> Markdown version of [/jobs/ext/2936448-security-architect](https://www.wearedevelopers.com/jobs/ext/2936448-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Stellar Professionals - **Location:** Richmond, VA, United States - **Experience:** Expert - **Salary:** $120,900.0 - $187,000.0 - **Contract:** Temporary to permanent - **Skills:** Java (Programming Language), .NET Framework, Software System Penetration Testing, ArcGIS (Software), Architectural Patterns, Microsoft Azure, Microsoft Online Services, Cloud Computing Security, Cloud Engineering, Cyber Security, Databases, Data Governance, Information Leak Prevention, Data Security, Identity and Access Management, Python (Programming Language), Key Management, Microsoft Dynamics, Microsoft Software, Microsoft SQL Server, OAuth, OpenID, Open Web Application Security, Public Key Infrastructure, Role-Based Access Control, Openid Connect, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, TypeScript, Software Security, Information Technology, Low-code, Virtual Agents, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 16, 2026 - **Apply:** https://www.careerjet.com/jobad/usc97a7e8b545e605bb7e7412b1ef336c0 ## About the Role * Software & Application Security Experience: 10+ years in software engineering, security engineering, or appsec roles, with at least 6+ years specifically focused on IT security architecture design. * SSDLC & Risk Management: 6+ years of hands-on experience in threat modeling, OWASP Top 10 mitigation, API security, and secure coding patterns across environments (.NET, Java, Python, or TypeScript). * Microsoft Ecosystem Security: 6+ years architecting end-to-end security across Microsoft Azure, SQL Server, Power Platform, and Dynamics 365 platforms. * Identity & Encryption Controls: 6+ years of experience with OAuth 2.0, SAML, OIDC, JWTs, secrets management, and cryptography standards. * Technical Communication: 10+ years drafting technical documentation, security risk assessments, remediation plans, and enterprise architecture diagrams. * Education: Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience., * Industry Certifications: Active CISSP, CSSLP, CCSP, GIAC, or vendor-specific cloud security credentials. * Public Sector & Regulated Experience: 6+ years working in government, financial, healthcare, or payments ecosystems. * GIS & Emerging Tech: Experience securing Esri ArcGIS platforms, DevSecOps automation, penetration testing remediation, or Agentic AI implementations. ## Description We are seeking a senior Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives at the Virginia Department of Transportation (VDOT) in Richmond, VA. This role establishes Secure Software Development Lifecycle (SSDLC) frameworks, threat modeling standards, data governance, and DevSecOps controls across hybrid ecosystems, cloud platforms, Microsoft stack solutions, enterprise GIS architectures, and Agentic AI tools. * Client: Virginia Department of Transportation (VDOT) * Location: Richmond, VA 23219 * Work Arrangement: Hybrid (Onsite requirements set by agency) * Role Type: Contract (9 Months with extension potential) * Interview Process: Either In-Person or Remote (Webcam) * Compliance: Must align with Commonwealth of Virginia (COV) and VITA SEC 530 security standards., * Application Security Architecture & SSDLC: Formulate security principles, threat models, architectural patterns, and security guardrails across web, mobile, microservice, cloud-native, and low-code/no-code platforms. * Data Security & Governance: Design end-to-end data security architectures (data-at-rest, in-transit, and in-use) using automated classification tools (Microsoft Purview), data loss prevention (DLP), and privacy impact assessments (DPIA). * Identity & Access Management (IAM): Establish authorization, authentication, and encryption standards incorporating OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, dynamic masking, Row-Level Security (RLS), and RBAC/ABAC models. * DevSecOps Integration: Partner with software engineering teams to embed security tools into CI/CD pipelines, including SAST, DAST, Software Composition Analysis (SCA), container/image scanning, secret scanning, and infrastructure-as-code (IaC) verification. * Regulatory & Compliance Alignment: Audit database activity and application logs to ensure strict compliance with VITA SEC 530 and state transportation cybersecurity requirements., Application Security Architect - Richmond, VA Duration: 9 Months | Hybrid Seeking for an Application Security Architect to define and oversee application security strategies ac… + 14 hours ago + ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Reimagining app development with Low-code and AI](https://www.wearedevelopers.com/videos/1651-reimagining-app-development-with-low-code-and-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [What If Apps Built Themselves? AI-Powered Low-Code for the Industrial Enterprise](https://www.wearedevelopers.com/videos/2079-what-if-apps-built-themselves-ai-powered-low-code-for-the-industrial-enterprise) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)