Application Security Architect - Hybrid/Onsite Richmond, VA
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+34 more
Job description
Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, API, distributed, and cloud-native systems.
-
Lead architecture and design reviews; identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
-
Facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
-
Establish reusable requirements for authentication, authorization, encryption, secrets management, session security, API protection, logging, privacy, and data protection.
-
Integrate security into code review, CI/CD, infrastructure as code, testing, release approval, and production monitoring.
-
Guide use of SAST, DAST, software-composition analysis, container/image scanning, API testing, secret scanning, and runtime protection.
-
Design vulnerability-management standards, remediation targets, exception processes, and verification practices.
-
Assess third-party libraries, SaaS integrations, open-source dependencies, and vendor components.
-
Design identity and access patterns using least privilege, MFA/SSO, service-to-service authentication, RBAC/ABAC, PKI/TLS, and secure secrets storage.
-
Maintain architecture diagrams, standards, risk assessments, risk registers, security decisions, exceptions, and remediation plans.
Requirements
10+ years in software engineering, application security, security engineering, or closely related technical roles.
-
6+ years designing and implementing security architecture for IT systems.
-
6+ years applying secure-development principles and addressing OWASP Top 10 risks, including authorization weaknesses, injection, deserialization, and API abuse.
-
6+ years designing end-to-end protection for data at rest, in transit, and in use across the Microsoft stack, including Azure, Microsoft 365, Power Platform, and Dynamics 365.
-
6+ years performing threat modeling and security-architecture reviews.
-
6+ years securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
-
6+ years with OAuth 2.0, OpenID Connect, SAML, JWT, authorization design, PKI/TLS, encryption, and secrets management.
-
10+ years producing clear architecture diagrams, standards, risk assessments, and actionable remediation plans.
-
Ability to work onsite in Richmond four days per week during the first 90 days and continue regular weekly onsite work afterward.
-
Ability to physically reside in the United States for the entire assignment.
Highly desired:
-
6+ years in regulated financial services, healthcare, government, or payments environments.
-
6+ years conducting or coordinating penetration testing and turning findings into durable architectural improvements.
-
4+ years implementing DevSecOps programs and security automation at scale.
-
4+ years with privacy engineering, data classification, and compliance frameworks.
-
2+ years designing security architecture for Esri ArcGIS.
-
CISSP, CSSLP, CCSP, GIAC, cloud-security, or relevant vendor certifications.
- Secure-coding familiarity in Java, .NET, JavaScript/TypeScript, or Python., * software, application-security or security engineering: 10 years (Required)
- security architecture for IT systems: 6 years (Required)
- secure SDLC and OWASP Top 10 risk work: 6 years (Required)
- Microsoft-stack data protection architecture: 6 years (Required)
- threat modeling and security architecture reviews: 6 years (Required)
- securing APIs, cloud, CI/CD and containers: 6 years (Required)
- OAuth, OIDC, SAML, JWT, PKI, TLS and encryption: 6 years (Required)
- architecture diagrams, standards and risk plans: 10 years (Required)
Benefits & conditions
Contract term: September 21, 2026 through June 30, 2027. Pay: $88-$96 per hour, depending on verified experience., Keyword lists are not enough. For every claimed requirement, show where and when the work occurred and what you personally designed, reviewed, implemented, or governed. Final submission resumes should make the exact evidence for every required area easy to verify.
Pay: $88.00 - $96.00 per hour
Expected hours: 40.0 per week
Application Question(s):
- What city and state do you currently reside in, and what is your normal one-way commute time to Richmond? A city name by itself is not proof of onsite availability.
- For each required experience area, list the employer or project, month/year dates, system, and what you personally designed, reviewed, implemented, or governed. Keyword lists without dated work evidence are not enough.
- List your years of direct experience with each area separately: ArcGIS security architecture; DevSecOps or security automation; penetration testing; privacy/data classification/compliance; and regulated government, healthcare, financial-services, or payments environments. Enter zero for any area you have not performed. Also confirm each item with Yes or No: currently within a practical Richmond commute; onsite four days weekly for the first 90 days and regular weekly onsite work afterward; available for webcam and in-person interviews; physically residing in the United States for the assignment; and comfortable with $88-$96 per hour.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this roleβ¦