Application Security Architect
Talent Portus
Location: Richmond, Virginia
Duration: 10 Months
Work Arrangement: Hybrid
Interview: Web Cam + In-Person
Local Candidates Only Work Arrangement
The selected candidate must be able to work onsite 4 days per week during the initial 90-day probationary period . Following successful completion of the probationary period, there may be an opportunity for a reduced onsite schedule; however, some weekly onsite presence will continue to be required.
Position OverviewWe are seeking an experienced Application Security Architect to define, implement, and oversee application security strategies across enterprise IT initiatives.
The Application Security Architect will establish and mature Secure Software Development Lifecycle (SSDLC) practices across a hybrid technology ecosystem that includes complex web applications, APIs, microservices, cloud-native solutions, AI-enabled applications, enterprise GIS platforms, and low-code/no-code technologies.
This role will also lead data protection, data governance, privacy, and security architecture initiatives. The successful candidate will define how structured, unstructured, and spatial/GIS data are classified, encrypted, stored, accessed, monitored, and protected across enterprise cloud and data platforms.
The architect will partner closely with application development, infrastructure, cloud, data, and cybersecurity teams to conduct threat modeling, perform secure architecture reviews, establish security standards, and ensure applications and platforms follow applicable security and compliance requirements.
Core Responsibilities-
Define application security architecture principles, standards, patterns, reference architectures, and security guardrails for web, mobile, API, microservice, and cloud-native applications.
-
Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, risks, and appropriate compensating controls.
-
Lead and facilitate threat-modeling activities for new applications, major features, integrations, and high-risk technology changes.
-
Establish repeatable security requirements covering authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data security.
-
Partner with software engineering teams to integrate security throughout the SDLC, including secure code reviews, CI/CD pipelines, infrastructure as code, security testing, release approvals, and production monitoring.
-
Evaluate and guide the implementation of security tools and processes, including SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime application protection.
-
Establish and maintain an application vulnerability-management strategy, including severity criteria, remediation SLAs, exception processes, risk acceptance, and verification of remediation.
-
Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security and supply-chain risks.
-
Design identity and access-management patterns incorporating least privilege, MFA, SSO, service-to-service authentication, RBAC, ABAC, and privileged-access controls.
-
Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless platforms, containers, CI/CD infrastructure, cloud IAM, network segmentation, and secrets-management solutions.
-
Define and implement security architectures for data at rest, in transit, and in use across enterprise cloud, database, CRM, productivity, low-code/no-code, and GIS platforms.
-
Establish data classification, encryption, DLP, privacy, and data-protection controls for sensitive enterprise information.
-
Implement granular data-access controls, including RBAC, row-level security, column-level encryption, dynamic data masking, database auditing, and activity monitoring.
-
Establish centralized security logging and monitoring capabilities for applications, databases, APIs, and cloud environments.
-
Advise incident-response teams on application-layer security threats and participate in root-cause analysis following security incidents.
-
Maintain application-security architecture documentation, security decision records, architecture diagrams, risk registers, security standards, and exception documentation.
-
Communicate security risks, architectural tradeoffs, and remediation strategies effectively to engineers, technical leadership, product teams, executives, and nontechnical stakeholders.
-
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
-
10+ years of experience in software engineering, application security, security engineering, or related technical roles.
-
6+ years of experience designing and implementing security architecture for IT systems.
-
6+ years of experience applying secure software-development principles and addressing common application security risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
-
6+ years of experience designing and implementing end-to-end security architectures for data at rest, in transit, and in use across Microsoft technologies such as Azure, Microsoft 365, Power Platform, Dynamics 365, and SQL Server .
-
6+ years of demonstrated experience with threat modeling and security architecture reviews.
-
6+ years of experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
-
Strong understanding of secure coding practices in one or more common technology ecosystems, including Java, .NET, JavaScript/TypeScript, or Python .
-
Strong experience with identity and access-management technologies and protocols, including OAuth 2.0, OpenID Connect, SAML, JWT, RBAC/ABAC, PKI/TLS, encryption, and secrets management .
-
Experience with data classification, encryption, DLP, privacy risk assessments, database security, and data-access controls.
-
Ability to analyze security architecture and identify vulnerabilities, attack paths, trust boundaries, and appropriate mitigation strategies.
-
Strong written and verbal communication skills.
-
Ability to create and maintain architecture diagrams, security standards, risk assessments, security documentation, and actionable remediation plans.
-
Ability to communicate complex technical security risks and tradeoffs to both technical and nontechnical stakeholders.
-
Experience working in regulated environments such as financial services, healthcare, government, insurance, or payments .
-
Experience implementing DevSecOps programs and security automation at scale .
-
Familiarity with privacy engineering, data classification, data governance, and compliance frameworks.
-
Experience with security architecture and security controls within Esri ArcGIS or other enterprise GIS platforms.
