VDOT Application Security Architect
$81 - $101 per hourTOMORROW HIRE
Job Description
Job Description
- Job Title: VDOT Application Security Architect
- Work Type: Hybrid
- Location: Richmond, VA
- Salary: $81–$101/hour
- Start Date: September 21, 2026
- End Date: June 30, 2027
- Industry Category: Information Technology / Cybersecurity
- Employment Type: 1099 Contract
- Requisition ID: 810287
Overview:
- VDOT is seeking an experienced Application Security Architect to define, implement, and oversee application security architecture across enterprise IT environments.
- The role will establish security principles, standards, patterns, reference implementations, and technical guardrails across complex applications and technology platforms.
- The position will support secure software development, cloud-native applications, GIS solutions, low-code/no-code platforms, Agentic AI, APIs, data platforms, and enterprise applications.
- The Application Security Architect will work closely with architecture, development, cybersecurity, and technology teams to identify and reduce security risks.
- The role will also support data protection, data governance, privacy, threat modeling, secure design, and compliance with Commonwealth of Virginia and VITA security requirements.
Application:
- Interested candidates should submit an updated resume for consideration.
- Candidates must be local to the Richmond, Virginia area.
- Candidates must physically reside within the United States for the duration of the assignment.
- Candidates must be legally authorized to work in the United States without employer sponsorship, now or in the future.
- Candidates must provide a valid email address.
- Candidates must provide their permanent city and state of residence.
- Candidates must confirm their ability to meet the required onsite schedule.
- Candidates should indicate how soon they can start after receiving an offer.
Job Description:
- Define, implement, and oversee application security architecture across VDOT's enterprise IT environment.
- Establish application security principles, standards, patterns, reference implementations, and technical guardrails.
- Embed security throughout the Secure Software Development Lifecycle (SSDLC), from requirements and architecture through development, testing, deployment, and production monitoring.
- Develop secure architecture patterns for complex web applications, APIs, distributed systems, cloud-native workloads, GIS applications, low-code/no-code platforms, and Agentic AI solutions.
- Lead application security architecture activities involving Azure, SQL Server, Microsoft Dynamics 365, Microsoft Power Platform, ArcGIS, and other enterprise technologies.
- Define and implement security controls for data at rest, data in transit, and data in use.
- Support data classification, encryption, Data Loss Prevention (DLP), privacy, data governance, and Data Protection Impact Assessments (DPIAs).
- Design granular access-control models using Role-Based Access Control (RBAC), Row-Level Security, Column-Level Encryption, dynamic data masking, and centralized database audit and activity monitoring.
- Align application security architecture and controls with VITA security requirements, including VITA SEC 530.
- Conduct threat modeling and security architecture reviews to identify vulnerabilities and security risks early in the development lifecycle.
- Define security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, APIs, and data protection.
- Integrate application security practices into CI/CD pipelines, Infrastructure as Code (IaC), development workflows, testing processes, and release management.
- Evaluate and support security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, API security testing, secret scanning, and runtime security monitoring.
- Support vulnerability management activities and help prioritize remediation based on business and technical risk.
- Assess security risks associated with third-party applications, open-source software, SaaS solutions, and external technology providers.
- Establish secure identity and access-management patterns, including least privilege, Multi-Factor Authentication (MFA), Single Sign-On (SSO), service authentication, RBAC, Attribute-Based Access Control (ABAC), and privileged access management.
- Develop security architecture for cloud environments, Kubernetes, serverless applications, containers, cloud IAM, network segmentation, and secrets management.
- Support cybersecurity incident response activities and perform root-cause analysis related to application security incidents.
- Maintain architecture documentation, security risk registers, exception documentation, remediation plans, standards, and security patterns.
- Communicate complex security risks, technical tradeoffs, and recommended solutions to technical and non-technical stakeholders.
- Work collaboratively with application development, enterprise architecture, cybersecurity, infrastructure, data, and project teams.
Responsibilities:
- Define and maintain application security architecture principles, standards, patterns, and reference implementations.
- Conduct architecture and design reviews for applications, platforms, integrations, APIs, and cloud solutions.
