VDOT Application Security Architect

TALENT Software Services - Richmond, VA

Hiring: VDOT Application Security Architect Company: TALENT Software Services Location: Richmond, VA Job Posted Time: 2026-09-16 16:35:54 Employment Type: Hybrid Target Skills & Keywords : .NET, ABAC, Azure, CI/CD, DAST, Encryption, IAM, Infrastructure as Code, Java, JavaScript, Kubernetes, Microservices, OAuth2, OWASP, OpenID Connect, PKI, Penetration Testing, Python, RBAC, REST, SAML, SAST, SQL Server, SaaS, Serverless, TLS, TypeScript About the job Experience: •10 years in software engineering, application security, security engineering, or related technical roles, including 2 years designing security architecture for systems. Required Skills: •Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems. •Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls. •Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes. •Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection. •Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring. •Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection. •Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes. •Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk. Qualifications: •Bachelor's degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience. •In-depth knowledge of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization, and API abuse. •Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards. •Demonstrated experience with threat modeling and security architecture reviews. •Solid functional working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms. •Demonstrated capacity to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders. •Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans. •Operational familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization. •Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!