Application Security Architect & Engineer

Mbi Llc

Richmond (VA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity firm is seeking an Application Security Architect & Engineer in Richmond, Virginia. The role involves providing security guidance, evaluating software architecture for security risks, and implementing security standards. Required qualifications include five years of application security experience and certifications like CompTIA Security+ and OSCP. The ideal candidate will possess strong analytical skills and a solid understanding of security concepts. This position offers full-time work with a collaborative team environment.

Qualifications

  • Five or more years’ experience in application security.
  • Strong understanding of security concepts, network protocols, and threat vectors.
  • Excellent analytical and problem-solving skills.

Responsibilities

  • Provide security guidance and best practices for development and operations teams.
  • Evaluate software architecture for security risks and DevSecOps alignment.
  • Promote secure coding standards.

Skills

Application Security
Network or Firewall/AWS Security Groups
Log collection and vulnerability management
Security tools proficiency (SIEM, IDS/IPS)
Analytical skills
Strong communication skills
Team collaboration

Education

CompTIA Security+
Certified in Cybersecurity (ISC2 CC)
Offensive Security Certified Professional (OSCP)
CCSP
CSSLP

Tools

Splunk
Terraform
Jenkins
Tenable
Rapid7
PowerShell

Job description

Application Security Architect & Engineer

  • 04-Mar-2026 to 18-Mar-2026 (UTC)
  • Full Time
  • 40 Weekly Hours
Responsibilities
  • Provide security guidance, training, and best practices for development and operations teams.
  • Support secure software development by applying knowledge of SDLC, Agile, and Scrum methodologies.
  • Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
  • Promote and enforce secure coding standards and guidelines.
  • Review source code to identify vulnerabilities and recommend remediation strategies.
  • Analyze and secure modern web application architectures, including cloud, APIs, microservices, and client–server models.
  • Identify and address common vulnerabilities, including those outlined in the OWASP Top 10.
  • Support vulnerability remediation, patch management, and continuous improvement efforts.
  • Utilize application security testing tools such as SAST, DAST, IAST, and platforms like Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable.
  • Interpret and act on findings from SIEM systems, including Splunk.
  • Apply knowledge of common security controls and frameworks.
  • Ensure compliance with relevant security regulations and standards (e.g., NIST 800?53, IRS Pub 1075, PCI?DSS).
  • Implement and evaluate AWS cloud security controls and best practices.
  • Create, maintain, and review System Security Plans (SSPs).
  • Troubleshoot and resolve complex technical and security-related issues.
  • Stay current with evolving threats, technologies, and industry trends.
  • Develop detailed plans and communicate risks, impacts, and recommendations effectively.
  • Collaborate with application teams, QA engineers, and operations teams to integrate security into workflows.
  • Provide constructive, actionable feedback to application teams.
  • Communicate technical concepts clearly to both technical and non?technical audiences.
  • Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
  • Manage multiple tasks, prioritize effectively, and meet deadlines.
  • Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.
Required Skills & Experience
  • Five or more years’ experience in application security.
  • Two or more years’ network or firewall/AWS Security Groups.
  • Experience with log collection, vulnerability scans and remediation, or privileged access management.
  • Strong understanding of security concepts, network protocols, and threat vectors.
  • Proficiency in SIEM,IDS/IPS, EDR,and other relevant security tools.
  • Excellent analytical and problem-solving skills.
  • Strong communication, collaboration, and documentation skills.
  • Ability to work independently and as part of a team in a fast-paced environment.
  • Splunk, Insigh tVM Rapid7, Tenable, CyberArk, Jenkins, Veracode
  • Linux and Windows Operating Systems, Baseline hardening of operating systems
  • IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall
Required Certifications
  • CompTIA Security+
  • ISC2 CC (Certified in Cybersecurity)
  • Offensive Security Certified Professional (OSCP)
  • CCSP (Certified Cloud Security Professional)
  • CSSLP (Certified Secure Software Lifecycle Professional)
Highly Desired Certifications
  • AWS Solutions Architect (Associate/Professional)
  • AWS Security Specialty
Desired Certifications
  • Certified Ethical Hacker (CEH), GIAC Certified Intrusion Analyst (GCIA
Skill Matrix
  • Application Security - Required - 5 years
  • Network or Firewall/AWS security Groups - Required - 2 years
  • Infrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning. - Required - 2 years
  • Experience with log collection, vulnerability scans and remediation, or privileged access management - Required - 4 years
  • Proficiency in SIEM, IDS/IPS, EDR, and other relevant security tools. - Required - 4 years
  • Networking & Hybrid Connectivity: Solid understanding of routing, firewalls, AWS Direct Connect, and VPNs in a hybrid cloud environment. - Required - 4 years
  • One REQUIRED: CompTIA Security+, ISC2 CC (Certified in Cybersecurity), Offensive Security Certified Professional (OSCP), CCSP, or CCLP. UPLOAD COPY!! - Required
  • CI/CD & DevOps: Experience with GitLab CI/CD, Jenkins, or AWS CodePipeline for automated, secure deployments. - Highly desired
  • Linux and Windows Operating Systems, Baseline hardening of operating systems - Highly desired - 2 years
  • IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall - Highly desired - 2 years
  • One highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty - Highly desired
  • One of these is DESIRED: CompTIA PenTest+, Certified Ethical Hacker (CEH), or GIAC Certified Intrusion Analyst (GCIA) - Highly desired

Apply Now

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
IT Security Specialist
IT Security Specialist

PlanIT Group, LLC • Reston (VA)

Remote
USD 100,000 - 130,000
Senior Delivery Consultant - Security
Senior Delivery Consultant - Security

Amazon Web Services (AWS) • Denver (CO)

On-site
USD 154,000 - 208,000
Health insurance
401(k) matching
Paid time off
+2
Senior Delivery Consultant - Security
Senior Delivery Consultant - Security

Amazon Web Services (AWS) • San Francisco (CA)

On-site
USD 177,000 - 239,000