Unknown Company

Application Security Architect

richmond, va • Posted 6 days ago
Hybrid Full Time Software Architecture & Engineering

Work Arrangement: Hybrid – Local Candidates Only

Work Arrangement

  • Local candidates only.
  • Candidate must be able to work onsite 4 days per week during the initial 90-day probationary period .
  • Following successful completion of the probationary period, there may be an opportunity for a reduced onsite commitment; however, some onsite presence will continue to be required weekly.

Key Responsibilities

  • Define application security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code reviews, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide the use of security tools, including SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risks.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Partner with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements following incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.

Required Qualifications

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including experience designing security architecture for IT systems.
  • Strong understanding of secure software-development principles and common application risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • 6+ years of experience designing and implementing end-to-end security architectures for data-at-rest, data-in-transit, and data-in-use across the Microsoft technology stack, including Azure, O365, Power Platform, and Dynamics 365.
  • Experience with SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms.
  • Experience utilizing automated data classification, such as Microsoft Purview, encryption, DLP rules, and privacy risk assessments (DPIAs).
  • Experience enforcing granular data access controls, including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking.
  • Experience establishing centralized database audit logging and activity-monitoring pipelines aligned with VITA SEC 530 security standards.
  • 6+ years of demonstrated experience with threat modeling and security architecture reviews.
  • 6+ years of experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • 6+ years of experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Strong ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.

Preferred Qualifications

  • Experience working in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks.
  • Experience with security architectures in Esri's ArcGIS platform.
  • Experience conducting or coordinating penetration testing and translating findings into durable architectural improvements.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.

Experience Requirements

  • 10+ years – Software engineering, application security, security engineering, or related technical roles – Required.
  • 6+ years – Designing and implementing security architecture for IT systems – Required.
  • 6+ years – Secure software-development principles and common application risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse – Required.
  • 6+ years – End-to-end security architectures for data-at-rest, data-in-transit, and data-in-use across the Microsoft technology stack – Required.
  • 6+ years – Threat modeling and security architecture reviews – Required.
  • 6+ years – Securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads – Required.
  • 6+ years – Identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets management – Required.
  • 10+ years – Creating architecture diagrams, standards, risk assessments, and actionable remediation plans – Required.
  • 6+ years – Experience in regulated environments such as financial services, healthcare, government, or payments – Highly Desired.
  • 6+ years – Conducting or coordinating penetration testing and translating results into architectural improvements – Highly Desired.
  • 4+ years – Implementing DevSecOps programs and security automation at scale – Highly Desired.
  • 4+ years – Privacy engineering, data classification, and compliance frameworks – Highly Desired.
  • 2+ years – Security architecture experience with Esri's ArcGIS platform – Highly Desired.

Education & Certifications

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field, or equivalent practical experience.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.

#J-18808-Ljbffr

Application Security Architect in richmond at Unknown Company

This position is listed as full time and hybrid.

Back to Job Search