Haystack
← Back to Jobs
Technology
DC

Application Security Architect

Data Capital IncRichmond, VA🇺🇸United StatesPosted 14 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
Yesterday
JavaScriptTypeScriptPythonJavaSQL.NETMicroservicesSQL ServerAzureOAuthJWTSAMLOWASPEncryptionPKI

Job Description

Position Overview

The Virginia Department of Transportation (VDOT) is seeking an experienced Application Security Architect to define, implement, and oversee application security strategies across enterprise IT initiatives.

The Application Security Architect will lead the Secure Software Development Lifecycle (SSDLC) across a complex hybrid technology ecosystem that includes web applications, APIs, microservices, cloud-native platforms, Agentic AI solutions, enterprise GIS, low-code/no-code platforms, and emerging technology patterns.

The role will also lead application and data protection strategies, data governance, and privacy architecture across VDOT's statewide transportation ecosystem. This includes defining how structured, unstructured, and spatial/GIS data are classified, encrypted, stored, monitored, and accessed across enterprise and cloud platforms.

The architect will work closely with software engineering, enterprise architecture, cloud/platform, data, and cybersecurity teams to conduct threat modeling, develop secure architecture patterns, identify security risks, and ensure alignment with Commonwealth of Virginia (COV) and VITA security standards.

Required Qualifications

  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles.
  • 2+ years of experience designing security architecture for enterprise systems.
  • Strong knowledge of secure software-development principles and application security risks, including the OWASP Top 10, injection, insecure authorization, deserialization, and API abuse.
  • Demonstrated experience designing security architectures across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS.
  • Experience with data classification, encryption, DLP, privacy assessments, and data-protection strategies.
  • Strong understanding of RBAC, Row-Level Security, column-level encryption, dynamic masking, database auditing, and activity monitoring.
  • Demonstrated experience conducting threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding practices in one or more technologies such as Java, .NET, JavaScript/TypeScript, or Python.
  • Strong knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, encryption, identity management, and secrets management.
  • Ability to translate complex security risks into clear technical and business recommendations.
  • Strong written and verbal communication skills, with experience producing architecture diagrams, security standards, risk assessments, and remediation plans.
  • Experience working with Commonwealth of Virginia (COV) / VITA security standards is highly valuable.

Similar jobs