Haystack
← Back to Jobs
Technology
ET

Application Security Architect

Esvee Technologies IncRichmond, VA🇺🇸United StatesPosted 14 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
Yesterday
SQLSQL ServerAzureKubernetesSSOMFAOWASPEncryption

Job Description

Core responsibilities
Define application-security architecture principles, standards, patterns, reference
implementations, and guardrails for web, mobile, API, microservice, and cloud-native
systems.
Perform architecture and design reviews, identify trust boundaries, attack paths, data
flows, security gaps, and compensating controls.
Lead or facilitate threat modeling for new applications, major features, integrations,
and high-risk changes.
Establish repeatable security requirements for authentication, authorization, session
management, encryption, secrets management, logging, privacy, API protection, and
data protection.
Partner with software engineers to integrate security throughout the SDLC, including
code review, CI/CD pipelines, infrastructure as code, testing, release approval, and
production monitoring.
Evaluate and guide use of security tools such as SAST, DAST, software composition
analysis, container/image scanning, API security testing, secret scanning, and runtime
protection.
Define a vulnerability-management approach for applications and dependencies,

including severity criteria, remediation SLAs, exception processes, and verification of
fixes.
Assess third-party libraries, open-source dependencies, SaaS integrations, and
vendor-provided components for security risk.
Design identity and access-control patterns, including least privilege, MFA/SSO
integration, service-to-service authentication, RBAC/ABAC, and privileged-access
controls.
Work with cloud and platform teams to secure application hosting environments,
including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation,
and secrets storage.
Advise incident-response teams on application-layer threats and contribute to root-
cause analysis and security improvements after incidents.
Maintain architecture documentation, security decision patterns, risk registers, and
exception documentation.
Required qualifications
Bachelor s degree in computer science, cybersecurity, engineering, or a related field or
equivalent practical experience.
10+ years in software engineering, application security, security engineering, or related
technical roles, including 2+ years designing security architecture for systems.
Strong understanding of secure software-development principles and common
application risks, including the OWASP Top 10, insecure authorization, injection,
deserialization and API abuse.
Design and implement end-to-end security architectures for data-at-rest, in-transit, and
in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS
platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption,
DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state
transportation and infrastructure assets.
Enforce granular data access controls (including RBAC, Row-Level Security, Column-

Similar jobs