Application Security Architect (Hybrid)

The Smart
Richmond, VA, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$124,800.0 - $166,400.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Artificial Intelligence ArcGIS (Software) Microsoft Azure Cloud Computing Security Code Review Encodings Cyber Security Continuous Integration Distributed Systems Identity and Access Management Information Systems Security Architecture Professional
+27 more
Key Management Microsoft Dynamics Microsoft SQL Server OAuth Open Web Application Security Public Key Infrastructure Systems Development Life Cycle Role-Based Access Control Openid Connect Cloud Services JSON Web Token Security Assertion Markup Language (SAML) Secure Coding Single Sign-On Software Engineering Software Vulnerability Management Web Applications Privacy Controls Enterprise Software Applications Data Classification Software Security Kubernetes Information Technology Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

As an Application Security Architect, you will lead the design and implementation of enterprise application security strategies, secure software development practices, and data protection frameworks across cloud, web, GIS, AI, and modern application platforms. This role focuses on embedding security throughout the SDLC, ensuring compliance with security standards, and protecting critical enterprise data through secure architecture, threat modeling, and governance initiatives., Define application security architecture standards, patterns, reference models, and security guardrails. Conduct architecture reviews, identify security risks, and recommend effective mitigation strategies. Lead threat modeling activities for applications, integrations, cloud solutions, and high-risk system changes. Establish security requirements for authentication, authorization, encryption, secrets management, and data protection. Integrate security practices throughout the SSDLC, including CI/CD pipelines, code reviews, and testing processes. Evaluate and guide the implementation of security tools such as SAST, DAST, SCA, container scanning, and API security testing. Design identity and access management solutions utilizing MFA, SSO, OAuth, OpenID Connect, RBAC, and ABAC. Secure cloud-native, containerized, and enterprise application environments across modern platforms. Develop vulnerability management processes, remediation standards, and security governance frameworks. Collaborate with engineering, architecture, operations, and security teams to strengthen enterprise security posture., Application Security Architect - Richmond, VA Duration: 9 Months | Hybrid Seeking for an Application Security Architect to define and oversee application security strategies ac…

  • 14 hours ago, Position: VDOT Application Security Architect Location : 1221 E. Broad St.Richmond, VA Interview : Both Web Cam and In Person Interview Job : Hybrid *Local candidates only…
  • 17 hours ago +

Requirements

Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience. 10+ years of experience in software engineering, application security, security engineering, or related technical roles. 2+ years of experience designing and implementing enterprise security architectures. Strong expertise in Secure Software Development Lifecycle (SSDLC), DevSecOps, and secure coding practices. Deep understanding of OWASP Top 10, API security, threat modeling, vulnerability management, and application security assessments. Experience securing cloud platforms, distributed systems, web applications, microservices, containers, Kubernetes, and CI/CD environments. Strong knowledge of data protection, encryption, privacy controls, data classification, governance, and compliance frameworks. Hands-on experience with Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS, IAM, OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, and secrets management. Proven experience with security tools including SAST, DAST, Software Composition Analysis, container security, and runtime protection solutions. Professional certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security certifications, or equivalent credentials are highly preferred. The hourly range for roles of this nature are $60.00 to $80.00/hr. Rates are heavily dependent on skills, experience, location, and industry. cyberThink is an Equal Opportunity Employer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all