Application Security Architect

Talent Portus

Virginia (MN)

Hybrid

USD 150,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Talent Portus seeks an experienced Application Security Architect to define and run SSDLC across a hybrid technology ecosystem, including web apps, APIs, microservices, cloud-native solutions, and GIS platforms. You will lead threat modeling, secure architecture reviews, and data-protection initiatives across enterprise cloud and data platforms.

The role collaborates with development, cloud, data, and cybersecurity teams to enforce security standards, perform risk assessments, and ensure

Qualifications

  • Bachelor's degree in CS, cybersecurity, engineering, or related field.
  • 10+ years in software engineering, application security, or related roles.
  • 6+ years designing and implementing security architecture for IT systems.
  • 6+ years addressing OWASP Top 10, insecure auth, injection, deserialization, API abuse.
  • 6+ years securing data at rest, in transit, and in use across Microsoft technologies.
  • 6+ years threat modeling and security architecture reviews.
  • 6+ years securing APIs, web apps, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Strong understanding of secure coding practices in Java, .NET, JavaScript/TypeScript, or Python.
  • Experience with IAM technologies: OAuth 2.0, OpenID Connect, SAML, JWT, RBAC/ABAC, PKI/TLS, encryption, secrets management.
  • Experience with data classification, encryption, DLP, privacy risk assessments, and database security.

Responsibilities

  • Define application security architecture principles, standards, patterns, reference architectures, and guardrails for web, mobile, API, microservice, and cloud-native apps.
  • Perform architecture reviews to identify trust boundaries, attack paths, data flows, gaps, risks, and controls.
  • Lead threat-modeling for new apps, major features, integrations, and high-risk changes.
  • Establish security requirements for authentication, authorization, encryption, secrets, logging, privacy, API protection, and data security.
  • Partner with engineering to integrate security throughout the SDLC, including secure code reviews and CI/CD.
  • Evaluate security tools: SAST, DAST, software composition analysis, container scans, API security testing, secret scanning.
  • Maintain vulnerability-management strategy with SLAs and remediation processes.
  • Assess third-party libraries, SaaS, and vendor components for security risks.
  • Design IAM patterns including MFA, SSO, RBAC/ABAC, and privileged access controls.
  • Secure hosting environments with Kubernetes, serverless, containers, and cloud IAM.
  • Define data protection architectures for data at rest, in transit, and in use across cloud and GIS platforms.
  • Implement data classification, encryption, DLP, privacy controls.
  • Establish centralized security logging and monitoring for apps, databases, APIs, and cloud.
  • Advise incident-response teams on application-layer threats and root cause analysis.
  • Maintain security architecture docs, risk registers, standards, and decision records.
  • Communicate risks and tradeoffs to engineers and executives.

Skills

Threat modeling
SSDLC
API security
IAM / IAM technologies
OAuth 2.0 / OpenID Connect
SAML / JWT
RBAC / ABAC
Kubernetes security
Cloud security (Azure, MS 365, Power &

Education

Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent

Tools

Esri ArcGIS
Kubernetes

Job description

Application Security Architect

Location: Richmond, Virginia
Duration: 10 Months
Work Arrangement: Hybrid
Interview: Web Cam + In-Person
Local Candidates Only

Work Arrangement

The selected candidate must be able to work onsite 4 days per week during the initial 90-day probationary period. Following successful completion of the probationary period, there may be an opportunity for a reduced onsite schedule; however, some weekly onsite presence will continue to be required.

Position Overview

We are seeking an experienced Application Security Architect to define, implement, and oversee application security strategies across enterprise IT initiatives.

The Application Security Architect will establish and mature Secure Software Development Lifecycle (SSDLC) practices across a hybrid technology ecosystem that includes complex web applications, APIs, microservices, cloud-native solutions, AI-enabled applications, enterprise GIS platforms, and low-code/no-code technologies.

This role will also lead data protection, data governance, privacy, and security architecture initiatives. The successful candidate will define how structured, unstructured, and spatial/GIS data are classified, encrypted, stored, accessed, monitored, and protected across enterprise cloud and data platforms.

The architect will partner closely with application development, infrastructure, cloud, data, and cybersecurity teams to conduct threat modeling, perform secure architecture reviews, establish security standards, and ensure applications and platforms follow applicable security and compliance requirements.

Core Responsibilities
  • Define application security architecture principles, standards, patterns, reference architectures, and security guardrails for web, mobile, API, microservice, and cloud-native applications.

  • Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, risks, and appropriate compensating controls.

  • Lead and facilitate threat-modeling activities for new applications, major features, integrations, and high-risk technology changes.

  • Establish repeatable security requirements covering authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data security.

  • Partner with software engineering teams to integrate security throughout the SDLC, including secure code reviews, CI/CD pipelines, infrastructure as code, security testing, release approvals, and production monitoring.

  • Evaluate and guide the implementation of security tools and processes, including SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime application protection.

