Quick Overview
Job Description
Core responsibilities
Define application-security architecture principles, standards, patterns, reference
implementations, and guardrails for web, mobile, API, microservice, and cloud-native
systems.
Perform architecture and design reviews, identify trust boundaries, attack paths, data
flows, security gaps, and compensating controls.
Lead or facilitate threat modeling for new applications, major features, integrations,
and high-risk changes.
Establish repeatable security requirements for authentication, authorization, session
management, encryption, secrets management, logging, privacy, API protection, and
data protection.
Partner with software engineers to integrate security throughout the SDLC, including
code review, CI/CD pipelines, infrastructure as code, testing, release approval, and
production monitoring.
Evaluate and guide use of security tools such as SAST, DAST, software composition
analysis, container/image scanning, API security testing, secret scanning, and runtime
protection.
Define a vulnerability-management approach for applications and dependencies,
including severity criteria, remediation SLAs, exception processes, and verification of
fixes.
Assess third-party libraries, open-source dependencies, SaaS integrations, and
vendor-provided components for security risk.
Design identity and access-control patterns, including least privilege, MFA/SSO
integration, service-to-service authentication, RBAC/ABAC, and privileged-access
controls.
Work with cloud and platform teams to secure application hosting environments,
including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation,
and secrets storage.
Advise incident-response teams on application-layer threats and contribute to root-
cause analysis and security improvements after incidents.
Maintain architecture documentation, security decision patterns, risk registers, and
exception documentation.
Required qualifications
Bachelor s degree in computer science, cybersecurity, engineering, or a related field or
equivalent practical experience.
10+ years in software engineering, application security, security engineering, or related
technical roles, including 2+ years designing security architecture for systems.
Strong understanding of secure software-development principles and common
application risks, including the OWASP Top 10, insecure authorization, injection,
deserialization and API abuse.
Design and implement end-to-end security architectures for data-at-rest, in-transit, and
in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS
platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption,
DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state
transportation and infrastructure assets.
Enforce granular data access controls (including RBAC, Row-Level Security, Column-
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, NY🇺🇸HybridYesterdayMicrosoft OfficeVMwareTechnology - PC
OT Security Analyst
NewPyramid Consulting, Inc.
Dallas, TX🇺🇸$45 - $50/hrOn-siteYesterdayTCP/IPDNSTechnology - RM
Firewall Engineer with Security Clearance
NewRMantras
Alexandria, VA🇺🇸On-siteYesterdayEngineering - AT
Cyber Security Engineer with rapid7
NewAce Technologies, Inc.
United States🇺🇸HybridYesterdayAWSAzureGoogle Cloud+1Technology - MB
Application Security Architect
NewMBI LLC
Richmond, VA🇺🇸On-siteYesterdayAzureOAuthSAML+4Technology - NI
Principal Vulnerability Researcher
NewNightwing
Sterling, Virginia🇺🇸$99k - $206k/yrOn-site1 hour agoAssemblyC++PythonTechnology