> Markdown version of [/jobs/ext/126802-application-security-architect](https://www.wearedevelopers.com/jobs/ext/126802-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - **Company:** ConsultNet - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Applications Architecture, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Cryptographic Protocols, Python (Programming Language), Linux Servers, OAuth, OpenID, Open Web Application Security, Security Assertion Markup Language (SAML), Secure Coding, Single Sign-On, Software Engineering, Systems Architecture, Enterprise Software Applications, Cloud Platform System, Data Classification, Spring Cloud, Software Security, Information Technology, CIS Benchmarks, Devsecops, Serverless Computing, Static Application Security Testing, Programming Languages, Microservices, Dynamic Application Security Testing - **Published:** May 16, 2026 - **Apply:** https://www.careerjet.com/jobad/us3571f4213b9ec88a2bcc469d9ecc7f0c ## About the Role Bachelor's degree in Computer Science, Information Security, or a related technical field 5+ years of experience in application security, including at least 2 years in a security architecture role Deep knowledge of secure design principles, threat modeling methodologies, and security architecture patterns Experience designing security controls for cloud environments such as AWS, Azure, or GCP Proficiency evaluating and implementing application security tools, including SAST, DAST, IAST, and SCA Hands-on experience with security testing and proxy tools Strong understanding of secure software development practices and DevSecOps implementation In-depth knowledge of OWASP Top 10, CWE/SANS, and related security standards Experience with authentication and identity technologies including MFA, SSO, OAuth 2.0, SAML, and OIDC Experience designing and securing APIs and microservices architectures Knowledge of regulatory requirements and their impact on application architecture Proficiency in one or more programming languages, preferably Java, Python, or JavaScript Experience performing secure code reviews and identifying common vulnerability patterns Understanding of cryptographic protocols and secure implementation practices Experience supporting modern application architectures such as SPAs, serverless, and container-based systems Strong communication skills with the ability to explain complex security concepts to technical and non-technical audiences Experience leading cross-functional initiatives and influencing stakeholders Relevant certifications such as CSSLP, CISSP, or cloud security certifications are highly desirable ## Description The Senior Application Security Architect is responsible for designing, implementing, and governing enterprise-wide application security architecture and standards. This role establishes security frameworks, conducts architecture and design reviews, and leads strategic security initiatives that embed security across the software development lifecycle. The position requires strong technical depth, architectural thinking, and leadership, along with the ability to manage multiple priorities and collaborate effectively across teams. Responsibilities Design and establish enterprise application security architecture frameworks, reference models, and standards aligned with business objectives and risk tolerance Lead application and system architecture reviews to identify security gaps and recommend appropriate controls Develop and maintain security baselines, standards, and reusable patterns for web, mobile, API, microservices, and cloud-native applications Create and evolve threat modeling practices and facilitate threat modeling sessions with development teams Define secure coding standards and security requirements based on application type, data classification, and risk profile Architect security solutions for authentication, authorization, encryption, and secure communications Establish security guardrails for cloud-native, serverless, containerized, and infrastructure-as-code environments Design and implement API security strategies, including identity flows, gateways, and rate limiting Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives Evaluate, select, and recommend application security tools and technologies Develop security architecture roadmaps and guide implementation of enterprise security capabilities Partner with development and platform teams to design secure solutions that balance security and business needs Lead cross-functional security initiatives with enterprise-wide impact Leverage GenAI technologies to enhance security architecture reviews and automate security analysis Maintain documentation of security architecture decisions, patterns, and reference implementations Develop and deliver security architecture training and guidance for developers and architects Stay current with emerging security threats, technologies, and architectural best practices Perform security design reviews for new applications and major system changes Architect secure data handling practices, including encryption at rest and in transit, MANTECH seeks a motivated, career and customer-oriented Telephony Engineer to join our team in McLean, VA. In this role, you'll combine expertise in telephony systems, Linux server… + 14 days ago ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)