- Perform threat modeling and identify application, infrastructure, data, and identity-related security risks.
- Define security requirements for authentication, authorization, encryption, secrets, logging, privacy, APIs, and data protection.
- Support secure coding practices and security reviews across Java, .NET, JavaScript, TypeScript, and Python applications.
- Integrate security controls into CI/CD pipelines and DevSecOps processes.
- Evaluate and implement application security testing and monitoring tools.
- Support vulnerability identification, prioritization, remediation, and risk acceptance.
- Establish secure identity and access-management patterns using modern authentication and authorization technologies.
- Design security controls for Azure, cloud-native workloads, containers, Kubernetes, serverless applications, and enterprise platforms.
- Support data protection and privacy requirements across structured, unstructured, and spatial data.
- Develop and maintain architecture diagrams, security standards, risk assessments, exception documentation, and remediation plans.
- Support incident response and root-cause analysis for application security issues.
- Evaluate third-party, open-source, and SaaS security risks.
- Provide guidance to development and architecture teams on secure application design and implementation.
- Ensure application security practices align with applicable VDOT, Commonwealth of Virginia, VITA, and organizational security requirements.
Requirements
Minimum Qualifications:- Bachelor's degree in Computer Science, Cybersecurity, Engineering, a related field, or equivalent practical experience.
- 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including experience designing and implementing security architecture.
- 6+ years of experience designing and implementing security architecture for IT systems, including end-to-end security architectures for data at rest, data in transit, and data in use.
- 6+ years of experience applying secure software development principles and addressing application security risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
- 6+ years of experience with Microsoft technology environments, including Azure, Microsoft 365/O365, Power Platform, and Dynamics 365, as well as automated data classification, Microsoft Purview, encryption, DLP, and DPIAs.
- 6+ years of experience with threat modeling and security architecture reviews.
- 6+ years of experience with APIs, web applications, distributed systems, cloud environments, CI/CD, and container workloads.
- 6+ years of experience with identity and authentication technologies, including OAuth2, OIDC, SAML, JWT, authorization, PKI/TLS, encryption, and secrets management.
- 10+ years of experience producing architecture diagrams, standards, risk assessments, remediation plans, and other technical documentation.
- Experience implementing granular access controls, including RBAC, Row-Level Security, Column-Level Encryption, dynamic masking, and centralized database audit/activity monitoring aligned with VITA SEC 530.
- Experience with secure coding practices in Java, .NET, JavaScript, TypeScript, and Python.
- Ability to explain technical security risks, business impacts, and architectural tradeoffs to technical and non-technical stakeholders.
- Strong written and verbal communication skills.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
- 6+ years of experience working in regulated environments such as financial services, healthcare, government, or payments.
- 6+ years of experience with penetration testing and translating findings into architectural improvements.
- 4+ years of experience developing or supporting DevSecOps programs and security automation at scale.
- 4+ years of experience with privacy engineering, data classification, and compliance frameworks.
- 2+ years of experience designing or implementing Esri ArcGIS security architectures.
- Experience with certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security, or relevant vendor certifications.
Benefits
Compensation:
- Pay Rate: $81–$101/hour.
Schedule:
- Full-time contract assignment.
- Hybrid work arrangement.
- Initial 90-day probationary period requires onsite work 4 days per week.
- After successful completion of the initial 90-day probationary period, the onsite requirement may be reduced.
- Some weekly onsite presence will continue after the probationary period.
- Candidates must be able to meet the required onsite schedule.
Work Location:
- Richmond, VA.
