Quick Overview
Job Description
Position Overview
The Virginia Department of Transportation (VDOT) is seeking an experienced Application Security Architect to define, implement, and oversee application security strategies across enterprise IT initiatives.
The Application Security Architect will lead the Secure Software Development Lifecycle (SSDLC) across a complex hybrid technology ecosystem that includes web applications, APIs, microservices, cloud-native platforms, Agentic AI solutions, enterprise GIS, low-code/no-code platforms, and emerging technology patterns.
The role will also lead application and data protection strategies, data governance, and privacy architecture across VDOT's statewide transportation ecosystem. This includes defining how structured, unstructured, and spatial/GIS data are classified, encrypted, stored, monitored, and accessed across enterprise and cloud platforms.
The architect will work closely with software engineering, enterprise architecture, cloud/platform, data, and cybersecurity teams to conduct threat modeling, develop secure architecture patterns, identify security risks, and ensure alignment with Commonwealth of Virginia (COV) and VITA security standards.
Required Qualifications
- 10+ years of experience in software engineering, application security, security engineering, or related technical roles.
- 2+ years of experience designing security architecture for enterprise systems.
- Strong knowledge of secure software-development principles and application security risks, including the OWASP Top 10, injection, insecure authorization, deserialization, and API abuse.
- Demonstrated experience designing security architectures across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS.
- Experience with data classification, encryption, DLP, privacy assessments, and data-protection strategies.
- Strong understanding of RBAC, Row-Level Security, column-level encryption, dynamic masking, database auditing, and activity monitoring.
- Demonstrated experience conducting threat modeling and security architecture reviews.
- Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
- Working knowledge of secure coding practices in one or more technologies such as Java, .NET, JavaScript/TypeScript, or Python.
- Strong knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, encryption, identity management, and secrets management.
- Ability to translate complex security risks into clear technical and business recommendations.
- Strong written and verbal communication skills, with experience producing architecture diagrams, security standards, risk assessments, and remediation plans.
- Experience working with Commonwealth of Virginia (COV) / VITA security standards is highly valuable.
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, NY🇺🇸HybridYesterdayMicrosoft OfficeVMwareTechnology - PC
OT Security Analyst
NewPyramid Consulting, Inc.
Dallas, TX🇺🇸$45 - $50/hrOn-siteYesterdayTCP/IPDNSTechnology - RM
Firewall Engineer with Security Clearance
NewRMantras
Alexandria, VA🇺🇸On-siteYesterdayEngineering - AT
Cyber Security Engineer with rapid7
NewAce Technologies, Inc.
United States🇺🇸HybridYesterdayAWSAzureGoogle Cloud+1Technology - MB
Application Security Architect
NewMBI LLC
Richmond, VA🇺🇸On-siteYesterdayAzureOAuthSAML+4Technology - NI
Principal Vulnerability Researcher
NewNightwing
Sterling, Virginia🇺🇸$99k - $206k/yrOn-site1 hour agoAssemblyC++PythonTechnology