Senior Application Security Architect // MD // VA

Overview

Hybrid
Depends on Experience
Full Time
Accepts corp to corp applications
No Travel Required
Able to Provide Sponsorship

Skills

Senior Application Security Architect

Job Details

Senior Application Security Architect

Rockville, MD/ McLean, VA.
This is a long term contract to hire

This is a hybrid, 3 days a week

Need & USC

Requirements:

5+ years of experience. Mostly US based.

Certs- cissp or similar REQUIRED.

Must have experience in security architecture in application focused roles.

Cloud security (must be mostly aws)

Threat modeling

Code reviews. We don t need a developer, but must be able to read code.

Some devsecops knowledge Nice to have:

AWS certs, Offensive security certs/ Pen testing certs.

Highly prefer someone with AI/ LLM experience

Would be great to have background in pen testing.,


Overview:
The Senior Application Security Architect is responsible for designing, implementing, and overseeing enterprise-wide application security architecture and standards. This role focuses on establishing security frameworks, conducting architecture reviews, developing security baselines, and leading strategic security initiatives that have broad impact across the organization. The position requires a blend of technical expertise, architectural thinking, and leadership to embed security throughout the software development lifecycle.

Job Responsibilities:

Design and establish enterprise application security architecture frameworks and reference models aligned with business objectives and risk tolerance

Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls

Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models

Create and evolvethreat modeling methodologies(STRIDE, PASTA, OCTAVE) and facilitate threat modeling sessions with development teams

Define secure coding standards and security requirements for different application types based on data classification and risk profile

Architect security solutions for authentication, authorization, encryption, and secure communication channels

Establish security guardrails for cloud-native applications, serverless architectures, and infrastructure-as-code implementations

Design and implement API security strategies including OAuth/OIDC flows, API gateways, and rate limiting

Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives

Evaluate and recommend security tools and technologies for the enterprise security tech stack

Develop security architecture roadmaps and guide implementation of security capabilities

Partner with development teams to design secure solutions that balance security requirements with business needs

Lead strategic security initiatives with enterprise-wide impact

LeverageGenAItechnologies to enhance security architecture reviews and automate security analysis

Maintain documentation of security architecture decisions, patterns, and reference implementations

Develop and deliver security architecture training to raise security awareness among developers and architects

Stay current with emerging security threats, technologies, and architectural approaches

Perform security design reviews for new applications and major changes to existing applications

Architect secure data handling practices including encryption at rest and in transit

Qualifications:

Bachelor's degree in Computer Science, Information Security, or related technical field required

5+ years of experience in application security, with at least 2 years in security architecture roles

Deep knowledge of secure design principles, threat modeling methodologies, and security patterns

Experience designing security controls for cloud environments (AWS, Azure, Google Cloud Platform)

Proficiency in evaluating and implementing application security tools (SAST, DAST, IAST, SCA)

Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, and other proxy tools

Experience with secure software development practices and DevSecOps implementation

Strong understanding of OWASP Top 10, SANS CWE, and other security standards

Knowledge of secure authentication mechanisms (MFA, SSO, OAuth 2.0, SAML, OIDC)

Experience with secure API design and implementation of API security controls

Knowledge of regulatory requirements (PCI-DSS, GDPR, SOX, etc.) and their architectural implications

Experience with containerization, microservices, and API security

Proficiency in one or more programming languages (Java, Python, JavaScript preferred)

Experience with secure code review techniques and identifying common vulnerability patterns

Knowledge of cryptographic protocols and implementations

Experience with security requirements for modern application architectures (SPA, serverless, etc.)

Excellent communication skills with ability to translate complex security concepts to technical and non-technical audiences

Experience leading cross-functional security initiatives and influencing stakeholders

Certifications such as CSSLP, CISSP, AWS Security Specialty are highly desirable

This position requires a strategic thinker who can balance security requirements with business objectives while driving the organization toward a more secure application ecosystem.

***Nice to Have:

Experience with securing Agentic AI or leveraging AI for security***

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.