Application Security Architect
Accylerate
Ideal Candidate Profile: Seeking an Application Security Architect with strong experience across software engineering, application security, or security engineering, including hands-on experience designing and reviewing secure application architectures to define, embed, and oversee application security strategies across enterprise IT initiatives.This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns.Strong background in SSDLC, threat modeling, OWASP risks, API/web security, cloud-native environments, CI/CD, containers, identity and access management, and DevSecOps practices. The ideal candidate should have experience securing and governing data across platforms such as Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS, with knowledge of encryption, RBAC, data classification, DLP, auditing, and privacy controls. Strong communication skills are required to translate security risks into practical architectural standards, remediation plans, and solutions for technical and nontechnical stakeholders.
Job Duties & Responsibilities
Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Skills & Experience
Bachelor's degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
Demonstrated experience with threat modeling and security architecture reviews.
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
Experience in a regulated environment such as financial services, healthcare, government, or payments.
Experience implementing DevSecOps programs and security automation at scale.
Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Job Duties & Responsibilities
Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Skills & Experience
Bachelor's degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
Demonstrated experience with threat modeling and security architecture reviews.
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
Experience in a regulated environment such as financial services, healthcare, government, or payments.
Experience implementing DevSecOps programs and security automation at scale.
Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the Application Security Architect in Richmond, VA vacancy
$90 - $95 per hour
...Security Architect Pay Range: $90.00hr - $95.00hr Requirement/Must Have: Software engineering, application security, security engineering, or related technical roles. Experience in designing and implementing security architecture for IT systems. Secure...Suggested- ...Application Security Architect The Commonwealth of Virginia in Richmond, VA is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives. This role will be responsible for the solution of...Suggested
- ...Application Security Architect Client is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives. This role will be responsible for the solution of Secure Software Development Lifecycle...Suggested
- ...Title/Role: Application Security Architect Worksite address: Richmond, VA Interview Type: Both Web Cam and In Person Interview Work Arrangement: Hybrid *Local candidates only please *Candidate must be able to work onsite 4 days/week during an initial...SuggestedLocal areaTrial period
$141.2k - $278.3k
...Summary Google Infrastructure and Security Lead ArchitectJoin our AI & Engineering... ...(GCP) Infrastructure & Security Lead Architect, you will serve as a strategic technical... ...networking topologies to guiding application migration strategies. A critical component...SuggestedLocal areaVisa sponsorshipFlexible hours$143k - $238.4k
...today, we want to hear from you.Lead Cyber Security ArchitectLocation: Richmond, VA, USA -... ...The OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role... ...Leadership, audit/compliance, product and application owners, infrastructure, and security engineering...Full time$105 - $175.58 per hour
...Agentforce is the future of AI, and you are the future of Salesforce.Applications will be accepted until 10/12/2026.The Experience:We are seeking a Principal Federal Compliance & Security Architect to serve as the chief technical authority for our federal platform footprint...Permanent employmentFull timeWork at officeRemote work- ...Job Title: .NET Application Architect Location: Richmond, VA Schedule: First Month 100% onsite then Hybrid Job Overview: We... ...projects with business and IT strategy. Ensure the use of secure coding practices and verification methods. Develop...Local area
- ...using Metadata API, ChangeSet and Ant.Best Practices understanding on Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementationsExperience on Force.com Integration Technologies (WebServices, 3rd Party tool like CastIron/Boomi) to Integrate...Permanent employmentFull timeH1bFlexible hours
- ...Month long (Extendable)Mandatory Technical /Functional Skills• Experience with iOS and Objective C • 2+ years experience in mobile application development • Fundamentals in object-oriented design, data structures, algorithm design, problem solving, and complexity analysis...Work at office
$110k
...vehicles seamlessly. As a React Native Engineer, you will play a key role in developing high-quality, scalable, and performant mobile applications used by millions of customers globally. You will collaborate closely with product managers, designers, backend engineers, and...Work experience placementWorldwideFlexible hours$150k - $200k
...forward-thinking, experienced Software Architect to lead the ongoing architecture and evolution... ...eCommerce platform is robust, scalable, secure, and positioned for innovation. This... ...and end users to identify and analyze application requirements. Design, develop,...Full timeWork experience placementRemote workWorldwideFlexible hours- ...architectural standards, best practices, and reusable acceleratorsMentor architects and developers through architecture reviews, communities of... ...certifications such as Platform Developer, Administrator, Application Architect, or System ArchitectOmniStudio certifications or...Work at officeRemote workVisa sponsorshipWork visaFlexible hours
