Application Security Architect

vTech Solution

Washington

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

vTech Solution is seeking an experienced Application Security Architect to lead SSDLC implementation across a state-wide transportation ecosystem. The role covers web, AI, cloud-native, and GIS systems with a focus on data protection and privacy per applicable standards.

The architect will drive security reviews, threat modeling, and architecture documentation while guiding engineering teams through secure design and deployment. Onsite collaboration and governance are essential.

Qualifications

  • Bachelor's degree or equivalent practical experience in CS or related field.
  • 10+ years in software engineering, application security, or related roles including 2+ years designing security architecture.
  • Strong knowledge of OWASP Top 10 and secure coding practices.
  • Experience designing end-to-end security architectures across Azure, on-prem, and cloud-native platforms.
  • Experience with threat modeling and security architecture reviews.
  • Familiarity with DevSecOps, security automation, and security tooling.

Responsibilities

  • Define security architecture principles, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Lead reviews to identify trust boundaries, data flows, and security gaps; define compensating controls.
  • Facilitate threat modeling for new apps and high-risk changes.
  • Establish requirements for authentication, authorization, sessions, encryption, and data protection.
  • Collaborate with engineers to embed security in the SDLC, CI/CD, IaC, testing, and release processes.
  • Evaluate tools for SAST, DAST, software composition, container/image scanning, API security, and secrets management.
  • Define vulnerability management processes for apps and dependencies with SLAs and remediation workflows.
  • Assess security risks of third-party libraries, SaaS integrations, and vendor components.
  • Design IAM patterns including MFA/SSO, RBAC/ABAC, and privilege access controls.
  • Secure hosting environments (Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, secrets storage).
  • Advise incident response teams on application-layer threats and contribute to root cause analysis.
  • Maintain architecture docs, decision patterns, risk registers, and exception records.

Skills

SSDLC
Threat modeling
API security
CI/CD security
Identity & access mgmt
Cloud security

Education

Bachelor's degree in CS or related field

Tools

Azure
SQL Server
Dynamics 365
Power Platform
ArcGIS
SAST
DAST
Container scanning

Job description

Job Summary:

The VDOT Application Security Architect is responsible for defining, embedding, and overseeing application security strategies across enterprise IT initiatives within a state-wide transportation ecosystem. This role focuses on implementing Secure Software Development Lifecycle (SSDLC) practices across a hybrid technology environment, including web applications, AI solutions, cloud-native platforms, and GIS systems. The architect leads data protection, governance, and privacy efforts while ensuring compliance with Commonwealth of Virginia and VITA security standards.

Responsibilities:
  • Define application security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Conduct architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Collaborate with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide the use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define vulnerability management processes for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess security risks of third-party libraries, open-source dependencies, SaaS integrations, and vendor components.
  • Design identity and access-control patterns including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged access controls.
  • Work with cloud and platform teams to secure hosting environments such as Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident response teams on application-layer threats and contribute to root cause analysis and security improvements post-incident.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Skills & Certifications:
  • Bachelor's degree in computer science, cybersecurity, engineering, or related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture.
  • Strong understanding of secure software development principles and common application risks such as OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • Experience designing and implementing end-to-end security architectures for data-at-rest, in-transit, and in-use across platforms including Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS.
  • Expertise in enforcing granular data access controls, centralized audit logging, and activity monitoring aligned with VITA SEC 530 standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Proficiency in secure coding practices in ecosystems such as Java, .NET, JavaScript/TypeScript, or Python.
  • Knowledge of identity and access management technologies including OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, and secrets management.
  • Strong written communication skills for creating architecture diagrams, standards, risk assessments, and remediation plans.
Preferred Skills & Certifications:
  • Experience in regulated environments such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security certifications, or other relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into architectural improvements.
  • Experience with security architectures in Esri's ArcGIS platform.
Special Considerations:
  • Candidate must work onsite 4 days per week during an initial 90-day probationary period.
  • Post-probation onsite requirements may be reduced but some weekly onsite presence remains mandatory.
  • Candidate must physically reside within the United States for the duration of the assignment.
  • Compliance with Commonwealth of Virginia security policies prohibiting offshore IT contractors is required.
  • Candidate must agree to work onsite at least once a month after the probation period.
Scheduling:
  • Work is primarily onsite 4 days per week during the first 90 days.
  • After probation, onsite workdays may be reduced but regular onsite presence is required weekly.
  • Work schedule aligns with typical business hours and state agency requirements.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

VDOT Application Security Architect
VDOT Application Security Architect

TOMORROW HIRE • Richmond (VA)

Hybrid
USD 112,000 - 139,000
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

My3tech • Richmond (VA)

On-site
USD 140,000 - 190,000
VDOT Application Security Architect
VDOT Application Security Architect

TALENT Software Services • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Security Architect
Security Architect

Stellar Professionals • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

V Group Inc. • Richmond (VA)

On-site
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Ampcus Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

Ampcus, Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Onsite 4 days/week
Application Security Architect
Application Security Architect

Accord Technologies Inc. • Richmond (VA)

On-site
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000