Application Security Architect - Hybrid/Onsite Richmond, VA

IEC TECH INC.
Richmond, VA, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$183,040.0 - $199,680.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) .NET Framework Microsoft Windows Application Programming Interfaces (APIs) Software System Penetration Testing ArcGIS (Software) Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Code Review
+34 more
Cyber Security Continuous Integration Distributed Systems Python (Programming Language) Key Management Microsoft Dynamics Microsoft Software OAuth Open Source Technology OpenID Open Web Application Security Public Key Infrastructure Systems Development Life Cycle Role-Based Access Control Openid Connect JSON Web Token Security Assertion Markup Language (SAML) Software Engineering Data Streaming TypeScript Web Applications Privacy Controls Data Logging Transport Layer Security Data Classification Software Security Containerization Infrastructure Automation Frameworks Information Technology Devsecops Api Management Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, API, distributed, and cloud-native systems.

  • Lead architecture and design reviews; identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.

  • Facilitate threat modeling for new applications, major features, integrations, and high-risk changes.

  • Establish reusable requirements for authentication, authorization, encryption, secrets management, session security, API protection, logging, privacy, and data protection.

  • Integrate security into code review, CI/CD, infrastructure as code, testing, release approval, and production monitoring.

  • Guide use of SAST, DAST, software-composition analysis, container/image scanning, API testing, secret scanning, and runtime protection.

  • Design vulnerability-management standards, remediation targets, exception processes, and verification practices.

  • Assess third-party libraries, SaaS integrations, open-source dependencies, and vendor components.

  • Design identity and access patterns using least privilege, MFA/SSO, service-to-service authentication, RBAC/ABAC, PKI/TLS, and secure secrets storage.

  • Maintain architecture diagrams, standards, risk assessments, risk registers, security decisions, exceptions, and remediation plans.

Requirements

10+ years in software engineering, application security, security engineering, or closely related technical roles.

  • 6+ years designing and implementing security architecture for IT systems.

  • 6+ years applying secure-development principles and addressing OWASP Top 10 risks, including authorization weaknesses, injection, deserialization, and API abuse.

  • 6+ years designing end-to-end protection for data at rest, in transit, and in use across the Microsoft stack, including Azure, Microsoft 365, Power Platform, and Dynamics 365.

  • 6+ years performing threat modeling and security-architecture reviews.

  • 6+ years securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.

  • 6+ years with OAuth 2.0, OpenID Connect, SAML, JWT, authorization design, PKI/TLS, encryption, and secrets management.

  • 10+ years producing clear architecture diagrams, standards, risk assessments, and actionable remediation plans.

  • Ability to work onsite in Richmond four days per week during the first 90 days and continue regular weekly onsite work afterward.

  • Ability to physically reside in the United States for the entire assignment.

Highly desired:

  • 6+ years in regulated financial services, healthcare, government, or payments environments.

  • 6+ years conducting or coordinating penetration testing and turning findings into durable architectural improvements.

  • 4+ years implementing DevSecOps programs and security automation at scale.

  • 4+ years with privacy engineering, data classification, and compliance frameworks.

  • 2+ years designing security architecture for Esri ArcGIS.

  • CISSP, CSSLP, CCSP, GIAC, cloud-security, or relevant vendor certifications.

  • Secure-coding familiarity in Java, .NET, JavaScript/TypeScript, or Python., * software, application-security or security engineering: 10 years (Required)
  • security architecture for IT systems: 6 years (Required)
  • secure SDLC and OWASP Top 10 risk work: 6 years (Required)
  • Microsoft-stack data protection architecture: 6 years (Required)
  • threat modeling and security architecture reviews: 6 years (Required)
  • securing APIs, cloud, CI/CD and containers: 6 years (Required)
  • OAuth, OIDC, SAML, JWT, PKI, TLS and encryption: 6 years (Required)
  • architecture diagrams, standards and risk plans: 10 years (Required)

Benefits & conditions

Contract term: September 21, 2026 through June 30, 2027. Pay: $88-$96 per hour, depending on verified experience., Keyword lists are not enough. For every claimed requirement, show where and when the work occurred and what you personally designed, reviewed, implemented, or governed. Final submission resumes should make the exact evidence for every required area easy to verify.

Pay: $88.00 - $96.00 per hour

Expected hours: 40.0 per week

Application Question(s):

  • What city and state do you currently reside in, and what is your normal one-way commute time to Richmond? A city name by itself is not proof of onsite availability.
  • For each required experience area, list the employer or project, month/year dates, system, and what you personally designed, reviewed, implemented, or governed. Keyword lists without dated work evidence are not enough.
  • List your years of direct experience with each area separately: ArcGIS security architecture; DevSecOps or security automation; penetration testing; privacy/data classification/compliance; and regulated government, healthcare, financial-services, or payments environments. Enter zero for any area you have not performed. Also confirm each item with Yes or No: currently within a practical Richmond commute; onsite four days weekly for the first 90 days and regular weekly onsite work afterward; available for webcam and in-person interviews; physically residing in the United States for the assignment; and comfortable with $88-$96 per hour.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…