Security Architect
Stellar Professionals
Richmond, VA, United States
8 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.careerjet.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$120,900.0 - $187,000.0
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
.NET Framework
Software System Penetration Testing
ArcGIS (Software)
Architectural Patterns
Microsoft Azure
Microsoft Online Services
Cloud Computing Security
Cloud Engineering
Cyber Security
Databases
Data Governance
+26 more
Information Leak Prevention
Data Security
Identity and Access Management
Python (Programming Language)
Key Management
Microsoft Dynamics
Microsoft Software
Microsoft SQL Server
OAuth
OpenID
Open Web Application Security
Public Key Infrastructure
Role-Based Access Control
Openid Connect
Security Assertion Markup Language (SAML)
Secure Coding
Software Engineering
TypeScript
Software Security
Information Technology
Low-code
Virtual Agents
Devsecops
Static Application Security Testing
Microservices
Dynamic Application Security Testing
Job description
We are seeking a senior Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives at the Virginia Department of Transportation (VDOT) in Richmond, VA. This role establishes Secure Software Development Lifecycle (SSDLC) frameworks, threat modeling standards, data governance, and DevSecOps controls across hybrid ecosystems, cloud platforms, Microsoft stack solutions, enterprise GIS architectures, and Agentic AI tools.
- Client: Virginia Department of Transportation (VDOT)
- Location: Richmond, VA 23219
- Work Arrangement: Hybrid (Onsite requirements set by agency)
- Role Type: Contract (9 Months with extension potential)
- Interview Process: Either In-Person or Remote (Webcam)
- Compliance: Must align with Commonwealth of Virginia (COV) and VITA SEC 530 security standards., * Application Security Architecture & SSDLC: Formulate security principles, threat models, architectural patterns, and security guardrails across web, mobile, microservice, cloud-native, and low-code/no-code platforms.
- Data Security & Governance: Design end-to-end data security architectures (data-at-rest, in-transit, and in-use) using automated classification tools (Microsoft Purview), data loss prevention (DLP), and privacy impact assessments (DPIA).
- Identity & Access Management (IAM): Establish authorization, authentication, and encryption standards incorporating OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, dynamic masking, Row-Level Security (RLS), and RBAC/ABAC models.
- DevSecOps Integration: Partner with software engineering teams to embed security tools into CI/CD pipelines, including SAST, DAST, Software Composition Analysis (SCA), container/image scanning, secret scanning, and infrastructure-as-code (IaC) verification.
-
Regulatory & Compliance Alignment: Audit database activity and application logs to ensure strict compliance with VITA SEC 530 and state transportation cybersecurity requirements., Application Security Architect - Richmond, VA Duration: 9 Months Hybrid Seeking for an Application Security Architect to define and oversee application security strategies ac… - 14 hours ago +
Requirements
- Software & Application Security Experience: 10+ years in software engineering, security engineering, or appsec roles, with at least 6+ years specifically focused on IT security architecture design.
- SSDLC & Risk Management: 6+ years of hands-on experience in threat modeling, OWASP Top 10 mitigation, API security, and secure coding patterns across environments (.NET, Java, Python, or TypeScript).
- Microsoft Ecosystem Security: 6+ years architecting end-to-end security across Microsoft Azure, SQL Server, Power Platform, and Dynamics 365 platforms.
- Identity & Encryption Controls: 6+ years of experience with OAuth 2.0, SAML, OIDC, JWTs, secrets management, and cryptography standards.
- Technical Communication: 10+ years drafting technical documentation, security risk assessments, remediation plans, and enterprise architecture diagrams.
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience., * Industry Certifications: Active CISSP, CSSLP, CCSP, GIAC, or vendor-specific cloud security credentials.
- Public Sector & Regulated Experience: 6+ years working in government, financial, healthcare, or payments ecosystems.
- GIS & Emerging Tech: Experience securing Esri ArcGIS platforms, DevSecOps automation, penetration testing remediation, or Agentic AI implementations.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerjet.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
CH
Chris Heilmann
Dev Digest 120 - Apple and peers
over 2 years ago