Application Security Architect – Contract Position

BranCore Technologies

Richmond (VA)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Onsite 4 days/week during probation
Contract extension possibility

Job summary

BranCore Technologies is seeking an Application Security Architect to define and oversee SSDLC across enterprise IT initiatives in a hybrid ecosystem spanning web apps, cloud-native systems, and GIS platforms.

You will lead data protection strategies, govern privacy posture, and classify/encrypt data across cloud data platforms while ensuring compliance with Virginia standards. Strong communication and deep security architecture experience are essential.

Qualifications

  • Bachelor’s degree or equivalent practical experience.
  • 10+ years in software engineering or security roles, incl. 2+ years designing security architecture.
  • Strong knowledge of OWASP Top 10 and secure coding practices.
  • End-to-end security for data-at-rest, in-transit, and in-use across MS stack (Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS).
  • Threat modeling experience and security architecture reviews.
  • Experience securing APIs, web apps, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Knowledge of identity, OAuth2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, secrets management.
  • Ability to explain risks to engineers, PMs, execs, and nontechnical stakeholders.
  • Strong written communication for architecture diagrams, standards, risk assessments.

Responsibilities

  • Define application-security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture/design reviews; identify trust boundaries, attack paths, data flows, gaps, and controls.
  • Lead or facilitate threat modeling for new apps, major features, and high-risk changes.
  • Establish repeatable security requirements for authentication, encryption, data protection, and privacy.
  • Partner with engineers to integrate security into the SDLC, including code review and CI/CD.
  • Evaluate security tools (SAST, DAST, SCA, container scanning, API security).
  • Define vulnerability-management approach for apps and dependencies; set SLAs and remediation processes.
  • Assess third-party libraries and vendor components for security risk.
  • Design IAM patterns (RBAC, MFA/SSO, service-to-service auth) and centralize audits.
  • Secure hosting environments (Kubernetes, serverless, containers, cloud IAM, network segmentation).
  • Advise incident-response on app-layer threats and contribute to post-incident improvements.
  • Maintain architecture docs, risk registers, and decision records.

Skills

Application security
Threat modeling
Security architecture
Cloud security
CI/CD security
APIs security
Identity & access management
Secure coding concepts
Communication
Architecture documentation

Education

Bachelor’s degree in CS/ cybersecurity/ engineering

Tools

SAST
DAST
Microsoft Purview

Job description

Contract Length: 9 months with the possibility of extending based on project need.

Candidate residing in Richmond, VA area is required.

*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.

Client is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.

This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.

Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.

Core responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required qualifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
  • Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Required/Desired Skills
  • Software engineering, application security, security engineering, or related technical roles. Required, 10 Years
  • Experience in designing and implementing security architecture for IT systems. Required, 6 Years
  • Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse. Required, 6 Years
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365). Required, 6 Years
  • Demonstrated experience with threat modeling and security architecture reviews. Required, 6
    Years
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads. Required, 6 Years
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices. Required, 6 Years
  • Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans. Required, 10 Years
  • Experience in a regulated environment such as financial services, healthcare, government, or payments. Highly desired, 6 Years
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements. Highly desired, 6 Years
  • Experience implementing DevSecOps programs and security automation at scale. Highly desired, 4 Years
  • Familiarity with privacy engineering, data classification, and compliance frameworks. Highly desired, 4 Years
  • Experience with security architectures in Esri’s ArcGIS platform. Highly desired, 2 Years
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VDOT Application Security Architect
VDOT Application Security Architect

Derex Technologies Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect & Engineer
Application Security Architect & Engineer

ADP, Inc. • McLean (VA)

Hybrid
USD 69,000 - 83,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
NET Application Architect/Developer w/C# -
NET Application Architect/Developer w/C# -

Beyond SOF • Richmond (VA)

On-site
USD 120,000 - 180,000
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2
Solutions Architect (Azure)
Solutions Architect (Azure)

Govserviceshub • Richmond (VA)

Hybrid
USD 90,000 - 110,000
Application Security Engineer
Application Security Engineer

WorkForce Unlimited • Salem (VA)

Hybrid
USD 110,000 - 150,000
Application Security Engineer
Application Security Engineer

Hampton North • United States

Remote
USD 110,000 - 150,000
Application Architect
Application Architect

Electrosoft • Arlington (VA)

On-site
USD 130,000 - 170,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000