An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Nexiva Inc. is seeking an Application Security Architect in a hybrid Richmond, VA setting. The candidate will define, embed, and oversee SSDLC-focused security strategies across complex apps, cloud-native systems, and GIS/enterprise platforms.
Required 15+ years of experience, strong threat modeling, and architecture leadership. Bachelor’s degree or equivalent plus industry certifications desired. Onsite presence is required 4 days/week during probation with potential reduced onsite later.
Application Security Architect, (Hybrid) Richmond, VA
Need Senior 15+years Candidate
Local candidates only, In-person interview.
The candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.
Client is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with client and client's security standards.
Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Core responsibilities
Required qualifications
Preferred qualifications
Required/Desired Skills
Skill
Required /Desired
Amount of experience you have
Experience you have in years
Software engineering, application security, security engineering, or related technical roles
Required
10
Experience in designing and implementing security architecture for IT systems
Required
6
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse
Required
6
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)
Required
6
Demonstrated experience with threat modeling and security architecture reviews
Required
6
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads
Required
6
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices
Required
6
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans
Required
10
Experience in a regulated environment such as financial services, healthcare, government, or payments
Highly desired
6
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
Highly desired
6
Experience implementing DevSecOps programs and security automation at scale
Highly desired
4
Familiarity with privacy engineering, data classification, and compliance frameworks
Highly desired
4
Experience with security architectures in Esri's ArcGIS platform
Highly desired
2