-
Experience conducting or coordinating penetration testing and translating findings into sustainable architectural and security improvements.
-
Experience with cloud-security architecture and security automation.
-
Certifications such as CISSP, CSSLP, CCSP, GIAC , or relevant cloud/vendor security certifications.
Skill Required / Desired Minimum Experience
| Software engineering, application security, security engineering, or related technical roles | Required | 10 Years |
| Designing and implementing security architecture for IT systems | Required | 6 Years |
| Secure software-development principles and application risks, including OWASP Top 10, authorization, injection, deserialization, and API abuse | Required | 6 Years |
| End-to-end security architecture across Azure, Microsoft 365, Power Platform, Dynamics 365, and SQL Server | Required | 6 Years |
| Threat modeling and security architecture reviews | Required | 6 Years |
| Securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads | Required | 6 Years |
| Identity, OAuth 2.0, OpenID Connect, SAML, JWT, authorization, PKI/TLS, encryption, and secrets management | Required | 6 Years |
| Security architecture documentation, diagrams, standards, risk assessments, and remediation plans | Required | 10 Years |
| Experience in regulated environments such as financial services, healthcare, government, or payments | Highly Desired | 6 Years |
| Penetration testing coordination and translating findings into architectural improvements | Highly Desired | 6 Years |
| DevSecOps programs and security automation at scale | Highly Desired | 4 Years |
| Privacy engineering, data classification, and compliance frameworks | Highly Desired | 4 Years |
| Security architecture experience with Esri ArcGIS or enterprise GIS platforms | Highly Desired | 2 Years |
- ...Title/Role: Application Security Architect Worksite address: Richmond, VA Interview Type: Both Web Cam and In Person Interview Work Arrangement: Hybrid *Local candidates only please *Candidate must be able to work onsite 4 days/week during an initial...SuggestedLocal areaTrial period
- Job Title:Application Security Architect Location: Richmond, VA Type: W2 Contract ***Only qualified Senior Application Security Architect Cloud Azure & DevSecOps located in the Richmond, VA area will be considered due to the position requiring an onsite...SuggestedContract work
$60 - $80 per hour
...Job Title: Application Security Architect (Hybrid) Duration (Contract): 9 Months Client Location: Richmond, VA 23219 Location Preference: Hybrid Job Description: As an Application Security Architect , you will lead the design and implementation...SuggestedHourly payContract work$158.05k - $193.33k
...passionate about helping engineering teams ship secure, high-quality software? Do you get... ...and partnering closely with developers, architects, and product teams? If so, we'd love to... ...to you. Alarm.com is looking for an Application Security Architect to join our growing security...SuggestedWork experience placementCasual workWork at officeImmediate start$90 - $95 per hour
Security Architect Pay Range: $90.00hr - $95.00hr Requirement/Must Have: Software engineering, application security, security engineering, or related technical roles. Experience in designing and implementing security architecture for IT systems. Secure software-development...Suggested- ...Corporation is seeking a Principal Software Architect to provide architectural oversight and lead the development of advanced applications for mission-critical government solutions.... ...teams and customer experts to deliver secure, scalable software. #J-18808-Ljbffr Jobleads...
- ...global workforce solutions on behalf of its clients. Artech's deep heritage, proven expertise and insightful market intelligence has secured long-term partnerships with Fortune 500 and government clients seeking world-class professional resources.Artech employs over 7000...Work experience placementShift workNight shift
$99k - $225k
Compliance ISSO and Enterprise Cybersecurity Security ArchitectThe Opportunity: Enterprise... ...You will partner directly with system architects and engineers to evaluate topologies,... ...Commitment to Non-DiscriminationAll qualified applicants will receive consideration for...Full timeContract workPart timeWork at officeLocal areaRemote work- General Dynamics Information Technology is seeking a Network Engineer to design technical solutions and lead security-focused infrastructure projects at the Herndon site. You will interpret requirements, allocate tasks to tech components, and drive implementation with...