- ...Description Job Description Job Title: Salesforce Technical Architect Financial Services Cloud Location: Onsite Virginia Type:... ...design in a digital banking environment, ensuring scalable and secure Salesforce implementations. Key Requirements: 20+ years of...Contract work
$105.09k
Agency: U.S. CourtsDepartment: Judicial BranchSub agency: United States Bankruptcy Court for the Eastern District of VirginiaSalary: Starting at $105,090 Per year (CL 30)Dates: Open 06/05/2026 to 06/04/2027Schedule: Full-timeWork type: PermanentRelocation: FalsePosition...- ...and platform needs in partnership with senior engineers and Architects Consistently share best practices and improve processes within... ...not apply) At least 2 years of experience building iOS applications At least 2 years of experience with Swift At least 1 year...InternshipLocal area
- ...~ Location: 100% Remote. -Security Architect - Consultant 9309 . Employment Type: W2 Only (No Subcontractors)Contract Duration: 12... ...including: NIST, CSF, CJIS, IRS 1075, CMS MARS-E Knowledge of application security (APPSEC) Certification CISSP, CISA, CISO or...Contract workWork experience placementFor subcontractorRemote work
$128.74k
Agency: U.S. Postal ServiceDepartment: Other Agencies and Independent OrganizationsSalary: Starting at $128,740 Per year (WE 4)Dates: Open 09/08/2026 to 10/08/2026Schedule: Full-timeWork type: PermanentRelocation: FalsePosition ID: DE-13055767-26-LLODocument ID: 8837470...$139.3k - $250.7k
...group that works on various technologies to architect, design, build, scale and maintain... ...digital world work faster and stay more secure, making the internet a better experience... ...brings to the workplace. All qualified applicants will receive consideration for employment...Work experience placementWork at office$178.5k - $297.5k
...architecture review board reviews and provide architectural guidance for enterprise technology initiatives.Partner with application, infrastructure, security, cloud, and operations teams to evaluate solution designs and technology decisions.Identify architectural,...Full time- Job ID: ATS #54122Reference: 51042Location: Richmond, VA, 23218, United StatesTitle: MMIS Systems AnalystLocation: Richmond, VA 23219-(Hybrid)Interview: Virtual and In-PersonWe are seeking a highly skilled Systems Analyst with strong technical and analytical expertise in...
- ...Seeking an Infrastructure Solutions Architect to design secure, scalable solutions aligned with enterprise standards, partnering with OIM and... ...collaborates with infrastructure teams, cloud engineers, application developers, security, data teams, and enterprise architects...Work at office
- ...Network Solutions Architect This individual will work with key members focusing on strategic planning, design,... ...be configured in such a way that all end users can securely and efficiently access the applications, data, and tools, this also involves implementing the...Remote work
- ...requirement. Infrastructure Solutions Architect – Azure / AWS / GCP Location: Richmond... ...design and guide the implementation of secure, scalable, resilient, and supportable... ...work closely with infrastructure, cloud, application development, security, data, and enterprise...Work at officeLocal areaWork visa
$135.2k - $306.4k
...Job Description Senior / Principal Software Engineer or Architect Database Engine, Search & Document Systems We are looking... ...indexing, pipelines, and production infrastructure for intelligent applications. What You Could Work On Depending on your background...Temporary workFlexible hours$55k - $70k
...support of VEDP’s business attraction and expansion efforts to secure decisions for Virginia. It is a highly collaborative position requiring... ...knowledge of Excel and PowerPoint Highly competitive applicants will also have one or several of the following: Ability to...InternshipLocal area- Data Warehouse/BI Developer Supplement division staff by executing existing metric procedures for statutory and ad hoc reporting as well as data discrepancy assessment and resolution. Develop?end-to-end automation framework and documentation to load data and query...Work experience placement
- ...vital records related projects. Virginia Vital Events and Screening Tracking System (VVESTS) is developed in Oracle Application Express (APEX), a secure, low-code development platform used to build scalable enterprise applications. VVESTS supports mission-critical...
- ...Office of Strategic Innovation (OSI). This role is essential for OSI to leverage Microsoft's Power Platform tools for creating applications and developing automated workflows. The ideal candidate will have extensive knowledge of these tools and experience in building...Work at office
$70 - $80 per hour
...Applications Analyst With Epic Willow ExpertiseAn innovative healthcare organization is seeking an experienced Applications Analyst with Epic Willow expertise to support pharmacy-related systems and initiatives. This role focuses on optimizing EHR applications and delivering...Hourly payRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Architect. Be the first to apply!
Related searches
- software architect Richmond, VA
- application architect Richmond, VA
- .net software architects (remote) Richmond, VA
- security architect Richmond, VA
- cyber security architect Richmond, VA
- cash app Richmond, VA
- now accepting applications Richmond, VA
- paper application Richmond, VA
- vice president of application development Richmond, VA
- application scientist Richmond, VA



