Application Security Architect

My3Tech

Richmond (VA)

Hybrid

USD 140,000 - 190,000

Full time

17 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

My3Tech in Virginia seeks a senior Application Security Architect to lead security design for web, mobile, API, and cloud-native systems. You will collaborate with engineers to embed security into the SDLC and guide threat modeling and guardrail definitions.

The role requires deep experience in secure software development, identity, and data protection, with hands-on Microsoft stack expertise and container security. Hybrid work is offered.

Qualifications

  • 10+ years in software engineering or security engineering, including design of security architecture for IT systems.
  • 6+ years designing and implementing end-to-end security architectures for data-at-rest, data-in-transit, and data-in-use on Microsoft tech stack (Azure, O365, Power Platform, Dynamics 365).
  • Experience with OWASP Top 10 and secure software-development principles.
  • 6+ years of threat modeling and security architecture reviews.
  • 6+ years securing APIs, web apps, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • 6+ years identity, OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, and secrets-management practices.
  • Strong ability to explain technical risks to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills and ability to create architecture diagrams and risk assessments.

Responsibilities

  • Define application security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code reviews, CI/CD, IaC, testing, release approval, and production monitoring.
  • Evaluate and guide the use of security tools (SAST, DAST, software composition analysis, container scanning, API security testing, secret scanning, runtime protection).
  • Define a vulnerability management approach for applications and dependencies with SLAs and remediation processes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor components for security risks.
  • Design identity and access-control patterns (least privilege, MFA/SSO, RBAC/ABAC, privileged-access controls).
  • Partner with cloud/platform teams to secure hosting environments (Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, secrets storage).
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements.
  • Maintain architecture documentation, decision patterns, risk registers, and exception docs.

Skills

Application security
Threat modeling
Security architecture
Secure SDLC
Cloud security
API security
Identity & access
Communication
Architecture diagrams

Education

Bachelor’s degree in CS/Cybersecurity/Engineering
Equivalent practical experience

Tools

Azure
O365
Power Platform
Dynamics 365
SQL Server
ArcGIS

Job description

Work Arrangement: Hybrid – Local Candidates Only

Work Arrangement
  • Local candidates only.
  • Candidate must be able to work onsite 4 days per week during the initial 90-day probationary period.
  • Following successful completion of the probationary period, there may be an opportunity for a reduced onsite commitment; however, some onsite presence will continue to be required weekly.
Key Responsibilities
  • Define application security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code reviews, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide the use of security tools, including SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risks.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Partner with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements following incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Qualifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including experience designing security architecture for IT systems.
  • Strong understanding of secure software-development principles and common application risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • 6+ years of experience designing and implementing end-to-end security architectures for data-at-rest, data-in-transit, and data-in-use across the Microsoft technology stack, including Azure, O365, Power Platform, and Dynamics 365.
  • Experience with SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms.
  • Experience utilizing automated data classification, such as Microsoft Purview, encryption, DLP rules, and privacy risk assessments (DPIAs).
  • Experience enforcing granular data access controls, including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking.
  • Experience establishing centralized database audit logging and activity-monitoring pipelines aligned with VITA SEC 530 security standards.
  • 6+ years of demonstrated experience with threat modeling and security architecture reviews.
  • 6+ years of experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • 6+ years of experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Strong ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred Qualifications
  • Experience working in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks.
  • Experience with security architectures in Esri's ArcGIS platform.
  • Experience conducting or coordinating penetration testing and translating findings into durable architectural improvements.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
Experience Requirements
  • 10+ years – Software engineering, application security, security engineering, or related technical roles – Required.
  • 6+ years – Designing and implementing security architecture for IT systems – Required.
  • 6+ years – Secure software-development principles and common application risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse – Required.
  • 6+ years – End-to-end security architectures for data-at-rest, data-in-transit, and data-in-use across the Microsoft technology stack – Required.
  • 6+ years – Threat modeling and security architecture reviews – Required.
  • 6+ years – Securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads – Required.
  • 6+ years – Identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets management – Required.
  • 10+ years – Creating architecture diagrams, standards, risk assessments, and actionable remediation plans – Required.
  • 6+ years – Experience in regulated environments such as financial services, healthcare, government, or payments – Highly Desired.
  • 6+ years – Conducting or coordinating penetration testing and translating results into architectural improvements – Highly Desired.
  • 4+ years – Implementing DevSecOps programs and security automation at scale – Highly Desired.
  • 4+ years – Privacy engineering, data classification, and compliance frameworks – Highly Desired.
  • 2+ years – Security architecture experience with Esri's ArcGIS platform – Highly Desired.
Education & Certifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field, or equivalent practical experience.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Mbi Llc • Richmond (VA)

On-site
USD 130,000 - 170,000
Application Security Architect
Application Security Architect

American business solutions inc • Richmond (VA)

On-site
USD 130,000 - 185,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

KPG99 INC • Richmond (VA)

On-site
USD 140,000 - 180,000
Application Architect
Application Architect

Electrosoft • Arlington (VA)

On-site
USD 130,000 - 170,000
Security Architect
Security Architect

Arctiq: Intelligent Architecture • Las Vegas (NV)

On-site
USD 130,000 - 190,000