Haystack
← Back to Jobs
Technology
AS

Application Security Architect with cloud security + data security/privacy + Microsoft ecosystem + GIS/ArcGIS (Need 13+ Years exp Virginia local only)

Analytics SolutionsRichmond, VA🇺🇸United StatesPosted Sep 16, 2026

Why This Role Stands Out

Advance your career as an Application Security Architect in a hybrid role that allows you to shape robust security strategies across a dynamic Microsoft and GIS ecosystem. You'll thrive by leveraging your extensive experience in cloud, data security, and secure SDLC to protect critical enterprise initiatives. This is an excellent opportunity to contribute to a leading analytics solutions provider and make a significant impact.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
Yesterday
EncryptionOAuthOWASPSAMLAzurePKIPenetration TestingREST

Job Description

Job: Application Security Architect with cloud security + data security/privacy + Microsoft ecosystem + GIS/ArcGIS 

Location: Richmond, Virginia (Hybrid)

Contract

 

Our client is seeking an experienced Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.

The ideal candidate will have strong experience in Application Security, Secure SDLC/SSDLC, Security Architecture, Agentic AI solutions, Threat Modeling, Azure/Cloud Security, DevSecOps, API Security, Identity & Access Management, and Data Protection.

 

Required Qualifications

• 10 years of experience in Software engineering, application security, security engineering, or related technical roles

• 6 years of experience in designing and implementing security architecture for IT systems

• 6 Years of experience in Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse 

• 6 Years of experience in Design and implement end-to-end security architectures for data-at-rest, in-transit and in-use for full MS stack (Azure, O365, Power Platform, D365 

• 6 years of demonstrated experience with threat modeling and security architecture reviews

• 6 years of experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads

• 6 years of experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices

• 10 years of experience with written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans

• 6 years of experience in a regulated environment such as financial services, healthcare, government, or payments 

• 6 years of experience conducting or coordinating penetration testing and translating results into durable architectural improvements

• 4 years of experience implementing DevSecOps programs and security automation at scale

• 4 years of experience with security architectures in Esri's ArcGIS platform  

• Familiarity with privacy engineering, data classification, and compliance frameworks

• Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field, or equivalent practical experience.

• Government/public-sector or other regulated-environment experience.

• VITA/Commonwealth of Virginia security standards experience.

• Privacy engineering, data classification, DLP, and DPIA experience.

• Penetration testing and vulnerability-management experience.

• CISSP, CSSLP, CCSP, GIAC, or relevant cloud/security certification.

Similar jobs