VDOT Application Security Architect

Derex Technologies Inc

Richmond (VA)

Hybrid

USD 140,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Derex Technologies Inc is seeking an Application Security Architect to define and oversee security across enterprise IT initiatives, with a focus on secure SDLC, threat modeling, and data protection across cloud and on-premises environments.

The role requires 10+ years in related fields, a Bachelor’s degree or equivalent, and strong communication to engineers and executives. Hybrid work with on-site requirements in Virginia. CISSP/CSSLP/GIAC preferred.

Qualifications

  • Bachelor’s degree in CS, cybersecurity, engineering, or equivalent experience.
  • 10+ years in software engineering, application security, or related roles, with 2+ years designing security architecture.
  • Strong knowledge of secure SDLC, OWASP Top 10, and security best practices.

Responsibilities

  • Define app-security architecture principles and guardrails for web, mobile, API, microservices and cloud-native systems.
  • Lead threat modeling for new apps and major features; review designs for security gaps.
  • Establish repeatable security requirements for authentication, encryption, logging, and data protection.

Skills

SSDLC
Threat Modeling
Security Architecture
OWASP Top 10
Cloud Security
Identity & Access

Education

Bachelor’s degree or equivalent

Tools

Azure
SQL Server
Dynamics 365
Power Platform
ArcGIS

Job description

Derex Technologies Inc specializes in providing IT consulting, staffing solutions and software services. Globally headquartered in Harrison New Jersey since 1996 Derex delivers the highest quality technology professionals and an array of customized IT talent solutions designed to improve productivity and drive results to global clients throughout North America.

With over two decades of unparalleled experience, Derex provides supports to its clientele, across such industries as Systems Integration, Banking and Finance, Telecommunications, Pharmaceutical and Life Sciences, Energy, Healthcare, Technology, Transportation, and local and federal Government agencies.

Job Description

Position: VDOT Application Security Architect

Interview : Both Web Cam and In Person Interview

Job : Hybrid

*Local candidates only please

*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.

VDOT is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.

This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.

Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.

Core responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required qualifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
  • Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Additional Information

All your information will be kept confidential according to EEO guidelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect – Contract Position
Application Security Architect – Contract Position

BranCore Technologies • Richmond (VA)

On-site
USD 140,000 - 190,000
Onsite 4 days/week during probation
Contract extension possibility
Information Technology Security Analyst
Information Technology Security Analyst

V Group Inc. • Richmond (VA)

On-site
USD 80,000 - 120,000
Application Security Architect & Engineer
Application Security Architect & Engineer

ADP, Inc. • McLean (VA)

Hybrid
USD 69,000 - 83,000
Senior Security Architect
Senior Security Architect

DirectViz Solutions, LLC • Washington

On-site
USD 120,000 - 150,000
Competitive compensation
Comprehensive medical plans
401k match
+2
Cloud Security Architect / Engineer
Cloud Security Architect / Engineer

Triumph Enterprises, Inc • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Network & Security Architect
Network & Security Architect

Vt Arc • Colorado Springs (CO)

On-site
USD 160,000 - 200,000
Program Manager – Data and GIS Governance
Program Manager – Data and GIS Governance

Jobtailor • Richmond (VA)

On-site
USD 130,000 - 170,000
IT Security Architect
IT Security Architect

DataStaff, Inc. • Richmond (VA)

Hybrid
USD 114,000 - 197,000
Medical insurance
Vision insurance
401(k) plan
+3
Network & Security Architect
Network & Security Architect

Virginia Tech Applied Research Corporation • Colorado Springs (CO)

On-site
USD 160,000 - 200,000
Information Systems Security Analyst (ISSA) - Dahlgreen, VA
Information Systems Security Analyst (ISSA) - Dahlgreen, VA

Yakshna Solutions, Inc. • Herndon (VA)

On-site
USD 75,000 - 100,000
401(k)
Health insurance
Dental insurance
+4