Application Security Architect
Integrated Resources
Job Title: Application Security Architect
Location: Richmond, VA (Hybrid 4 days onsite)
Duration : 6 months Contract (High possibility of extension)
Interview mode : Both Web Cam and In Person Interview Job Summary:
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs, and ensure compliance with Commonwealth and Client security standards.
Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
C ore responsibilities
Skill Matrix: Skill Required Amount of Experience Experience Software engineering, application security, security engineering, or related technical roles Required 10 Years Experience in designing and implementing security architecture for IT systems Required 6 Years Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse Required 6 Years Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) Required 6 Years Demonstrated experience with threat modeling and security architecture reviews Required 6 Years Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads Required 6 Years Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and Products-management practices Required 6 Years Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans Required 10 Years Experience in a regulated environment such as financial services, healthcare, government, or payments Highly desired 6 Years Experience conducting or coordinating penetration testing and translating results into durable architectural improvements Highly desired 6 Years Experience implementing DevSecOps programs and security automation at scale Highly desired 4 Years Familiarity with privacy engineering, data classification, and compliance frameworks Highly desired 4 Years Experience with security architectures in Esri's ArcGIS platform Highly desired 2 Years
Location: Richmond, VA (Hybrid 4 days onsite)
Duration : 6 months Contract (High possibility of extension)
Interview mode : Both Web Cam and In Person Interview Job Summary:
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs, and ensure compliance with Commonwealth and Client security standards.
Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
C ore responsibilities
- Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
- Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
- Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
- Establish repeatable security requirements for authentication, authorization, session management, encryption, Products management, logging, privacy, API protection, and data protection.
- Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
- Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, Product scanning, and runtime protection.
- Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
- Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
- Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
- Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and Products storage.
- Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
- Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
- Bachelor's degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
- 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
- Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
- Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
- Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with Client SEC 530 security standards.
- Demonstrated experience with threat modeling and security architecture reviews.
- Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
- Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
- Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and Products-management practices.
- Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
- Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
- Experience in a regulated environment such as financial services, healthcare, government, or payments.
- Experience implementing DevSecOps programs and security automation at scale.
- Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
- Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
- Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Skill Matrix: Skill Required Amount of Experience Experience Software engineering, application security, security engineering, or related technical roles Required 10 Years Experience in designing and implementing security architecture for IT systems Required 6 Years Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse Required 6 Years Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) Required 6 Years Demonstrated experience with threat modeling and security architecture reviews Required 6 Years Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads Required 6 Years Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and Products-management practices Required 6 Years Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans Required 10 Years Experience in a regulated environment such as financial services, healthcare, government, or payments Highly desired 6 Years Experience conducting or coordinating penetration testing and translating results into durable architectural improvements Highly desired 6 Years Experience implementing DevSecOps programs and security automation at scale Highly desired 4 Years Familiarity with privacy engineering, data classification, and compliance frameworks Highly desired 4 Years Experience with security architectures in Esri's ArcGIS platform Highly desired 2 Years
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Application Security Architect in Richmond, VA vacancy
- ...Engagement Type Contract Core responsibilities Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems. Perform architecture and design...SuggestedContract work
- ...Job Title: Application Security Architect Location: Richmond, VA Type: W2 Contract ***Only qualified Senior Application Security Architect Cloud Azure & DevSecOps located in the Richmond, VA area will be considered due to the position requiring an onsite presence...SuggestedContract work
- ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Application Security Architect Location(s): Richmond, VA (Hybrid: 4 days/week on site) Description Seeking an Application Security Architect...SuggestedLocal areaTrial period
- ...reduced onsite commitment; however, some onsite presence will continue to be required weekly. Key Responsibilities Define application security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice,...SuggestedLocal area
- ...Job Title: Application Security Architect Duration: 6-12+ months Final onsite Interview ~10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for...Suggested
$60 - $80 per hour
...Job Title: Application Security Architect (Hybrid) Duration (Contract): 9 Months Client Location: Richmond, VA 23219 Location Preference: Hybrid Job Description: As an Application Security Architect , you will lead the design and implementation...Hourly payContract work- ...Title/Role: Application Security Architect Worksite address: Richmond, VA Interview Type: Both Web Cam and In Person Interview Work Arrangement: Hybrid *Local candidates only please *Candidate must be able to work onsite 4 days/week during an initial...Local areaTrial period
- ...IT Security Architect Richmond, VA - Hybrid Need local to VA candidates only. ABOUT THE ROLE This position is for the remediation of the existing SSP and baseline backlog of submitting new requests Ensure that the Commonwealth of Virginia's security...Local area
$143k - $238.4k
...today, we want to hear from you.Lead Cyber Security ArchitectLocation: Richmond, VA, USA -... ...The OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role... ...Leadership, audit/compliance, product and application owners, infrastructure, and security engineering...Full time$143.25k - $179.04k
...opportunity at OD. As the Cybersecurity Architect at Old Dominion Freight Line, you will... ..., provide expert guidance on technical security solutions, and ensure the effective... ...emerging technologies, systems, and software applications to ensure they meet security standards...Full timeTemporary workWork experience placementLocal areaImmediate startShift workDay shift- DataStaff, Inc is in need of an IT Security Architect for a long-term contract opportunity with one of our direct clients located in Richmond... ...Architect to serve the leadership in the domains of Application, Data and Technology Security through the development of architecture...Long term contractContract workWork at officeLocal areaRemote work
- Job Title:.NET Application Architect Location: Richmond, VA Schedule: First Month 100% onsite then Hybrid Job Overview We are seeking a highly... ...Align projects with business and IT strategy. Ensure the use of secure coding practices and verification methods. Develop product...
