Security Architect

Hybrid in Richmond, VA, US • Posted 4 hours ago • Updated 4 hours ago
Contract Independent
Contract Corp To Corp
Contract W2
9 Months
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Security Architect
  • CISSP
  • Cyber Security
  • Continuous Integration
  • Cloud Security
  • Cloud Computing
  • Cisco Certifications
  • ArcGIS
  • OWASP
  • OAuth
  • Network
  • Security Engineering
  • Threat Modeling
  • TLS
  • SAML
  • Root Cause Analysis
  • RBAC
  • PKI
  • DevSecOps
  • DLP
  • Data Flow
  • Data Security
  • Code Review
  • Esri
  • Encryption
  • Application Security Architect

Summary

  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
  • Required qualifications:
    • Bachelor s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
    • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
    • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
    • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
    • Demonstrated experience with threat modeling and security architecture reviews.
    • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
    • Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
    • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
    • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
    • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
  • Preferred qualifications:
    • Experience in a regulated environment such as financial services, healthcare, government, or payments.
    • Experience implementing DevSecOps programs and security automation at scale.
    • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
    • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
    • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.

Professional Skills :

Skill NameRequired/DesiredTotal Years
Software engineering, application security, security engineering, or related technical rolesRequired10
Experience in designing and implementing security architecture for IT systemsRequired6
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuseRequired6
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)Required6
Demonstrated experience with threat modeling and security architecture reviewsRequired6
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloadsRequired6
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practicesRequired6
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plansRequired10
Experience in a regulated environment such as financial services, healthcare, government, or paymentsHighly desired6
Experience conducting or coordinating penetration testing and translating results into durable architectural improvementsHighly desired6
Experience implementing DevSecOps programs and security automation at scaleHighly desired4
Familiarity with privacy engineering, data classification, and compliance frameworksHighly desired4
Experience with security architectures in Esri's ArcGIS platformHighly desired2
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10179676
  • Position Id: 9083905
  • Posted 4 hours ago
Contact the job poster
Siva Prasad

Siva Prasad

Recruiter @ Solomons International
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Richmond, Virginia

Today

Easy Apply

Contract, Third Party

Depends on Experience

Hybrid in Richmond, Virginia

Today

Easy Apply

Contract, Third Party

Depends on Experience

Richmond, Virginia

Today

Easy Apply

Third Party, Contract

80 - 85

Hybrid in Richmond, Virginia

Today

Easy Apply

Contract

Depends on Experience

Search all similar jobs