CybersecurityJobs.io
← Back to all jobs

Job Description

Contract Application Security Architect in Richmond, VA (onsite). absiusa is looking for an experienced application security leader to define secure architecture direction and make security practices repeatable across the full SDLC, from design reviews and threat modeling to vulnerability management and cloud-native hosting.

What you’ll help improve

You will set application security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, APIs, microservices, and cloud-native systems. The role also focuses on integrating security into delivery pipelines and helping teams reduce risk through consistent authentication and authorization controls, secure data practices, and measurable vulnerability remediation.

Responsibilities

  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails across web, mobile, API, microservice, and cloud-native systems.
  • Conduct architecture and design reviews by mapping trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements covering authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security across the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess security risk in third-party libraries, open-source dependencies, SaaS integrations, and vendor components.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Collaborate with cloud/platform teams to secure application hosting environments including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.

Requirements

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience).
  • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • Ability to design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS using automated classification (such as Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs).
  • Experience enforcing granular data access controls including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking, plus centralized database audit logging and activity monitoring pipelines aligned to VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding in one or more ecosystems such as Java, .NET, JavaScript/TypeScript, or Python.
  • Experience with identity and security standards and practices including OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets management.
  • Ability to explain technical risks and tradeoffs to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including architecture diagrams, standards, risk assessments, and actionable remediation plans.

Preferred qualifications

  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.

Technologies you may work with

Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS, Microsoft Purview, OWASP Top 10, VITA SEC 530, SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, runtime protection, OAuth 2.0, OpenID Connect, SAML, JWTs, PKI/TLS, RBAC, ABAC, Row-Level Security, Column-Level Encryption, dynamic masking, Kubernetes, serverless, CI/CD pipelines, infrastructure as code, Java, .NET, JavaScript/TypeScript, Python, MFA, SSO, DLP rules, DPIAs, encryption

Similar Jobs