Why This Role Stands Out
Elevate your career as an Application Security Architect at Accylerate, where you'll shape the security of innovative solutions and drive enterprise-wide security strategies. This role is perfect for a seasoned professional with a passion for secure development lifecycles and a knack for translating complex security risks into actionable plans, offering a hybrid work model for enhanced flexibility. Embrace this opportunity to contribute to a leading company and advance your expertise in a dynamic technological landscape.
Quick Overview
Job Description
Client: VDOT
Title: Application Security Architect
Duration: 12+ Months
Location: Richmond, VA (Hybrid)
Ideal Candidate Profile:
· Seeking an Application Security Architect with strong experience across software engineering, application security, or security engineering, including hands-on experience designing and reviewing secure application architectures to define, embed, and oversee application security strategies across enterprise IT initiatives.
· This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns.Strong background in SSDLC, threat modeling, OWASP risks, API/web security, cloud-native environments, CI/CD, containers, identity and access management, and DevSecOps practices.
· The ideal candidate should have experience securing and governing data across platforms such as Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS, with knowledge of encryption, RBAC, data classification, DLP, auditing, and privacy controls. Strong communication skills are required to translate security risks into practical architectural standards, remediation plans, and solutions for technical and nontechnical stakeholders.
Job Duties & Responsibilities
· Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
· Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
· Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
· Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
· Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
· Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
· Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
· Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
· Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
· Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
· Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
· Maintain architecture documentation, security decision patterns, risk registers, and exception documentation
Required Skills & Experience
· Bachelor's degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
· 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
· Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
· Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
· Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
· Demonstrated experience with threat modeling and security architecture reviews.
· Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
· Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
· Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
· Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
· Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
· Experience in a regulated environment such as financial services, healthcare, government, or payments.
· Experience implementing DevSecOps programs and security automation at scale.
· Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
· Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
· Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, NY🇺🇸HybridYesterdayMicrosoft OfficeVMwareTechnology - PC
OT Security Analyst
NewPyramid Consulting, Inc.
Dallas, TX🇺🇸$45 - $50/hrOn-siteYesterdayTCP/IPDNSTechnology - RM
Firewall Engineer with Security Clearance
NewRMantras
Alexandria, VA🇺🇸On-siteYesterdayEngineering - AT
Cyber Security Engineer with rapid7
NewAce Technologies, Inc.
United States🇺🇸HybridYesterdayAWSAzureGoogle Cloud+1Technology - MB
Application Security Architect
NewMBI LLC
Richmond, VA🇺🇸On-siteYesterdayAzureOAuthSAML+4Technology - NI
Principal Vulnerability Researcher
NewNightwing
Sterling, Virginia🇺🇸$99k - $206k/yrOn-site1 hour agoAssemblyC++PythonTechnology