Haystack
← Back to Jobs
Technology
SY

Security Architect in Richmond VA Hybrid

SyntricateRichmond, VA🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Richmond, VA, United States
Posted
Yesterday
JavaScriptTypeScriptPythonJavaSQL.NETSQL ServerAzureKubernetesOAuthJWTSAMLSSOMFAOWASPPenetration TestingEncryptionPKI

Job Description

We are looking for Security Architect in Richmond VA Hybrid. Please read the job description below and let me know if you are interested.
 
Position: Application Security Architect
Location: Richmond, VA – Hybrid (Local candidates Only)
Duration: 1o+ Months Contract
Interview Process: Virtual/In-Person
Req ID: 810287
 
Job Description 

The Virginia Department of Transportation (VDOT) is seeking an experienced Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives. The role will focus on implementing a Secure Software Development Lifecycle (SSDLC) across a hybrid technology ecosystem, including complex web applications, Agentic AI solutions, cloud-native platforms, enterprise GIS, and low-code/no-code solutions.

Key Responsibilities

  • Define application security architecture principles, standards, patterns, reference implementations, and security guardrails.
  • Perform architecture and design reviews, identifying trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for applications, integrations, major features, and high-risk changes.
  • Establish security requirements for authentication, authorization, encryption, secrets management, logging, privacy, APIs, and data protection.
  • Integrate security throughout the SDLC, including code reviews, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide security tools including SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Develop vulnerability-management approaches covering severity criteria, remediation SLAs, exceptions, and verification.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risks.
  • Design identity and access-control patterns, including MFA/SSO, OAuth, RBAC/ABAC, service authentication, and privileged-access controls.
  • Work with cloud and platform teams to secure Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Support incident-response teams with application-layer threats and root-cause analysis.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles.
  • 2+ years of experience designing security architecture for IT systems.
  • Strong knowledge of secure software-development principles and application security risks, including OWASP Top 10.
  • Experience designing end-to-end security architectures for data at rest, in transit, and in use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS.
  • Experience with data classification, encryption, DLP, and privacy risk assessments.
  • Experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding in Java, .NET, JavaScript/TypeScript, or Python.
  • Experience with OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, encryption, and secrets management.
  • Strong communication skills with the ability to explain technical risks and tradeoffs to technical and non-technical stakeholders.
  • Strong technical documentation skills, including architecture diagrams, standards, risk assessments, and remediation plans.

Preferred Qualifications

  • Experience in regulated environments such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Knowledge of privacy engineering, data classification, and compliance frameworks.
  • Experience with penetration testing and translating findings into architectural improvements.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience with security architecture in Esri ArcGIS environments.
 
  •  
 SkillRequired / DesiredAmountof ExperienceExpertise RatingMove
[ ]Software engineering, application security, security engineering, or related technical rolesRequired10Years  
[ ]Experience in designing and implementing security architecture for IT systemsRequired6Years  
[ ]Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuseRequired6Years  
[ ]Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)Required6Years  
[ ]Demonstrated experience with threat modeling and security architecture reviewsRequired6Years  
[ ]Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloadsRequired6Years  
[ ]Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practicesRequired6Years  
[ ]Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plansRequired10Years  
[ ]Experience in a regulated environment such as financial services, healthcare, government, or paymentsHighly desired6Years  
[ ]Experience conducting or coordinating penetration testing and translating results into durable architectural improvementsHighly desired6Years  
[ ]Experience implementing DevSecOps programs and security automation at scaleHighly desired4Years  
[ ]Familiarity with privacy engineering, data classification, and compliance frameworksHighly desired4Years  
[ ]Experience with security architectures in Esri's ArcGIS platformHighly desired2Years  
 
 
 
Best Regards,
Salman Alam
IT Recruiter||Syntricate Technologies Inc.
Direct:
Email:

Similar jobs