Haystack
← Back to Jobs
Technology
ME

Application Security Architect

MetaSense, Inc.Richmond, VA🇺🇸United StatesPosted Sep 18, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Richmond, VA, United States
Posted
Yesterday
SQLSQL ServerAzureKubernetesOAuthJWTSAMLOWASPEncryptionPKI

Job Description

Title: Application Security Architect

📍 Location: Richmond, VA — 1 day/month
⚠️ Local Candidates Only
Duration: Long-Term (12+ Months)
🎥 Interview: Video + Onsite

Role Overview:
Seeking an experienced Application Security Architect to define and implement application security strategies across enterprise IT initiatives. The role will focus on SSDLC, secure architecture, threat modeling, data protection, cloud security, DevSecOps, and privacy across web, API, cloud-native, GIS, low-code/no-code, and AI solutions.

Key Responsibilities:

  • Define application security architecture, standards, patterns, and controls.
  • Lead threat modeling and security architecture reviews.
  • Integrate security across the SDLC, CI/CD, and DevSecOps processes.
  • Establish security requirements for authentication, authorization, encryption, APIs, secrets, logging, and data protection.
  • Secure Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS, Kubernetes, and cloud environments.
  • Implement data classification, encryption, DLP, RBAC, auditing, and privacy controls.
  • Manage application vulnerabilities, dependencies, and security exceptions.
  • Partner with engineering, cloud, cybersecurity, and leadership teams to address security risks.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field (or equivalent experience).
  • 10+ years of experience in software engineering, application security, or security engineering.
  • 2+ years of security architecture experience.
  • Strong knowledge of OWASP Top 10, threat modeling, API/web security, cloud security, and DevSecOps.
  • Experience with OAuth 2.0, OIDC, SAML, JWT, PKI/TLS, encryption, and secrets management.
  • Strong communication and documentation skills.

Preferred: CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, government/regulated-industry experience, and penetration-testing experience.

Onsite Requirement: Candidate must be available to work 4 days/week onsite during the initial 90-day probationary period, with the possibility of reduced onsite requirements afterward.

Similar jobs