Haystack
← Back to Jobs
Technology
BT

Application Security Architect – Hybrid – Richmond, VA

Brillfy TechnologyRichmond, VA🇺🇸United StatesPosted 14 Sept 2026

Why This Role Stands Out

This hybrid Application Security Architect role offers a fantastic opportunity to shape enterprise security strategies and drive innovation in a dynamic technology environment. You'll thrive here if you possess extensive experience in application security architecture and a passion for integrating security into the entire development lifecycle. Apply today to make a significant impact and advance your career in a reputable company.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Richmond, VA, United States
Posted
Yesterday
AzureKubernetesOAuthJWTSAMLSSOMFAOWASPPenetration TestingEncryptionPKI

Job Description

🔐 APPLICATION SECURITY ARCHITECT

📍 Location: Richmond, VA
🏢 Work Type: Hybrid
🎥 Interview: WebCam + In-Person
📌 Local Candidates Only

We are seeking a highly experienced Application Security Architect to define and oversee enterprise application security strategies across modern IT environments.

🔹 KEY RESPONSIBILITIES

• Define application security architecture standards, patterns, and guardrails
• Lead threat modeling and security architecture reviews
• Apply SSDLC principles across enterprise applications
• Secure web, mobile, API, microservice, and cloud-native applications
• Integrate security into CI/CD, IaC, development, testing, and production
• Evaluate SAST, DAST, SCA, container scanning, API security, and secret scanning tools
• Establish vulnerability management and remediation processes
• Design IAM patterns including RBAC/ABAC, MFA, SSO, OAuth 2.0, OIDC, SAML, and JWT
• Secure Kubernetes, containers, serverless platforms, cloud IAM, and network environments
• Develop data classification, encryption, DLP, privacy, and audit strategies
• Support incident response and application-layer security investigations
• Maintain security architecture documentation, risk registers, and security standards

🔹 REQUIRED SKILLS

✅ 10+ years in software engineering, application security, or security engineering
✅ 6+ years designing and implementing security architecture
✅ Strong OWASP Top 10 and secure coding knowledge
✅ Threat modeling and architecture review experience
✅ Azure and Microsoft technology security experience
✅ Experience with APIs, web applications, distributed systems, and cloud platforms
✅ CI/CD, DevSecOps, containers, and Kubernetes security
✅ OAuth 2.0, OIDC, SAML, JWT, PKI/TLS, encryption, and secrets management
✅ Strong technical documentation and communication skills
✅ Bachelor’s degree or equivalent practical experience

⭐ PREFERRED

• Government or other regulated-industry experience
• ArcGIS/Esri security architecture
• Privacy engineering and data classification
• Penetration testing
• DevSecOps security automation
• CISSP, CSSLP, CCSP, GIAC, or relevant certifications

📩 Interested candidates can send their updated resume.

Similar jobs