Senior Application Security Architect (Hybrid)

My3Tech

Richmond (VA)

Hybrid

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

My3Tech in Virginia seeks a senior Application Security Architect to lead security design for web, mobile, API, and cloud-native systems. You will collaborate with engineers to embed security into the SDLC and guide threat modeling and guardrail definitions.

The role requires deep experience in secure software development, identity, and data protection, with hands-on Microsoft stack expertise and container security. Hybrid work is offered.

Qualifications

  • 10+ years in software engineering or security engineering, including design of security architecture for IT systems.
  • 6+ years designing and implementing end-to-end security architectures for data-at-rest, data-in-transit, and data-in-use on Microsoft tech stack (Azure, O365, Power Platform, Dynamics 365).
  • Experience with OWASP Top 10 and secure software-development principles.
  • 6+ years of threat modeling and security architecture reviews.
  • 6+ years securing APIs, web apps, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • 6+ years identity, OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, encryption, and secrets-management practices.
  • Strong ability to explain technical risks to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills and ability to create architecture diagrams and risk assessments.

Responsibilities

  • Define application security architecture principles, standards, patterns, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews to identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code reviews, CI/CD, IaC, testing, release approval, and production monitoring.
  • Evaluate and guide the use of security tools (SAST, DAST, software composition analysis, container scanning, API security testing, secret scanning, runtime protection).
  • Define a vulnerability management approach for applications and dependencies with SLAs and remediation processes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor components for security risks.
  • Design identity and access-control patterns (least privilege, MFA/SSO, RBAC/ABAC, privileged-access controls).
  • Partner with cloud/platform teams to secure hosting environments (Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, secrets storage).
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements.
  • Maintain architecture documentation, decision patterns, risk registers, and exception docs.

Skills

Application security
Threat modeling
Security architecture
Secure SDLC
Cloud security
API security
Identity & access
Communication
Architecture diagrams

Education

Bachelor’s degree in CS/Cybersecurity/Engineering
Equivalent practical experience

Tools

Azure
O365
Power Platform
Dynamics 365
SQL Server
ArcGIS

Job description

My3Tech in Virginia seeks a senior Application Security Architect to lead security design for web, mobile, API, and cloud-native systems. You will collaborate with engineers to embed security into the SDLC and guide threat modeling and guardrail definitions.

The role requires deep experience in secure software development, identity, and data protection, with hands-on Microsoft stack expertise and container security. Hybrid work is offered.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior App Security Architect & Engineer (Hybrid/Remote)
Senior App Security Architect & Engineer (Hybrid/Remote)

ADP, Inc. • McLean (VA)

Hybrid
USD 69,000 - 83,000
Senior Application Security Architect - Hybrid/Remote (EST)
Senior Application Security Architect - Hybrid/Remote (EST)

Sas • Cary (NC)

Hybrid
USD 140,000 - 210,000
Comprehensive medical, prescription, 

401k plan
Tuition Assistance Program
+1
Senior App Security Architect - Hybrid in Richmond
Senior App Security Architect - Hybrid in Richmond

TOMORROW HIRE • Richmond (VA)

Hybrid
USD 112,000 - 139,000
Hybrid Application Security Architect: Enterprise & Cloud
Hybrid Application Security Architect: Enterprise & Cloud

Ampcus, Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Onsite 4 days/week
Senior App Security Architect - Cloud & DevSecOps
Senior App Security Architect - Cloud & DevSecOps

American business solutions inc • Richmond (VA)

On-site
USD 130,000 - 185,000
Senior Application Security Engineer — Hybrid (Azure DevSecOps)
Senior Application Security Engineer — Hybrid (Azure DevSecOps)

WorkForce Unlimited • Salem (VA)

Hybrid
USD 110,000 - 150,000
Senior Application Security Engineer - Hybrid NYC
Senior Application Security Engineer - Hybrid NYC

STEPS Talent • New York (NY)

Hybrid
USD 140,000 - 200,000
Senior Application Security Architect - Hybrid & Impact
Senior Application Security Architect - Hybrid & Impact

State Street • Quincy (MA)

Hybrid
USD 120,000 - 203,000
Senior SSDLC Security Architect – Hybrid/VA
Senior SSDLC Security Architect – Hybrid/VA

Dia Software Solutions • Richmond (VA)

Hybrid
USD 130,000 - 170,000
Hybrid App Security Architect - SSDLC & Data Protection
Hybrid App Security Architect - SSDLC & Data Protection

Ampcus Inc • Richmond (VA)

Hybrid
USD 140,000 - 190,000