> Markdown version of [/jobs/ext/3391046-application-security-architect-hybrid-onsite-richmond-va](https://www.wearedevelopers.com/jobs/ext/3391046-application-security-architect-hybrid-onsite-richmond-va). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - Hybrid/Onsite Richmond, VA - **Company:** IEC TECH INC. - **Location:** Richmond, VA, United States - **Experience:** Expert - **Salary:** $183,040.0 - $199,680.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), .NET Framework, Microsoft Windows, Application Programming Interfaces (APIs), Software System Penetration Testing, ArcGIS (Software), Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Distributed Systems, Python (Programming Language), Key Management, Microsoft Dynamics, Microsoft Software, OAuth, Open Source Technology, OpenID, Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Role-Based Access Control, Openid Connect, JSON Web Token, Security Assertion Markup Language (SAML), Software Engineering, Data Streaming, TypeScript, Web Applications, Privacy Controls, Data Logging, Transport Layer Security, Data Classification, Software Security, Containerization, Infrastructure Automation Frameworks, Information Technology, Devsecops, Api Management, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5b1e66882d7c95b9 ## About the Role 10+ years in software engineering, application security, security engineering, or closely related technical roles. - 6+ years designing and implementing security architecture for IT systems. - 6+ years applying secure-development principles and addressing OWASP Top 10 risks, including authorization weaknesses, injection, deserialization, and API abuse. - 6+ years designing end-to-end protection for data at rest, in transit, and in use across the Microsoft stack, including Azure, Microsoft 365, Power Platform, and Dynamics 365. - 6+ years performing threat modeling and security-architecture reviews. - 6+ years securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads. - 6+ years with OAuth 2.0, OpenID Connect, SAML, JWT, authorization design, PKI/TLS, encryption, and secrets management. - 10+ years producing clear architecture diagrams, standards, risk assessments, and actionable remediation plans. - Ability to work onsite in Richmond four days per week during the first 90 days and continue regular weekly onsite work afterward. - Ability to physically reside in the United States for the entire assignment. Highly desired: - 6+ years in regulated financial services, healthcare, government, or payments environments. - 6+ years conducting or coordinating penetration testing and turning findings into durable architectural improvements. - 4+ years implementing DevSecOps programs and security automation at scale. - 4+ years with privacy engineering, data classification, and compliance frameworks. - 2+ years designing security architecture for Esri ArcGIS. - CISSP, CSSLP, CCSP, GIAC, cloud-security, or relevant vendor certifications. - Secure-coding familiarity in Java, .NET, JavaScript/TypeScript, or Python., * software, application-security or security engineering: 10 years (Required) * security architecture for IT systems: 6 years (Required) * secure SDLC and OWASP Top 10 risk work: 6 years (Required) * Microsoft-stack data protection architecture: 6 years (Required) * threat modeling and security architecture reviews: 6 years (Required) * securing APIs, cloud, CI/CD and containers: 6 years (Required) * OAuth, OIDC, SAML, JWT, PKI, TLS and encryption: 6 years (Required) * architecture diagrams, standards and risk plans: 10 years (Required) ## Description Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, API, distributed, and cloud-native systems. - Lead architecture and design reviews; identify trust boundaries, attack paths, data flows, security gaps, and compensating controls. - Facilitate threat modeling for new applications, major features, integrations, and high-risk changes. - Establish reusable requirements for authentication, authorization, encryption, secrets management, session security, API protection, logging, privacy, and data protection. - Integrate security into code review, CI/CD, infrastructure as code, testing, release approval, and production monitoring. - Guide use of SAST, DAST, software-composition analysis, container/image scanning, API testing, secret scanning, and runtime protection. - Design vulnerability-management standards, remediation targets, exception processes, and verification practices. - Assess third-party libraries, SaaS integrations, open-source dependencies, and vendor components. - Design identity and access patterns using least privilege, MFA/SSO, service-to-service authentication, RBAC/ABAC, PKI/TLS, and secure secrets storage. - Maintain architecture diagrams, standards, risk assessments, risk registers, security decisions, exceptions, and remediation plans.