Application Security Architect :: Richmond, VA (Hybrid)

ARK Solutions, Inc.

  • Richmond, VA
  • 2 days ago

    Highlights

    This role is pivotal in ensuring the Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, including complex web applications, AI solutions, and cloud-native platforms. 10 years in software engineering, application security, or related technical roles, including 2 years designing security architecture.

    Numbers & Facts

    LocationRichmond, VA

    Description

    Application Security Architect - Richmond, VA

    Duration: 9 Months | Hybrid

    Seeking for an Application Security Architect to define and oversee application security strategies across enterprise IT initiatives. This role is pivotal in ensuring the Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, including complex web applications, AI solutions, and cloud-native platforms. You will lead data protection strategies and privacy posture across our transportation ecosystem.

    Responsibilities:

    • Define application-security architecture principles and standards for web, mobile, API, microservice, and cloud-native systems.
    • Conduct architecture and design reviews, identifying trust boundaries, attack paths, and security gaps.
    • Lead threat modeling for new applications and high-risk changes.
    • Establish security requirements for authentication, authorization, encryption, and data protection.
    • Partner with software engineers to integrate security throughout the SDLC.
    • Evaluate and guide the use of security tools like SAST, DAST, and API security testing.
    • Define vulnerability-management approaches for applications and dependencies.
    • Design identity and access-control patterns, including MFA/SSO integration.
    • Secure application hosting environments, including Kubernetes and cloud IAM.
    • Advise incident-response teams on application-layer threats.
    • Maintain architecture documentation and risk registers.

    Required Qualifications:

    • Bachelor's degree in computer science, cybersecurity, engineering, or related field or equivalent practical experience.
    • 10 years in software engineering, application security, or related technical roles, including 2 years designing security architecture.
    • Strong understanding of secure software-development principles and common application risks.
    • Experience securing APIs, web applications, distributed systems, and cloud platforms.
    • Proficiency in secure coding in ecosystems like Java, .NET, JavaScript/TypeScript, or Python.
    • Experience with identity and access management, including OAuth 2.0 and SAML.
    • Strong written communication skills for creating architecture diagrams and risk assessments.

    Preferred Qualifications:

    • Experience in regulated environments such as financial services or government.
    • Experience with DevSecOps programs and security automation.
    • Familiarity with privacy engineering and compliance frameworks.
    • Certifications such as CISSP, CSSLP, CCSP, or relevant vendor credentials.
    • Experience with security architectures in Esri's ArcGIS platform.

    Similar Jobs

    See more jobs