OWASP API Azure OAuth SAML Architect

COOLSOFT

Richmond (VA)

Hybrid

USD 165,000 - 248,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid
Onsite 4 days/week during probation
Local candidates only

Job summary

VDOT seeks an Application Security Architect to define, embed, and oversee security strategies across enterprise IT initiatives in a hybrid environment in Richmond, VA. This role focuses on SSDLC across web apps, cloud-native systems, and data protection.

The position requires a BS in a technical field and 10+ years in software engineering or security, with CISSP/CCSP/GIAC or similar credentials highly desired. On-site 4 days per week during probation; local candidates preferred.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, engineering, or related field (or equivalent practical experience).
  • 10+ years in software engineering, application security, security engineering.

Responsibilities

  • Define application-security architecture principles, standards, and guardrails for web, mobile, API, and cloud-native systems.
  • Lead threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish security requirements for authentication, authorization, encryption, secrets management, and data protection.
  • Collaborate with engineers to integrate security across the SDLC, including CI/CD, IaC, testing, and production monitoring.
  • Evaluate and guide the use of security tooling (SAST, DAST, container scanning, API security testing).
  • Design identity and access-control patterns with MFA/SSO, RBAC/ABAC, and least-privilege principles.
  • Work with cloud and platform teams to secure hosting environments (Kubernetes, serverless, containers, CI/CD).
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis.

Skills

IT Systems Engineering
OWASP
API
Azure OAuth SAML

Education

Bachelor's degree in computer science, cybersecurity, engineering, or related field

Job description

OWASP API Azure OAuth SAML Architect

(Jobs in Richmond, VA)

Job title Architect

Job location in Richmond, VA

Skills required IT Systems Engineering, OWASP, API, Azure OAuth SAML

Job type Contract

Duration 10 Months

Compensation DOE

Start date :9/21/2026

End Date : 06/30/2027

Submission deadline :9/16/2026

Client Info : VDOT

Note:

  • Hybrid
  • Both Web Cam and In Person Interview
  • Local candidates only please

Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.

Description:

Clint is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.

This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.

Bachelors degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.

Core responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, micro service, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required qualifications
  • Bachelors degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10+ years in software engineering, application security, security engi

EOE Protected Veterans/Disability

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident
Application Security Architect | W2/1099 | Applicant Must Be Current VA Resident

V.L.S. Systems, Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Application Security Architect
Application Security Architect

Ampcus, Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Onsite 4 days/week
VDOT Application Security Architect
VDOT Application Security Architect

TOMORROW HIRE • Richmond (VA)

Hybrid
USD 112,000 - 139,000
Sr Application Security Architect
Sr Application Security Architect

Dia Software Solutions • Richmond (VA)

Hybrid
USD 130,000 - 170,000
VDOT Application Security Architect
VDOT Application Security Architect

Derex Technologies Inc • Richmond (VA)

Hybrid
USD 140,000 - 180,000
Solutions Architect (Azure)
Solutions Architect (Azure)

Govserviceshub • Richmond (VA)

Hybrid
USD 90,000 - 110,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Architect - Richmond, VA (Hybrid)
Application Security Architect - Richmond, VA (Hybrid)

Yakshna Solutions, Inc. • Richmond (VA)

Hybrid
USD 130,000 - 140,000
Benefits package
Application Security Architect & Engineer
Application Security Architect & Engineer

ADP, Inc. • McLean (VA)

Hybrid
USD 69,000 - 83,000
IT Security Architect
IT Security Architect

DataStaff, Inc. • Richmond (VA)

Hybrid
USD 114,000 - 197,000
Medical insurance
Vision insurance
401(k) plan
+3