Security Architect

Stellar Professionals
Richmond, VA, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$120,900.0 - $187,000.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) .NET Framework Software System Penetration Testing ArcGIS (Software) Architectural Patterns Microsoft Azure Microsoft Online Services Cloud Computing Security Cloud Engineering Cyber Security Databases Data Governance
+26 more
Information Leak Prevention Data Security Identity and Access Management Python (Programming Language) Key Management Microsoft Dynamics Microsoft Software Microsoft SQL Server OAuth OpenID Open Web Application Security Public Key Infrastructure Role-Based Access Control Openid Connect Security Assertion Markup Language (SAML) Secure Coding Software Engineering TypeScript Software Security Information Technology Low-code Virtual Agents Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking a senior Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives at the Virginia Department of Transportation (VDOT) in Richmond, VA. This role establishes Secure Software Development Lifecycle (SSDLC) frameworks, threat modeling standards, data governance, and DevSecOps controls across hybrid ecosystems, cloud platforms, Microsoft stack solutions, enterprise GIS architectures, and Agentic AI tools.

  • Client: Virginia Department of Transportation (VDOT)
  • Location: Richmond, VA 23219
  • Work Arrangement: Hybrid (Onsite requirements set by agency)
  • Role Type: Contract (9 Months with extension potential)
  • Interview Process: Either In-Person or Remote (Webcam)
  • Compliance: Must align with Commonwealth of Virginia (COV) and VITA SEC 530 security standards., * Application Security Architecture & SSDLC: Formulate security principles, threat models, architectural patterns, and security guardrails across web, mobile, microservice, cloud-native, and low-code/no-code platforms.
  • Data Security & Governance: Design end-to-end data security architectures (data-at-rest, in-transit, and in-use) using automated classification tools (Microsoft Purview), data loss prevention (DLP), and privacy impact assessments (DPIA).
  • Identity & Access Management (IAM): Establish authorization, authentication, and encryption standards incorporating OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, dynamic masking, Row-Level Security (RLS), and RBAC/ABAC models.
  • DevSecOps Integration: Partner with software engineering teams to embed security tools into CI/CD pipelines, including SAST, DAST, Software Composition Analysis (SCA), container/image scanning, secret scanning, and infrastructure-as-code (IaC) verification.
  • Regulatory & Compliance Alignment: Audit database activity and application logs to ensure strict compliance with VITA SEC 530 and state transportation cybersecurity requirements., Application Security Architect - Richmond, VA Duration: 9 Months Hybrid Seeking for an Application Security Architect to define and oversee application security strategies ac…
  • 14 hours ago +

Requirements

  • Software & Application Security Experience: 10+ years in software engineering, security engineering, or appsec roles, with at least 6+ years specifically focused on IT security architecture design.
  • SSDLC & Risk Management: 6+ years of hands-on experience in threat modeling, OWASP Top 10 mitigation, API security, and secure coding patterns across environments (.NET, Java, Python, or TypeScript).
  • Microsoft Ecosystem Security: 6+ years architecting end-to-end security across Microsoft Azure, SQL Server, Power Platform, and Dynamics 365 platforms.
  • Identity & Encryption Controls: 6+ years of experience with OAuth 2.0, SAML, OIDC, JWTs, secrets management, and cryptography standards.
  • Technical Communication: 10+ years drafting technical documentation, security risk assessments, remediation plans, and enterprise architecture diagrams.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience., * Industry Certifications: Active CISSP, CSSLP, CCSP, GIAC, or vendor-specific cloud security credentials.
  • Public Sector & Regulated Experience: 6+ years working in government, financial, healthcare, or payments ecosystems.
  • GIS & Emerging Tech: Experience securing Esri ArcGIS platforms, DevSecOps automation, penetration testing remediation, or Agentic AI implementations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:09 min

Defining low-code systems and determining their ideal use cases

Halil İbrahim Kalkan Halil İbrahim Kalkan · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all