- ...using Metadata API, ChangeSet and Ant.Best Practices understanding on Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementationsExperience on Force.com Integration Technologies (WebServices, 3rd Party tool like CastIron/Boomi) to Integrate...Permanent employmentFull timeH1bFlexible hours
- ...Month long (Extendable)Mandatory Technical /Functional Skills• Experience with iOS and Objective C • 2+ years experience in mobile application development • Fundamentals in object-oriented design, data structures, algorithm design, problem solving, and complexity analysis...Work at office
- ...Description Job Description Job Title: Salesforce Technical Architect Financial Services Cloud Location: Onsite Virginia Type:... ...design in a digital banking environment, ensuring scalable and secure Salesforce implementations. Key Requirements: 20+ years of...Contract work
- ...~ Location: 100% Remote. -Security Architect - Consultant 9309 . Employment Type: W2 Only (No Subcontractors)Contract Duration: 12... ...including: NIST, CSF, CJIS, IRS 1075, CMS MARS-E Knowledge of application security (APPSEC) Certification CISSP, CISA, CISO or...Contract workWork experience placementFor subcontractorRemote work
- ...architectural standards, best practices, and reusable acceleratorsMentor architects and developers through architecture reviews, communities of... ...certifications such as Platform Developer, Administrator, Application Architect, or System ArchitectOmniStudio certifications or...Work at officeRemote workVisa sponsorshipWork visaFlexible hours
$166.4k - $197.6k
...Position Title: Infrastructure Solutions Architect Location: Richmond, VA (Hybrid)... ...interfaces, data exchange standards, APIs, security models, and cloud adoption strategies.... ...HIPAA, state security policies, and other applicable controls. Participate in governance processes...Contract work$117.24 per hour
...Title: DMAS - Infrastructure Solutions Architect 3 Work Type: Hybrid Location:... ...technical implementation, integration, security, cloud adoption, and enterprise architecture... ...Maximum Vendor Rate: $117.24/hr Application: Qualified candidates should have extensive...Hourly payContract workFor contractors2 days per week- ...requirement. Infrastructure Solutions Architect – Azure / AWS / GCP Location: Richmond... ...design and guide the implementation of secure, scalable, resilient, and supportable... ...work closely with infrastructure, cloud, application development, security, data, and enterprise...Work at officeLocal areaWork visa
$85 - $90 per hour
...Proficiency in architectural modeling, data management concepts, and security best practices. Considerable experience with cloud... ...compliance with NIST, HIPAA, state security policies, and other applicable controls. Participate in governance processes, review change...Temporary workLocal area- ...Seeking an Infrastructure Solutions Architect to design secure, scalable solutions aligned with enterprise standards, partnering with OIM and... ...collaborates with infrastructure teams, cloud engineers, application developers, security, data teams, and enterprise architects...Work at office
- ...an experienced Infrastructure Solutions Architect to provide technical leadership for a... ...governance, system integration, cloud adoption, security, and modernization initiatives. The... ...teams to ensure solutions align with applicable security, privacy, and compliance...
$90.48 per hour
...Description Job Title: Infrastructure Solutions Architect Work Type: Onsite Location:... ...role will evaluate, design, and guide secure, scalable, interoperable, and... ...with enterprise architecture standards. Application: Candidates should have strong experience...Contract work- ...architectures (Azure, AWS, hybrid). Develop and execute network consolidation strategies across multiple environments and business units. Architect secure, scalable connectivity patterns including: Site-to-site and client VPNs, SD-WAN deployments, Cloud transit hubs and hub/spoke...
$178.5k - $297.5k
...architecture review board reviews and provide architectural guidance for enterprise technology initiatives.Partner with application, infrastructure, security, cloud, and operations teams to evaluate solution designs and technology decisions.Identify architectural,...Full time- Job Description Job Description Schedule: Mon-Fri 7:30am-4:30pm (1 hr lunch) Summary: Responsible for assisting with operational maintenance, troubleshooting, diagnostics, housekeeping, and repairs on commercial/industrial buildings, industrial systems, grounds...Part timeLocal areaFlexible hoursNight shiftWeekend work
$139.3k - $250.7k
...group that works on various technologies to architect, design, build, scale and maintain... ...digital world work faster and stay more secure, making the internet a better experience... ...brings to the workplace. All qualified applicants will receive consideration for employment...Work experience placementWork at office- ...VDOT's Information Technology Division seeks a Network Architect to join the Enterprise Architecture team. This role... ...Network Architect will configure network systems to enable secure, efficient user access to applications and data while adhering to security standards....Remote work
- ...Network Solutions Architect This individual will work with key members focusing on strategic planning, design,... ...be configured in such a way that all end users can securely and efficiently access the applications, data, and tools, this also involves implementing the...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Architect. Be the first to apply!
Related searches
- .net software architects (remote) Richmond, VA
- software architect Richmond, VA
- application architect Richmond, VA
- security architect Richmond, VA
- cyber security architect Richmond, VA
- application scientist Richmond, VA
- director enterprise applications Richmond, VA
- now accepting applications Richmond, VA
- cash application clerk Richmond, VA
- application security lead Richmond, VA


