Application Security Architect

Mbi Llc

Richmond (VA)

On-site

USD 130,000 - 170,000

Full time

20 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Mbi Llc in the United States is seeking a Senior Security Architect to define and govern security architectures for enterprise applications, APIs, and cloud-native systems across Azure, ArcGIS, and related platforms.

You will lead threat modeling, security reviews, and integration of security throughout the SDLC, working with engineers, product teams, and incident-response professionals to reduce risk and strengthen controls.

Qualifications

  • Bachelor’s degree or equivalent practical experience in a related field.
  • 10+ years in software engineering or security roles, with 2+ years designing security architecture.
  • Strong understanding of OWASP Top 10 and secure SDLC practices.
  • Experience designing end-to-end security for data-at-rest/in-transit/in-use across major platforms.

Responsibilities

  • Define application-security architecture principles and guardrails for web, mobile, API, and cloud-native systems.
  • Lead threat modeling for new applications and high-risk changes; perform architecture reviews.
  • Establish repeatable security requirements for authentication, authorization, encryption, and data protection.
  • Partner with engineers to integrate security across the SDLC including CI/CD, IaC, and monitoring.

Skills

Software engineering
Application security
Security engineering
Security architecture
Threat modeling
Security reviews

Education

Bachelor’s degree in computer science, cybersecurity, engineering, or related field

Tools

Azure
SQL Server
Dynamics 365
Power Platform
ArcGIS

Job description

Core responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required qualifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
  • Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Skill

Software engineering, application security, security engineering, or related technical roles

Amount

Required

Candidate's No. of years of experience

10

Experience in designing and implementing security architecture for IT systems

Required

6

Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse

Required

6

Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)

Required

6

Demonstrated experience with threat modeling and security architecture reviews

Required

6

Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads

Required

6

Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices

Required

6

Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans

Required

10

Experience in a regulated environment such as financial services, healthcare, government, or payments

Highly desired

6

Experience conducting or coordinating penetration testing and translating results into durable architectural improvements

Highly desired

6

Experience implementing DevSecOps programs and security automation at scale

Highly desired

4

Familiarity with privacy engineering, data classification, and compliance frameworks

Highly desired

4

Experience with security architectures in Esri's ArcGIS platform

Highly desired

2

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

American business solutions inc • Richmond (VA)

On-site
USD 130,000 - 185,000
Application Security Architect
Application Security Architect

My3Tech • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Principal, Product Security
Principal, Product Security

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

KPG99 INC • Richmond (VA)

On-site
USD 140,000 - 180,000
Senior Application Security Architect Cloud Azure & DevSecOps
Senior Application Security Architect Cloud Azure & DevSecOps

Rose International • Richmond (VA)

Hybrid
USD 117,000 - 124,000