  • Establish and maintain an application vulnerability-management strategy, including severity criteria, remediation SLAs, exception processes, risk acceptance, and verification of remediation.

  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security and supply-chain risks.

  • Design identity and access-management patterns incorporating least privilege, MFA, SSO, service-to-service authentication, RBAC, ABAC, and privileged-access controls.

  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless platforms, containers, CI/CD infrastructure, cloud IAM, network segmentation, and secrets-management solutions.

  • Define and implement security architectures for data at rest, in transit, and in use across enterprise cloud, database, CRM, productivity, low-code/no-code, and GIS platforms.

  • Establish data classification, encryption, DLP, privacy, and data-protection controls for sensitive enterprise information.

  • Implement granular data-access controls, including RBAC, row-level security, column-level encryption, dynamic data masking, database auditing, and activity monitoring.

  • Establish centralized security logging and monitoring capabilities for applications, databases, APIs, and cloud environments.

  • Advise incident-response teams on application-layer security threats and participate in root-cause analysis following security incidents.

  • Maintain application-security architecture documentation, security decision records, architecture diagrams, risk registers, security standards, and exception documentation.

  • Communicate security risks, architectural tradeoffs, and remediation strategies effectively to engineers, technical leadership, product teams, executives, and nontechnical stakeholders.

Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.

  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles.

  • 6+ years of experience designing and implementing security architecture for IT systems.

  • 6+ years of experience applying secure software-development principles and addressing common application security risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.

  • 6+ years of experience designing and implementing end‑to‑end security architectures for data at rest, in transit, and in use across Microsoft technologies such as Azure, Microsoft 365, Power Platform, Dynamics 365, and SQL Server.

  • 6+ years of demonstrated experience with threat modeling and security architecture reviews.

  • 6+ years of experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.

  • Strong understanding of secure coding practices in one or more common technology ecosystems, including Java, .NET, JavaScript/TypeScript, or Python.

  • Strong experience with identity and access-management technologies and protocols, including OAuth 2.0, OpenID Connect, SAML, JWT, RBAC/ABAC, PKI/TLS, encryption, and secrets management.

  • Experience with data classification, encryption, DLP, privacy risk assessments, database security, and data‑access controls.

  • Ability to analyze security architecture and identify vulnerabilities, attack paths, trust boundaries, and appropriate mitigation strategies.

  • Strong written and verbal communication skills.

  • Ability to create and maintain architecture diagrams, security standards, risk assessments, security documentation, and actionable remediation plans.

  • Ability to communicate complex technical security risks and tradeoffs to both technical and nontechnical stakeholders.

Preferred Qualifications
  • Experience working in regulated environments such as financial services, healthcare, government, insurance, or payments.

  • Experience implementing DevSecOps programs and security automation at scale.

  • Familiarity with privacy engineering, data classification, data governance, and compliance frameworks.

  • Experience with security architecture and security controls within Esri ArcGIS or other enterprise GIS platforms.

  • Experience conducting or coordinating penetration testing and translating findings into sustainable architectural and security improvements.

  • Experience with cloud‑security architecture and security automation.

  • Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant cloud/vendor security certifications.

Skill Matrix

Skill Matrix Skill Required / Desired Minimum Experience Software engineering, application security, security engineering, or related technical roles Required 10 Years Designing and implementing security architecture for IT systems Required 6 Years Secure software‑development principles and application risks, including OWASP Top 10, authorization, injection, deserialization, and API abuse Required 6 Years End‑to‑end security architecture across Azure, Microsoft 365, Power Platform, Dynamics 365, and SQL Server Required 6 Years Threat modeling and security architecture reviews Required 6 Years Securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads Required 6 Years Identity, OAuth 2.0, OpenID Connect, SAML, JWT, authorization, PKI/TLS, encryption, and secrets management Required 6 Years Security architecture documentation, diagrams, standards, risk assessments, and remediation plans Required 10 Years Experience in regulated environments such as financial services, healthcare, government, or payments Highly Desired 6 Years Penetration testing coordination and translating findings into architectural improvements Highly Desired 6 Years DevSecOps programs and security automation at scale Highly Desired 4 Years Privacy engineering, data classification, and compliance frameworks Highly Desired 4 Years Security architecture experience with Esri ArcGIS or enterprise GIS platforms Highly Desired 2 Years

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Architect - VA
Application Security Architect - VA

Nexiva Inc • Richmond (VA)

Hybrid
USD 180,000 - 240,000
Application Security Architect
Application Security Architect

American business solutions inc • Richmond (VA)

On-site
USD 130,000 - 185,000
Application Security Architect
Application Security Architect

Mbi Llc • Richmond (VA)

On-site
USD 130,000 - 170,000
Application Security Architect
Application Security Architect

My3tech • Richmond (VA)

On-site
USD 140,000 - 190,000
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Accord Technologies Inc. • Richmond (VA)

On-site
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Systems Architect
Systems Architect

Compunnel, Inc. • Irving (TX)

On-site
USD 140,000 - 190,000