Security Analytics Architect
Openkyber
Hello, Greetings from OpenKyber..! Jobtitle: Security Analytics Architect
Location: Richmond VA
Client: State of Virginia
- Local candidates only please
- Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; possibility of reduced onsite commitment after probation, though some onsite presence will continue weekly.
Seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives. Responsible for Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem including web applications, AI solutions, cloud-native solutions, GIS platforms, low-code and no-code patterns. Lead data protection strategy, data governance frameworks, and privacy posture across state-wide transportation. Define handling of structured, unstructured, and spatial data classification, encryption, storage, and access across cloud data platforms. Support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
Bachelor's degree in computer science, cybersecurity, engineering, or related field (or equivalent experience) required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials highly desired.
Core responsibilities:- Define application-security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
- Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
- Lead threat modeling for new apps, features, integrations, and high-risk changes.
- Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API and data protection.
- Partner with engineers to integrate security into SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, approvals, and monitoring.
- Evaluate security tools SAST, DAST, composition analysis, container scanning, API security testing, secrets scanning, runtime protection.
- Define vulnerability-management for applications and dependencies including severity, remediation SLAs, exceptions, and verification.
- Assess 3rd-party libraries, open-source dependencies, SaaS integrations, and vendor components for security risk.
- Design identity and access-control patterns including least privilege, MFA/SSO, service authentication, RBAC/ABAC, and privileged access.
- Work with cloud and platform teams to secure hosting environments, Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, secrets store.
- Advise incident-response teams on application-layer threats and contribute to root-cause analysis and improvements.
- Maintain architecture documentation, decision patterns, risk registers, and exceptions.
- Bachelor's degree or equivalent experience.
- 10+ years in software engineering, application security or related, including 2+ years security architecture design.
- Strong understanding of secure software principles and common risks including OWASP Top 10, insecure auth, injection, deserialization, API abuse.
- Implement security for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS using classification, encryption, DLP, privacy risk (DPIAs).
- Enforce granular access controls (RBAC, row/column encryption, dynamic masking) and centralized audit logging per VITA SEC 530.
- Experience in threat modeling and security architecture reviews.
- Secure APIs, web applications, distributed systems, cloud, CI/CD pipelines, container workloads.
- Secure coding knowledge in Java, .NET, JavaScript/TypeScript, Python.
- Identity and auth technologies OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, secrets management.
- Ability to communicate technical risks to varied stakeholders.
- Strong written communication including diagrams, standards, risk assessments, and remediation plans.
- Experience in regulated environments finance, healthcare, government or payments.
- Experience DevSecOps programs and security automation at scale.
- Familiarity with privacy engineering, data classification, compliance frameworks.
- Certifications CISSP, CSSLP, CCSP, GIAC, cloud-security or vendor credentials.
- Experience with penetration testing and translating findings into security improvements.
For applications and inquiries, contact:View email address on us.fitly.work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analytics Architect. Be the first to apply!