Vacancy posted 23 days ago
Similar jobs that could be interesting for youBased on the VDOT Application Security Architect in Richmond, VA vacancy
- ...Job Description Job Description Position: VDOT Application Security Architect Location : 1221 E. Broad St.Richmond, VA Interview : Both Web Cam and In Person Interview Job : Hybrid *Local candidates only please *Candidate must be able to work onsite...SuggestedLocal areaTrial period
$81 - $101 per hour
...Job Description Job Description Job Title: VDOT Application Security Architect Work Type: Hybrid Location: Richmond, VA Salary: $81–$101/hour Start Date: September 21, 2026 End Date: June 30, 2027 Industry Category: Information Technology /...SuggestedPermanent employmentFull timeContract workLocal area$90 - $95 per hour
Security Architect Pay Range: $90.00hr - $95.00hr Requirement/Must Have: Software engineering, application security, security engineering, or related technical roles. Experience in designing and implementing security architecture for IT systems. Secure software-development...Suggested- DataStaff, Inc is in need of an IT Security Architect for a long-term contract opportunity with one... ...serve the leadership in the domains of Application, Data and Technology Security through... ...Security Architect (Hybrid or Virtual) VDOT IT Security Architect 4 - Hybrid in Richmond...SuggestedLong term contractContract workWork at officeLocal areaRemote work
$218.4k - $365.2k
...Agentforce is the future of AI, and you are the future of Salesforce.Applications will be accepted until 10/12/2026.The Experience:We are seeking a Principal Federal Compliance & Security Architect to serve as a key customer-facing technical leader for our federal platform...SuggestedPermanent employmentFull timeWork at officeRemote work$143k - $238.4k
...today, we want to hear from you.Lead Cyber Security ArchitectLocation: Richmond, VA, USA -... ...The OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role... ...Leadership, audit/compliance, product and application owners, infrastructure, and security engineering...Full time- ...Experience designing and developing web based applications using C#, .NET Core, HTML, CSS,... ...presentation experience. ~7 Years - Design and architect DVS Business applications. ~7 Years... ...and QA teams to ensure the use of secure coding practices and verification...
- ...McKesson is seeking a Lead Cyber Security Architect in Richmond, VA to establish and evolve MMS security architecture, patterns, and guardrails across cloud, network, identity, endpoint, and data protection. You will collaborate with CISO and senior leaders to drive secure...
- ...using Metadata API, ChangeSet and Ant.Best Practices understanding on Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementationsExperience on Force.com Integration Technologies (WebServices, 3rd Party tool like CastIron/Boomi) to Integrate...Permanent employmentFull timeH1bFlexible hours
- ...expert and in Microsoft Power Apps and Power Automate within the VDOT Office of Strategic Innovation (OSI). This role is essential... ...OSI to leverage Microsoft's Power Platform tools for creating applications and developing automated workflows. The ideal candidate will have...Work at office
- ...United States | Posted on 10/01/2026 Actual Job Title 804810 - VDOT Technical Lead (.Net/SQL) Programmer Analyst 4 Job Type FT... ...Support compliance requirements including PCI,retention rules, and secure data handling. Operate effectively within delivery workflowsand...Contract workLocal area
- ...and define/refine a governance approach for the platform's use at VDOT.Participate in Agile SDLCSkill Required / DesiredIT experience... ...Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and...
- ...Month long (Extendable)Mandatory Technical /Functional Skills• Experience with iOS and Objective C • 2+ years experience in mobile application development • Fundamentals in object-oriented design, data structures, algorithm design, problem solving, and complexity analysis...Work at office
$78.4k - $130k
...and internal product lines. • Work from specifications with limited guidance to design and modify moderately complex software applications, tools, and utilities. • Apply software design theories, engineering principles, and scientific methods to create robust, maintainable...Local areaRemote work- ...Description Job Description Job Title: Salesforce Technical Architect Financial Services Cloud Location: Onsite Virginia Type:... ...design in a digital banking environment, ensuring scalable and secure Salesforce implementations. Key Requirements: 20+ years of...Contract work
- ...out of Richmond, VA. Responsibilities: VDOT-AMD is seeking a Developer with Strong Oral... ...and at least 10 yrs or more .NET Web application development. Experience and fluency with... ...middleware, C#, Web API Design, Development and Security, Blazor, JavaScript including frameworks...Contract work3 days per week
- ...Maryland, Michigan, Mississippi, Missouri, North Carolina, Ohio, South Carolina, Tennessee, Texas, Virginia, or West Virginia*** The Applications Analyst-Staff manages or performs work associated with analysis, design, implementation, operation, deployment, and support of...
