Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
My3tech is seeking an Application Security Architect to define, embed, and oversee security across enterprise IT initiatives in a predominantly on-site setup in Richmond, VA. This role focuses on SSDLC across hybrid environments, data protection, and privacy governance for critical transportation assets.
The ideal candidate has a Bachelor’s degree or equivalent, 10+ years in related roles, and strong abilities in threat modeling, architecture reviews, and security controls across APIs, cloud,
Job: Application Security Architect
Location: 1221 E. Broad St. Richmond, VA
*Local candidates only please
*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.
Client is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Software engineering, application security, security engineering, or related technical roles. - Required 10 Years
Experience in designing and implementing security architecture for IT systems. - Required 6 Years
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse. - Required 6 Years
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365). - Required 6 Years
Demonstrated experience with threat modeling and security architecture reviews. - Required 6 Years
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads. - Required 6 Years
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices. - Required 6 Years
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans. - Required 10 Years
Experience in a regulated environment such as financial services, healthcare, government, or payments. - Highly desired 6 Years
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements. - Highly desired 6 Years
Experience implementing DevSecOps programs and security automation at scale. - Highly desired 4 Years
Familiarity with privacy engineering, data classification, and compliance frameworks. - Highly desired 4 Years
Experience with security architectures in Esri's ArcGIS platform. - Highly desired 2 Years