Job Summary:
The VDOT Application Security Architect is responsible for defining, embedding, and overseeing application security strategies across enterprise IT initiatives within a state-wide transportation ecosystem. This role focuses on implementing Secure Software Development Lifecycle (SSDLC) practices across a hybrid technology environment, including web applications, AI solutions, cloud-native platforms, and GIS systems. The architect leads data protection, governance, and privacy efforts while ensuring compliance with Commonwealth of Virginia and VITA security standards.
Responsibilities:
- Define application security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
- Conduct architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
- Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
- Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
- Collaborate with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
- Evaluate and guide the use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
- Define vulnerability management processes for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
- Assess security risks of third-party libraries, open-source dependencies, SaaS integrations, and vendor components.
- Design identity and access-control patterns including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged access controls.
- Work with cloud and platform teams to secure hosting environments such as Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
- Advise incident response teams on application-layer threats and contribute to root cause analysis and security improvements post-incident.
- Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Skills & Certifications:
- Bachelor's degree in computer science, cybersecurity, engineering, or related field, or equivalent practical experience.
- 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture.
- Strong understanding of secure software development principles and common application risks such as OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
- Experience designing and implementing end-to-end security architectures for data-at-rest, in-transit, and in-use across platforms including Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS.
- Expertise in enforcing granular data access controls, centralized audit logging, and activity monitoring aligned with VITA SEC 530 standards.
- Demonstrated experience with threat modeling and security architecture reviews.
- Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
- Proficiency in secure coding practices in ecosystems such as Java, .NET, JavaScript/TypeScript, or Python.
- Knowledge of identity and access management technologies including OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, and secrets management.
- Strong written communication skills for creating architecture diagrams, standards, risk assessments, and remediation plans.
Preferred Skills & Certifications:
- Experience in regulated environments such as financial services, healthcare, government, or payments.
- Experience implementing DevSecOps programs and security automation at scale.
- Familiarity with privacy engineering, data classification, and compliance frameworks.
- Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security certifications, or other relevant vendor credentials.
- Experience conducting or coordinating penetration testing and translating results into architectural improvements.
- Experience with security architectures in Esri's ArcGIS platform.
Special Considerations:
- Candidate must work onsite 4 days per week during an initial 90-day probationary period.
- Post-probation onsite requirements may be reduced but some weekly onsite presence remains mandatory.
- Candidate must physically reside within the United States for the duration of the assignment.
- Compliance with Commonwealth of Virginia security policies prohibiting offshore IT contractors is required.
- Candidate must agree to work onsite at least once a month after the probation period.
Scheduling:
- Work is primarily onsite 4 days per week during the first 90 days.
- After probation, onsite workdays may be reduced but regular onsite presence is required weekly.
- Work schedule aligns with typical business hours and state agency requirements.