Application Security Architect

Accord Technologies Inc.

Richmond (VA)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Accord Technologies Inc. in Richmond, VA is seeking a Senior Application Security Architect to lead secure software development across Azure-based environments and DevSecOps practices.

This is an onsite role with a strong focus on designing security architectures for complex systems. Responsibilities include threat modeling, architecture reviews, enforcement of OAuth2/OpenID, JWTs, data protection, and secure SDLC integration with CI/CD.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, engineering, or related field (or equivalent practical experience).
  • Certifications such as CISSP, CSSLP, CCSP, GIAC are highly desired.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for Azure stack.
  • Lead threat modeling and security architecture reviews across complex projects.

Responsibilities

  • Define application-security architecture principles, standards, patterns, and guardrails for web, API, and cloud-native systems.
  • Perform architecture/design reviews, identify trust boundaries, attack paths, data flows, gaps, and controls.
  • Lead or facilitate threat modeling for new applications and high-risk changes.
  • Establish security requirements for authentication, authorization, encryption, secrets management, and data protection.
  • Partner with engineers to integrate security into the SDLC, including CI/CD and IaC.
  • Evaluate security tools such as SAST, DAST, container/image scanning, and API security testing.
  • Define vulnerability-management approach for applications and dependencies, with remediation SLAs.
  • Assess third-party libraries, open-source components, and vendor integrations for risk.
  • Design identity/access-control patterns including MFA/SSO, RBAC/ABAC, and least privilege.
  • Work with cloud/platform teams to secure hosting environments (Kubernetes, containers, CI/CD).
  • Advise incident-response teams on application-layer threats and contribute to post-incident improvements.
  • Maintain architecture documentation, risk registers, and security decision patterns.

Skills

Software engineering
Application security
Security architecture
Threat modeling
API security
Identity & access
Data protection
CI/CD security
SAST/DAST
Documentation

Education

Bachelor's degree

Tools

Azure
Kubernetes
CI/CD tooling

Job description

Job Title:Application Security Architect

Location: Richmond, VA

Type: W2 Contract

*Only qualified Senior Application Security Architect Cloud Azure & DevSecOps located in the Richmond, VA area will be considered due to the position requiring an onsite presence *

Required Education

Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience)

Preferred Certifications

Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired

Required Skills
  • Software engineering, application security, security engineering, or related technical roles (10 Years)
  • Experience in designing and implementing security architecture for IT systems (6 Years)
  • Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse (6 Years)
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) (6 Years)
  • Demonstrated experience with threat modeling and security architecture reviews (6 Years)
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads (6 Years)
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices (6 Years)
  • Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans (10 Years)
Preferred Skills
  • Experience in a regulated environment such as financial services, healthcare, government, or payments
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
  • Experience implementing DevSecOps programs and security automation at scale
  • Familiarity with privacy engineering, data classification, and compliance frameworks
  • Experience with security architectures in Esri's ArcGIS platform
About the Role

This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with the client

Job responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation
Interview Process

Both webcam and in-person interviews

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Application Security Architect
Application Security Architect

My3tech • Richmond (VA)

On-site
USD 140,000 - 190,000
Security Architect
Security Architect

Stellar Professionals • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Ampcus Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

Ampcus, Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Onsite 4 days/week
Application Security Architect - VA
Application Security Architect - VA

Nexiva Inc • Richmond (VA)

Hybrid
USD 180,000 - 240,000
Application Security Architect
Application Security Architect

American business solutions inc • Richmond (VA)

On-site
USD 130,000 - 185,000
Application Security Architect
Application Security Architect

V Group Inc. • Richmond (VA)

On-site
USD 140,000 - 180,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000