- ...work here.NTT DATA Services currently seeks a Information Security Architect/Splunk Subject Matter Expert to join our team in Sterling,... ...automation across a comprehensive portfolio of consulting, applications, infrastructure and business process services.NTT DATA Services...For contractors
$125.8k - $209.7k
...initiatives, the need for robust, scalable security architecture has never been greater.... ...gaps and risks across network, cloud, application, data, and identity domains, and develop... ...such as CISSP, CCSP, SABSA Chartered Architect (SCF/SCM), TOGAF, or other relevant security...Immediate start$185k - $240k
...Dark Wolf Solutions, LLC seeks a DevSecOps Subject Matter Expert to architect, lead, and optimize CI/CD tooling, security paradigms, and observability across the software development lifecycle. You will drive shift-left security, zero-trust architectures, and high-reliability...Shift work$154.05k - $278.48k
...Leidos has an exciting opening for you as our next TS/SCI Security Engineer Solution Architect supporting the creation of an Enterprise AI Platform... ...and DevOpsSec environments Experience with big data applications Experience with Jira and Confluence Experience with...Remote work$86.8k - $198k
Enterprise Security Architect, LeadThe Opportunity: Security must be architected, not bolted on. You understand how to embed security into... ...those designs into practical architectures for network and application deployments. You will advise on security technologies and...Full timeContract workPart timeWork at officeLocal areaRemote work- ...We are seeking a senior Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives at the Virginia Department of Transportation (VDOT) in Richmond, VA. This role establishes Secure Software Development...Contract workRemote work
$218.4k - $365.2k
...Agentforce is the future of AI, and you are the future of Salesforce.Applications will be accepted until 10/12/2026.The Experience:We are seeking a Principal Federal Compliance & Security Architect to serve as the chief technical authority for our federal platform footprint...Permanent employmentFull timeWork at officeRemote work- ...to grow with us. Your Mission TFS is seeking a Sr Cyber Security Architect to research, evaluate, and implement next-generation cyber capabilities... ..., or a related field. · 7-10+ years of related or applicable professional experience with machinery control systems,...
$185k - $195k
GovCIO is currently hiring for a Security Architect to support modernization effort. This position will be located in Hampton, VA on Joint Base Langley-Eustis and will be a fully onsite position.ResponsibilitiesWe are seeking a Security Architect to lead the design and...Currently hiring- ...Position Overview SteerBridge is seeking an experienced Security Architect to support our government contracting initiatives. This role... ...creating a diverse and inclusive workplace where all qualified applicants and employees are treated with respect and dignity—...
- ...we serve. POSITION OVERVIEW SteerBridge is seeking a Security Architect to define the security architecture and compliance strategy... ...leveraging Zscaler (ZTNA/SASE) to broker secure access to applications and infrastructure Design defense-in-depth control frameworks...
$173.46k - $231.98k
...you are the future of Salesforce. We're looking for a Security & Compliance Architect to support sales to the Department of War/Department of... ...communicate how Salesforce's infrastructure, architecture, and application features address them Apply deep knowledge of DOW-...For contractors$173.9k - $290.1k
...initiatives, the need for robust, scalable security architecture has never been greater.... ...leadership-including CISOs, enterprise architects, and technology executives-to evaluate... ...security posture across network, cloud, application, data, and identity domains, facilitate...Immediate start$125k - $175k
Celestar Corporation seeks a Program Security Representative to support the DARPA PSS task order. The role requires active TS/SCI clearance and work in Arlington, VA, with salary $125,000-$175,000 per year, contingent on contract award. Responsibilities include developing...Contract work- Strategic Analysis, Inc. in Arlington, VA seeks a Senior SAP Security Specialist to strengthen security across SAP programs, applying program protection, personnel, physical, information security, and OPSEC disciplines. You will advise program managers, government customers...
$153.6k - $207.8k
...passionate about helping Government Customers secure their mission data using AWS cloud... ...Services (AWS) is seeking a security solutions architect to work with some of our largest Public... ..., implementation, or consulting in applications and infrastructures experience- 10+...Flexible hours- Salesforce seeks a Security & Compliance Architect to support pre-sales with DoD and national security customers, blending technical depth with sales acumen. You will work with cross-functional teams to map requirements to Salesforce security capabilities, ensure regulatory...
$143k - $238.4k
...today, we want to hear from you.Lead Cyber Security ArchitectLocation: Richmond, VA, USA -... ...The OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role... ...Leadership, audit/compliance, product and application owners, infrastructure, and security engineering...Full time$78.6k - $160.2k
The Security Architecture Specialists will work in the Security Architecture, Engineering and Risk Tower in the CISO organization. The... ...in one or more of the following areas: cloud security, application security, network security, security plans/procedures, protecting...Work experience placementH1bLive inWork at officeLocal areaWork visa- Job Title: IT - Cyber Security Architect/Engineer III Location work will be performed: DCO048 - Washington, DC - (Remote support is authorized) The Info Security Identity Access Portfolio is in need of Cyber Security Solutions Engineer/Architect supporting its Authentication...Interim roleRemote work
- ...Maturity Models and federal mandatesCollaborate with senior architects to integrate security controls into systems design, evaluating new tools /... ...the software development lifecycle (DevSecOps), perform application vulnerability assessments, and establish secure application...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Architect. Be the first to apply!
- .net software architects (remote) Virginia
- security architect Virginia
- cyber security architect Virginia
- cash app Virginia
- now accepting applications Virginia
- paper application Virginia
- director enterprise applications Virginia
- applications consultant Virginia
- app Virginia
- senior application administrator Virginia


