Quick Overview
Job Description
Title/Role: Application Security Architect
Worksite address: Richmond, VA
Interview Type: Both Web Cam and In Person Interview
Work Arrangement: Hybrid
*Local candidates only please
*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.
Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Required qualifications
· Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
· 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
· Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
· Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
· Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
· Demonstrated experience with threat modeling and security architecture reviews.
· Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
· Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
· Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
· Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
· Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
· Experience in a regulated environment such as financial services, healthcare, government, or payments.
· Experience implementing DevSecOps programs and security automation at scale.
· Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
· Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
· Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Similar jobs
- II
Senior Python Backend Developer
NewInfosat IT Services LLC
Charlotte, NC🇺🇸On-site16 hours agoAWSAgileAzure+3Technology - CS
Data Engineer - Databricks
NewContract Staffing Recruiters
United States🇺🇸Hybrid16 hours agoMySQLOracleSQL+7Technology - CS
Regression Test Engineer - REMOTE
NewContract Staffing Recruiters
United States🇺🇸Remote16 hours agoSQLSQL ServerETL+2Technology - CS
SAP ACCOUNTING ANALYST
NewContract Staffing Recruiters
United States🇺🇸Hybrid16 hours agoCost AccountingReconciliationSAP+1Technology - PG
RF Test Engineer
NewPROLIM Global Corporation
Maple Grove, MN🇺🇸Hybrid16 hours agoContinuous ImprovementTechnology - CM
Information System Security Officer (ISSO)
Chenega MIOS
Arlington, VA🇺🇸Remote4 days agoSplunkAgileTechnology