- ...exceptions The contractor will be responsible for purchasing parking through the VDOT Parking Management Office or procuring their own parking VDOT is seeking a senior .Net Applications Developer who will be responsible for analyzing complex software requirements to design...For contractorsWork at officeLocal area
- ...If you are unable to complete this application due to a disability, contact this employer... ...application process. Infrastructure Solutions Architect – Richmond, VA Contract Falls Church... ..., data exchange standards, APIs, security models, and cloud adoption strategies....Contract work
$105.09k
Agency: U.S. CourtsDepartment: Judicial BranchSub agency: United States Bankruptcy Court for the Eastern District of VirginiaSalary: Starting at $105,090 Per year (CL 30)Dates: Open 06/05/2026 to 06/04/2027Schedule: Full-timeWork type: PermanentRelocation: FalsePosition...$178.5k - $297.5k
...architecture review board reviews and provide architectural guidance for enterprise technology initiatives.Partner with application, infrastructure, security, cloud, and operations teams to evaluate solution designs and technology decisions.Identify architectural,...Full time- ...BA, QA, DevOps, Cloud, and CAB teams for cohesive delivery. Support compliance requirements including PCI, retention rules, and secure data handling. Operate effectively within delivery workflows and agile components as needed. Deliverables & Success Metrics...Long term contract
$117.24 per hour
...Title: DMAS - Infrastructure Solutions Architect 3 Work Type: Hybrid Location:... ...technical implementation, integration, security, cloud adoption, and enterprise architecture... ...Maximum Vendor Rate: $117.24/hr Application: Qualified candidates should have extensive...Hourly payContract workFor contractors2 days per week- ...The candidate will work closely with IT architects, product teams, infrastructure... ...collaboration with architects. Ensure the security, performance, and reliability of AI solutions... ...experience in Generative AI or AI/ML application development. ~2+ years of experience...Full timeRemote work
$85 - $90 per hour
...Proficiency in architectural modeling, data management concepts, and security best practices. Considerable experience with cloud... ...compliance with NIST, HIPAA, state security policies, and other applicable controls. Participate in governance processes, review change...Temporary workLocal area$86.8k - $198k
...considerable direction.You Have: Experience using Microsoft Office applications and presentation toolsKnowledge of enterprise architecture,... ...: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for...Full timeContract workPart timeWork at officeLocal areaRemote work$140k
...standards, best practices, and reusable accelerators Mentor architects and developers through architecture reviews, communities of... ...Salesforce certifications such as Platform Developer, Administrator, Application Architect, or System Architect OmniStudio certifications...Work at officeRemote workFlexible hours$128.74k
Agency: U.S. Postal ServiceDepartment: Other Agencies and Independent OrganizationsSalary: Starting at $128,740 Per year (WE 4)Dates: Open 09/08/2026 to 10/08/2026Schedule: Full-timeWork type: PermanentRelocation: FalsePosition ID: DE-13055767-26-LLODocument ID: 8837470...- Job ID: z5G7h3l6a1kMvyS65NP3cxXweLlxdXmmzZRf80S9Bsk=Job Code: ATS #54122Location: Richmond, VA, 23218, United StatesTitle: MMIS Systems AnalystLocation: Richmond, VA 23219-(Hybrid)Interview: Virtual and In-PersonWe are seeking a highly skilled Systems Analyst with strong...
- ...Project Overview: Data Platform Engineering enables reliable, secure, scalable, and cost-effective data platforms that support... ...capabilities. This individual works with platform leaders, owners, architects, engineers, and stakeholders to translate business strategy into...Full timeContract workTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to VDOT Application Security Architect. Be the first to apply!
Related searches
- .net software architects (remote) Richmond, VA
- cash applications coordinator Richmond, VA
- applications consultant Richmond, VA
- paper application Richmond, VA
- senior application security Richmond, VA
- application security lead Richmond, VA
- app Richmond, VA
- director enterprise applications Richmond, VA
- application scientist Richmond, VA
- director application development Richmond, VA




