliance support while translating security requirements into practical solutions that help teams deliver secure, resilient products.

How you will do it

  • Act as a trusted security advisor throughout the software development lifecycle.

  • Guide development teams on secure coding, threat modeling, security architecture, and security-by-design principles.

  • Lead secure SDLC activities, including security requirements definition, architecture reviews, code reviews, security testing, and remediation planning.

  • Translate regulatory, customer, and cybersecurity requirements into practical security controls and development practices.

  • Collaborate with security champions, architects, engineers, and product leaders to balance security, usability, and business objectives.

  • Partner with teams across cloud, mobile, embedded, and connected product environments to address evolving security challenges.

  • Stay current with emerging threats, vulnerabilities, and industry best practices, sharing knowledge and recommendations across the organization.

What we look for

Required

  • Minimum 3 years in cybersecurity, governance, risk, compliance, product security, or a related security function.

  • Experience working with cybersecurity and compliance frameworks NIST 800-53 and also ISO 27001 or SOC 2.

  • Experience evaluating cybersecurity risks and implementing or recommending appropriate security controls.

  • Ability to translate security requirements into actionable technical guidance.

  • Strong stakeholder management skills, with the ability to build trusted relationships and establish credibility with customers, engineering teams, business leaders, and other key stakeholders.

Preferred

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related technical discipline.

  • Professional cybersecurity certifications such as CISSP, GSEC, Security+, or equivalent.

  • Knowledge of compliance frameworks such as ISA/IEC 62443, GDPR, EU CRA, or similar.

  • Experience utilizing AI technologies and ensuring the secure design, implementation, and operation of AI capabilities within products.

  • Familiarity with Operational Technology (OT), industrial controls, building management systems, or IoT ecosystems.

  • Overview of tools such as SD Elements, FiniteState, ArmorCode, jFrog and Jira.

About Us

Johnson Controls, a global leader in thermal management, mission-critical building systems, energy efficiency, and decarbonization, helps customers use energy more productively, reduce carbon emissions, and operate with the precision and resilience required in rapidly expanding industries such as data centers, healthcare, pharmaceuticals, advanced manufacturing, and higher education.

For more than 140 years, Johnson Controls has delivered performance where it really matters. Backed by advanced technology, lifecycle services and an industry-leading field organization, we elevate customer performance, turn goals into real-world results and help move society forward.

We are committed to diversity and inclusion and believe that different perspectives make us stronger. By encouraging open dialogue and valuing individuality, we strive to be one of the most desirable places to work.

#LI-BB1

#LI-Hybrid

Get Application Security Architect jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Mazedesign logo

Senior Security Engineer (Remote)

Remote · Ireland +5
✓ From careers page· 12h ago
Job Listings at WuXi AppTec logo

Security Engineer

Saint Paul, MN
✓ From careers page· 12h ago
Verizon logo

Senior CSIRT Consultant

Tokyo, Japan
✓ From careers page· 13h ago
Scalian logo

SOC & SIEM Specialist

Brussels, BE
✓ From careers page· 14h ago

Frequently asked questions

What skills are required for Application Security Architect at Johnson Controls?

The required skills for Application Security Architect at Johnson Controls include: ISO 27001, SOC 2, CISSP, CompTIA Security+, GDPR, AI, IoT, JIRA.

What is the seniority level for Application Security Architect at Johnson Controls?

Application Security Architect at Johnson Controls is a Mid Level level position.

How do I apply for Application Security Architect at Johnson Controls?

You can view the full description and apply for Application Security Architect at Johnson Controls on EchoJobs: https://echojobs.io/job/johnson-controls-application-security-architect-m3huc.