Why This Role Stands Out
This role offers a significant opportunity to shape application security strategies for a major state agency, utilizing cutting-edge technologies like Agentic AI and DevSecOps. You'll thrive here if you're a seasoned Security Architect eager to build robust frameworks and make a tangible impact on enterprise-wide security initiatives. Apply today to leverage your expertise in a dynamic and influential position.
Quick Overview
Job Description
We are seeking a senior Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives at the Virginia Department of Transportation (VDOT) in Richmond, VA. This role establishes Secure Software Development Lifecycle (SSDLC) frameworks, threat modeling standards, data governance, and DevSecOps controls across hybrid ecosystems, cloud platforms, Microsoft stack solutions, enterprise GIS architectures, and Agentic AI tools.
- Client: Virginia Department of Transportation (VDOT)
- Location: Richmond, VA 23219
- Work Arrangement: Hybrid (Onsite requirements set by agency)
- Role Type: Contract (9 Months with extension potential)
- Interview Process: Either In-Person or Remote (Webcam)
- Compliance: Must align with Commonwealth of Virginia (COV) and VITA SEC 530 security standards.
Key Responsibilities
- Application Security Architecture & SSDLC: Formulate security principles, threat models, architectural patterns, and security guardrails across web, mobile, microservice, cloud-native, and low-code/no-code platforms.
- Data Security & Governance: Design end-to-end data security architectures (data-at-rest, in-transit, and in-use) using automated classification tools (Microsoft Purview), data loss prevention (DLP), and privacy impact assessments (DPIA).
- Identity & Access Management (IAM): Establish authorization, authentication, and encryption standards incorporating OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, dynamic masking, Row-Level Security (RLS), and RBAC/ABAC models.
- DevSecOps Integration: Partner with software engineering teams to embed security tools into CI/CD pipelines, including SAST, DAST, Software Composition Analysis (SCA), container/image scanning, secret scanning, and infrastructure-as-code (IaC) verification.
- Regulatory & Compliance Alignment: Audit database activity and application logs to ensure strict compliance with VITA SEC 530 and state transportation cybersecurity requirements.
Required Skills & Qualifications
- Software & Application Security Experience: 10+ years in software engineering, security engineering, or appsec roles, with at least 6+ years specifically focused on IT security architecture design.
- SSDLC & Risk Management: 6+ years of hands-on experience in threat modeling, OWASP Top 10 mitigation, API security, and secure coding patterns across environments (.NET, Java, Python, or TypeScript).
- Microsoft Ecosystem Security: 6+ years architecting end-to-end security across Microsoft Azure, SQL Server, Power Platform, and Dynamics 365 platforms.
- Identity & Encryption Controls: 6+ years of experience with OAuth 2.0, SAML, OIDC, JWTs, secrets management, and cryptography standards.
- Technical Communication: 10+ years drafting technical documentation, security risk assessments, remediation plans, and enterprise architecture diagrams.
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
Preferred Qualifications
- Industry Certifications: Active CISSP, CSSLP, CCSP, GIAC, or vendor-specific cloud security credentials.
- Public Sector & Regulated Experience: 6+ years working in government, financial, healthcare, or payments ecosystems.
- GIS & Emerging Tech: Experience securing Esri ArcGIS platforms, DevSecOps automation, penetration testing remediation, or Agentic AI implementations.
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, NY🇺🇸HybridYesterdayMicrosoft OfficeVMwareTechnology - PC
OT Security Analyst
NewPyramid Consulting, Inc.
Dallas, TX🇺🇸$45 - $50/hrOn-siteYesterdayTCP/IPDNSTechnology - RM
Firewall Engineer with Security Clearance
NewRMantras
Alexandria, VA🇺🇸On-siteYesterdayEngineering - AT
Cyber Security Engineer with rapid7
NewAce Technologies, Inc.
United States🇺🇸HybridYesterdayAWSAzureGoogle Cloud+1Technology - MB
Application Security Architect
NewMBI LLC
Richmond, VA🇺🇸On-siteYesterdayAzureOAuthSAML+4Technology - NI
Principal Vulnerability Researcher
NewNightwing
Sterling, Virginia🇺🇸$99k - $206k/yrOn-site1 hour agoAssemblyC++PythonTechnology