layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
TOMORROW HIRE
Richmond, VA, US
Source: TOMORROW HIRE careers · View original posting
From TOMORROW HIRE's posting. “We” and “our” refer to the employer.
VDOT is seeking an experienced Application Security Architect to define, implement, and oversee application security architecture across enterprise IT environments.
The role will establish security principles, standards, patterns, reference implementations, and technical guardrails across complex applications and technology platforms.
The position will support secure software development, cloud-native applications, GIS solutions, low-code/no-code platforms, Agentic AI, APIs, data platforms, and enterprise applications.
The Application Security Architect will work closely with architecture, development, cybersecurity, and technology teams to identify and reduce security risks.
The role will also support data protection, data governance, privacy, threat modeling, secure design, and compliance with Commonwealth of Virginia and VITA security requirements.
Interested candidates should submit an updated resume for consideration.
Candidates must be local to the Richmond, Virginia area.
Candidates must physically reside within the United States for the duration of the assignment.
Candidates must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Candidates must provide a valid email address.
Candidates must provide their permanent city and state of residence.
Candidates must confirm their ability to meet the required onsite schedule.
Candidates should indicate how soon they can start after receiving an offer.
Define, implement, and oversee application security architecture across VDOT's enterprise IT environment.
Establish application security principles, standards, patterns, reference implementations, and technical guardrails.
Embed security throughout the Secure Software Development Lifecycle (SSDLC), from requirements and architecture through development, testing, deployment, and production monitoring.
Develop secure architecture patterns for complex web applications, APIs, distributed systems, cloud-native workloads, GIS applications, low-code/no-code platforms, and Agentic AI solutions.
Lead application security architecture activities involving Azure, SQL Server, Microsoft Dynamics 365, Microsoft Power Platform, ArcGIS, and other enterprise technologies.
Define and implement security controls for data at rest, data in transit, and data in use.
Support data classification, encryption, Data Loss Prevention (DLP), privacy, data governance, and Data Protection Impact Assessments (DPIAs).
Design granular access-control models using Role-Based Access Control (RBAC), Row-Level Security, Column-Level Encryption, dynamic data masking, and centralized database audit and activity monitoring.
Align application security architecture and controls with VITA security requirements, including VITA SEC 530.
Conduct threat modeling and security architecture reviews to identify vulnerabilities and security risks early in the development lifecycle.
Define security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, APIs, and data protection.
Integrate application security practices into CI/CD pipelines, Infrastructure as Code (IaC), development workflows, testing processes, and release management.
Evaluate and support security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, API security testing, secret scanning, and runtime security monitoring.
Support vulnerability management activities and help prioritize remediation based on business and technical risk.
Assess security risks associated with third-party applications, open-source software, SaaS solutions, and external technology providers.
Establish secure identity and access-management patterns, including least privilege, Multi-Factor Authentication (MFA), Single Sign-On (SSO), service authentication, RBAC, Attribute-Based Access Control (ABAC), and privileged access management.
Develop security architecture for cloud environments, Kubernetes, serverless applications, containers, cloud IAM, network segmentation, and secrets management.
Support cybersecurity incident response activities and perform root-cause analysis related to application security incidents.
Maintain architecture documentation, security risk registers, exception documentation, remediation plans, standards, and security patterns.
Communicate complex security risks, technical tradeoffs, and recommended solutions to technical and non-technical stakeholders.
Work collaboratively with application development, enterprise architecture, cybersecurity, infrastructure, data, and project teams.
Compensation
Pay Rate: $81–$101/hour.
Full-time contract assignment.
Hybrid work arrangement.
Initial 90-day probationary period requires onsite work 4 days per week.
After successful completion of the initial 90-day probationary period, the onsite requirement may be reduced.
Some weekly onsite presence will continue after the probationary period.
Candidates must be able to meet the required onsite schedule.
Richmond, VA.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: