Senior Application Security Architect Cloud Azure & DevSecOps

Rose International

Richmond (VA)

Hybrid

USD 117,000 - 124,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Rose International seeks a Senior Application Security Architect specializing in Cloud Azure & DevSecOps in the Richmond, VA area. The role requires on-site presence 2-3 days weekly, with hybrid work arrangements in a government/staffing setting.

You will lead SSDLC security architectures, threat modeling, and security-program implementation across Azure, O365, Power Platform, and GIS-related platforms. Ten years in related roles, strong API/security experience, and CISSP/CSSLP/CCSP/GIAC

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience)
  • Certifications such as CISSP, CSSLP, CCSP, GIAC are highly desired
  • Experience in security architectures across cloud and enterprise environments

Responsibilities

  • Define application-security architecture principles, standards, and guardrails for web, API, microservices, and cloud-native systems
  • Lead threat modeling and security-architecture reviews across new applications and high-risk changes
  • Partner with engineers to integrate security through the SDLC, including CI/CD, IaC, and secure coding practices
  • Define vulnerability-management approaches for applications and dependencies and track remediation
  • Secure APIs, web apps, and distributed systems in cloud platforms and CI/CD pipelines

Skills

API
CISSP
Engineering
Security

Education

Bachelor's Degree

Job description

Date Posted: 09/14/2026

Hiring Organization: Rose International

Position Number: 507389

Industry: Government/Staffing

Job Title: Senior Application Security Architect Cloud Azure & DevSecOps

Job Location: Richmond, VA, USA, 23173

Work Model: Hybrid

Work Model Details: This position requires on-site 2-3 days a week

Shift: Regular

Employment Type: Temporary

FT/PT: Full-Time

Estimated Duration (In months): 10

Min Hourly Rate($): 85.00

Max Hourly Rate($): 90.00

Must Have Skills/Attributes: API, CISSP, Engineering, Security

Experience Desired: Experience with security architectures in Esri's ArcGIS platform (2 yrs); Familiarity with privacy engineering, data classification, and compliance frameworks (4 yrs); Experience implementing Dev SecOps programs and security automation at scale (4 yrs); Experience in designing and implementing security architecture for IT systems (6 yrs); Experience in a regulated environment such as financial services, healthcare, government, or payment (6 yrs); Software engineering, application security, security engineering, or related technical roles (10 yrs); Demonstrated experience with threat modeling and security architecture reviews (6 yrs)

Required Minimum Education: Bachelor’s Degree

Preferred Certifications/Licenses: CISSP, CSSLP, CCSP, GIAC

Job Description

***Only qualified Senior Application Security Architect Cloud Azure & DevSecOps located in the Richmond, VA area will be considered due to the position requiring an onsite presence***

Required Education
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience)
Preferred Certifications
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired
Required Skills
  • Software engineering, application security, security engineering, or related technical roles (10 Years)
  • Experience in designing and implementing security architecture for IT systems (6 Years)
  • Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse (6 Years)
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) (6 Years)
  • Demonstrated experience with threat modeling and security architecture reviews (6 Years)
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads (6 Years)
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices (6 Years)
  • Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans (10 Years)
Preferred Skills
  • Experience in a regulated environment such as financial services, healthcare, government, or payments
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
  • Experience implementing DevSecOps programs and security automation at scale
  • Familiarity with privacy engineering, data classification, and compliance frameworks
  • Experience with security architectures in Esri's ArcGIS platform

About the Role: This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with the client

Job Responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation

Interview Process: Both webcam and in-person interviews

Benefits

For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.

California Pay Equity

For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.

Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect – Contract Position
Application Security Architect – Contract Position

BranCore Technologies • Richmond (VA)

On-site
USD 140,000 - 190,000
Onsite 4 days/week during probation
Contract extension possibility
Database Administrator
Database Administrator

Rose International • Austin (TX)

Hybrid
USD 96,000 - 103,000
Senior Backend Java Engineer
Senior Backend Java Engineer

Rose International • Chicago (IL)

Hybrid
USD 96,000 - 103,000
Application Security Architect
Application Security Architect

Ampcus, Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Onsite 4 days/week
Senior UIUX Developer Accessibility Design Systems Angular WCAG
Senior UIUX Developer Accessibility Design Systems Angular WCAG

Rose International • Des Moines (IA)

Hybrid
USD 90,000 - 101,000
Full Stack Software Engineer Java, Spring Boot, Angular
Full Stack Software Engineer Java, Spring Boot, Angular

Rose International • Rutherford (NJ)

On-site
USD 90,000 - 102,000
Lead AI Software Engineer
Lead AI Software Engineer

Rose International • Chicago (IL)

Hybrid
USD 110,000 - 117,000
Application Security Architect - Richmond, VA (Hybrid)
Application Security Architect - Richmond, VA (Hybrid)

Yakshna Solutions, Inc. • Richmond (VA)

Hybrid
USD 130,000 - 140,000
Benefits package
System Engineer- Cyber Security Engineering Focus
System Engineer- Cyber Security Engineering Focus

PowerToFly • Vienna (VA)

On-site
USD 117,000 - 198,000
Health insurance
401(k)
Profit-sharing programs
+2
System Engineer- Cyber Security Engineering Focus
System Engineer- Cyber Security Engineering Focus

Esri • Redlands (CA)

On-site
USD 117,520 - 197,600
Health and welfare benefits
401(k) and profit-sharing programs
Paid holidays and vacation leave