Why This Role Stands Out
This hybrid Application Security Architect role offers a fantastic opportunity to shape enterprise security strategies and drive innovation in a dynamic technology environment. You'll thrive here if you possess extensive experience in application security architecture and a passion for integrating security into the entire development lifecycle. Apply today to make a significant impact and advance your career in a reputable company.
Quick Overview
Job Description
🔐 APPLICATION SECURITY ARCHITECT
📍 Location: Richmond, VA
🏢 Work Type: Hybrid
🎥 Interview: WebCam + In-Person
📌 Local Candidates Only
We are seeking a highly experienced Application Security Architect to define and oversee enterprise application security strategies across modern IT environments.
🔹 KEY RESPONSIBILITIES
• Define application security architecture standards, patterns, and guardrails
• Lead threat modeling and security architecture reviews
• Apply SSDLC principles across enterprise applications
• Secure web, mobile, API, microservice, and cloud-native applications
• Integrate security into CI/CD, IaC, development, testing, and production
• Evaluate SAST, DAST, SCA, container scanning, API security, and secret scanning tools
• Establish vulnerability management and remediation processes
• Design IAM patterns including RBAC/ABAC, MFA, SSO, OAuth 2.0, OIDC, SAML, and JWT
• Secure Kubernetes, containers, serverless platforms, cloud IAM, and network environments
• Develop data classification, encryption, DLP, privacy, and audit strategies
• Support incident response and application-layer security investigations
• Maintain security architecture documentation, risk registers, and security standards
🔹 REQUIRED SKILLS
✅ 10+ years in software engineering, application security, or security engineering
✅ 6+ years designing and implementing security architecture
✅ Strong OWASP Top 10 and secure coding knowledge
✅ Threat modeling and architecture review experience
✅ Azure and Microsoft technology security experience
✅ Experience with APIs, web applications, distributed systems, and cloud platforms
✅ CI/CD, DevSecOps, containers, and Kubernetes security
✅ OAuth 2.0, OIDC, SAML, JWT, PKI/TLS, encryption, and secrets management
✅ Strong technical documentation and communication skills
✅ Bachelor’s degree or equivalent practical experience
⭐ PREFERRED
• Government or other regulated-industry experience
• ArcGIS/Esri security architecture
• Privacy engineering and data classification
• Penetration testing
• DevSecOps security automation
• CISSP, CSSLP, CCSP, GIAC, or relevant certifications
📩 Interested candidates can send their updated resume.
Similar jobs
- AS
Monitoring / Observability Tool Developer
NewApex Systems
Atlanta, GA🇺🇸Hybrid13 hours agoSQLShellSpring+10Technology - AS
Nexthink Developer
NewApex Systems
Raleigh, NC🇺🇸Hybrid13 hours agoPowerShellTechnology - CG
Network Engineer with Security Clearance
NewContact Government Services, LLC
Baltimore, MD🇺🇸$135.6k - $184.0k/yrHybrid13 hours agoAgileJiraPenetration Testing+1Technology - AS
Senior Software Engineer (Snowflake)
NewApex Systems
Orlando, FL🇺🇸On-site2 days agoSQLSnowflakeAgile+9Technology - AI
Sr. Technical Writer, Mission Autonomy with Security Clearance
NewAnduril Industries
Santa Ana, CA🇺🇸Hybrid13 hours agoTechnology - PD
Network Engineer 3 with Security Clearance
NewPDS Defense Inc.
San Antonio, TX🇺🇸On-site13 hours agoFiberEncryptionActive Directory+6Technology