Application Security Architect & Engineer

ADP, Inc.

McLean (VA)

Hybrid

USD 69,000 - 83,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Virginia Tax in McLean, VA is hiring an Application Security Architect & Engineer to partner with development teams, embed security into the SDLC, and lead vulnerability remediation efforts. The role is hybrid/remote with occasional onsite work and requires US citizenship or permanent residency.

Responsibilities include guiding secure design, training teams, and validating architecture against secure coding standards, cloud controls, and regulatory requirements.

Qualifications

  • Five+ years in application security.

Responsibilities

  • Provide security guidance and best practices for dev and ops teams.

Skills

Application security
Secure SDLC
Threat modeling
Cloud security
SIEM concepts

Education

CompTIA Security+
ISC2 CC (Certified in Cybersecurity)
OSCP
CCSP (Certified Cloud Security Professional)
CSSLP (Certified Secure Software Lifecycle Professional)
AWS Solutions Architect (Associate/Professional)
AWS Security Specialty

Tools

Splunk
InsightVM
Rapid7
Tenable
CyberArk
Jenkins
Veracode

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Application Security Architect & Engineer

3 days ago Requisition ID: 1108

Salary Range: $50.00 To $60.00 Hourly

ABOUT THE ROLE

Hybrid/Remote (Occasional onsite required)

Must be a US Citizen or Permanent Resident.

Virginia Tax is seeking an Application Security Engineer (ASE) with 5+ years of experience to join the Office of Technology under Joint Security Operations. In this role, the ASE serves as a dedicated security partner to application teams, providing guidance on secure design, vulnerability management, and secure development practices. The ASE works collaboratively across the SDLC to ensure security is embedded into application design, development, testing, and deployment. This includes supporting compliance requirements, delivering training and education, and assisting teams with vulnerability remediation efforts.

  • The successful candidate will identify and recommend improvements to improve the security of all Virginia Tax applications, promote secure coding and development practices, and contribute to ongoing initiatives that reduce risk and strengthen the agency’s overall security posture.

Responsibilities include but not limited to:

  • Provide security guidance, training, and best practices for development and operations teams.
  • Support secure software development by applying knowledge of SDLC, Agile, and Scrum methodologies.
  • Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
  • Promote and enforce secure coding standards and guidelines.
  • Review source code to identify vulnerabilities and recommend remediation strategies.
  • Analyze and secure modern web application architectures, including cloud, APIs, microservices, and client-server models.
  • Identify and address common vulnerabilities, including those outlined in the OWASP Top 10.
  • Support vulnerability remediation, patch management, and continuous improvement efforts.
  • Utilize application security testing tools such as SAST, DAST, IAST, and platforms like Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable.
  • Interpret and act on findings from SIEM systems, including Splunk.
  • Apply knowledge of common security controls and frameworks.
  • Ensure compliance with relevant security regulations and standards (e.g., NIST 800-53, IRS Pub 1075, PCI-DSS).
  • Implement and evaluate AWS cloud security controls and best practices.
  • Create, maintain, and review System Security Plans (SSPs).
  • Troubleshoot and resolve complex technical and security-related issues.
  • Stay current with evolving threats, technologies, and industry trends.
  • Develop detailed plans and communicate risks, impacts, and recommendations effectively.
  • Collaborate with application teams, QA engineers, and operations teams to integrate security into workflows.
  • Provide constructive, actionable feedback to application teams.
  • Communicate technical concepts clearly to both technical and non-technical audiences.
  • Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
  • Manage multiple tasks, prioritize effectively, and meet deadlines.
  • Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.

Required Skills/Experience:

  • Five or more years’ experience in application security.
  • Two or more years’ network or firewall/AWS Security Groups.
  • Experience with log collection, vulnerability scans and remediation, or privileged access management.
  • Strong understanding of security concepts, network protocols, and threat vectors.
  • Proficiency in SIEM,IDS/IPS, EDR,and other relevant security tools.
  • Excellent analytical and problem-solving skills.
  • Strong communication, collaboration, and documentation skills.
  • Ability to work independently and as part of a team in a fast-paced environment.
  • Have experience and a strong knowledge of the following:
  • Splunk, Insigh tVM Rapid7, Tenable, CyberArk, Jenkins, Veracode
  • Linux and Windows Operating Systems, Baseline hardening of operating systems
  • IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall
  • At least one of these certs below is REQUIRED:
    • CompTIA Security+
    • ISC2 CC (Certified in Cybersecurity)
    • Offensive Security Certified Professional (OSCP)
    • CCSP (Certified Cloud Security Professional)
    • CSSLP (Certified Secure Software Lifecycle Professional)
  • At least one of these certs below is highly DESIRED (Independently and or with one of the above)
    • AWS Solutions Architect (Associate/Professional)
    • AWS Security Specialty
    • At least one of the any is DESIRED
    • CompTIAPenTest+
    • Certified Ethical Hacker (CEH),GIAC Certified Intrusion Analyst (GCIA
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect – Contract Position
Application Security Architect – Contract Position

BranCore Technologies • Richmond (VA)

On-site
USD 140,000 - 190,000
Onsite 4 days/week during probation
Contract extension possibility
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Sr. IT Application Security Engineer (USC or Green Card a must)
Sr. IT Application Security Engineer (USC or Green Card a must)

Creative Solutions Services, LLC • Reston (VA)

Hybrid
USD 150,000 - 180,000
Application Security Engineer
Application Security Engineer

WorkForce Unlimited • Salem (VA)

Hybrid
USD 110,000 - 150,000
APPLICATION SECURITY ENGINEER
APPLICATION SECURITY ENGINEER

Target Labs, Inc • Rockville (MD)

On-site
USD 100,000 - 130,000
VDOT Application Security Architect
VDOT Application Security Architect

Derex Technologies Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Engineer
Application Security Engineer

Hampton North • United States

Remote
USD 110,000 - 150,000
Security Operations Team Lead
Security Operations Team Lead

Commonwealth of VA Careers • Richmond (VA)

Hybrid
USD 120,000 - 140,000
Job stability
Telework options
Paid holidays
+3
Security Engineer
Security Engineer

Inadev • Reston (VA)

Hybrid
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Eliassen Group • Washington

On-site
USD 90,000 - 120,000