Jobs Companies TOMORROW HIRE VDOT Application Security Architect

Über diese VDOT Application Security Architect Stelle bei TOMORROW HIRE

TOMORROW HIRE · Hybrid · Richmond, Virginia, United States
  • Job Title: VDOT Application Security Architect
  • Work Type: Hybrid
  • Location: Richmond, VA
  • Salary: $81–$101/hour
  • Start Date: September 21, 2026
  • End Date: June 30, 2027
  • Industry Category: Information Technology / Cybersecurity
  • Employment Type: 1099 Contract
  • Requisition ID: 810287

Overview:

  • VDOT is seeking an experienced Application Security Architect to define, implement, and oversee application security architecture across enterprise IT environments.
  • The role will establish security principles, standards, patterns, reference implementations, and technical guardrails across complex applications and technology platforms.
  • The position will support secure software development, cloud-native applications, GIS solutions, low-code/no-code platforms, Agentic AI, APIs, data platforms, and enterprise applications.
  • The Application Security Architect will work closely with architecture, development, cybersecurity, and technology teams to identify and reduce security risks.
  • The role will also support data protection, data governance, privacy, threat modeling, secure design, and compliance with Commonwealth of Virginia and VITA security requirements.

Application:

  • Interested candidates should submit an updated resume for consideration.
  • Candidates must be local to the Richmond, Virginia area.
  • Candidates must physically reside within the United States for the duration of the assignment.
  • Candidates must be legally authorized to work in the United States without employer sponsorship, now or in the future.
  • Candidates must provide a valid email address.
  • Candidates must provide their permanent city and state of residence.
  • Candidates must confirm their ability to meet the required onsite schedule.
  • Candidates should indicate how soon they can start after receiving an offer.

Job Description:

  • Define, implement, and oversee application security architecture across VDOT's enterprise IT environment.
  • Establish application security principles, standards, patterns, reference implementations, and technical guardrails.
  • Embed security throughout the Secure Software Development Lifecycle (SSDLC), from requirements and architecture through development, testing, deployment, and production monitoring.
  • Develop secure architecture patterns for complex web applications, APIs, distributed systems, cloud-native workloads, GIS applications, low-code/no-code platforms, and Agentic AI solutions.
  • Lead application security architecture activities involving Azure, SQL Server, Microsoft Dynamics 365, Microsoft Power Platform, ArcGIS, and other enterprise technologies.
  • Define and implement security controls for data at rest, data in transit, and data in use.
  • Support data classification, encryption, Data Loss Prevention (DLP), privacy, data governance, and Data Protection Impact Assessments (DPIAs).
  • Design granular access-control models using Role-Based Access Control (RBAC), Row-Level Security, Column-Level Encryption, dynamic data masking, and centralized database audit and activity monitoring.
  • Align application security architecture and controls with VITA security requirements, including VITA SEC 530.
  • Conduct threat modeling and security architecture reviews to identify vulnerabilities and security risks early in the development lifecycle.
  • Define security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, APIs, and data protection.
  • Integrate application security practices into CI/CD pipelines, Infrastructure as Code (IaC), development workflows, testing processes, and release management.
  • Evaluate and support security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, API security testing, secret scanning, and runtime security monitoring.
  • Support vulnerability management activities and help prioritize remediation based on business and technical risk.
  • Assess security risks associated with third-party applications, open-source software, SaaS solutions, and external technology providers.
  • Establish secure identity and access-management patterns, including least privilege, Multi-Factor Authentication (MFA), Single Sign-On (SSO), service authentication, RBAC, Attribute-Based Access Control (ABAC), and privileged access management.
  • Develop security architecture for cloud environments, Kubernetes, serverless applications, containers, cloud IAM, network segmentation, and secrets management.
  • Support cybersecurity incident response activities and perform root-cause analysis related to application security incidents.
  • Maintain architecture documentation, security risk registers, exception documentation, remediation plans, standards, and security patterns.
  • Communicate complex security risks, technical tradeoffs, and recommended solutions to technical and non-technical stakeholders.
  • Work collaboratively with application development, enterprise architecture, cybersecurity, infrastructure, data, and project teams.

Responsibilities:

  • Define and maintain application security architecture principles, standards, patterns, and reference implementations.
  • Conduct architecture and design reviews for applications, platforms, integrations, APIs, and cloud solutions.
  • Perform threat modeling and identify application, infrastructure, data, and identity-related security risks.
  • Define security requirements for authentication, authorization, encryption, secrets, logging, privacy, APIs, and data protection.
  • Support secure coding practices and security reviews across Java, .NET, JavaScript, TypeScript, and Python applications.
  • Integrate security controls into CI/CD pipelines and DevSecOps processes.
  • Evaluate and implement application security testing and monitoring tools.
  • Support vulnerability identification, prioritization, remediation, and risk acceptance.
  • Establish secure identity and access-management patterns using modern authentication and authorization technologies.
  • Design security controls for Azure, cloud-native workloads, containers, Kubernetes, serverless applications, and enterprise platforms.
  • Support data protection and privacy requirements across structured, unstructured, and spatial data.
  • Develop and maintain architecture diagrams, security standards, risk assessments, exception documentation, and remediation plans.
  • Support incident response and root-cause analysis for application security issues.
  • Evaluate third-party, open-source, and SaaS security risks.
  • Provide guidance to development and architecture teams on secure application design and implementation.
  • Ensure application security practices align with applicable VDOT, Commonwealth of Virginia, VITA, and organizational security requirements.

Requirements

Minimum Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including experience designing and implementing security architecture.
  • 6+ years of experience designing and implementing security architecture for IT systems, including end-to-end security architectures for data at rest, data in transit, and data in use.
  • 6+ years of experience applying secure software development principles and addressing application security risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • 6+ years of experience with Microsoft technology environments, including Azure, Microsoft 365/O365, Power Platform, and Dynamics 365, as well as automated data classification, Microsoft Purview, encryption, DLP, and DPIAs.
  • 6+ years of experience with threat modeling and security architecture reviews.
  • 6+ years of experience with APIs, web applications, distributed systems, cloud environments, CI/CD, and container workloads.
  • 6+ years of experience with identity and authentication technologies, including OAuth2, OIDC, SAML, JWT, authorization, PKI/TLS, encryption, and secrets management.
  • 10+ years of experience producing architecture diagrams, standards, risk assessments, remediation plans, and other technical documentation.
  • Experience implementing granular access controls, including RBAC, Row-Level Security, Column-Level Encryption, dynamic masking, and centralized database audit/activity monitoring aligned with VITA SEC 530.
  • Experience with secure coding practices in Java, .NET, JavaScript, TypeScript, and Python.
  • Ability to explain technical security risks, business impacts, and architectural tradeoffs to technical and non-technical stakeholders.
  • Strong written and verbal communication skills.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Preferred Qualifications:

  • 6+ years of experience working in regulated environments such as financial services, healthcare, government, or payments.
  • 6+ years of experience with penetration testing and translating findings into architectural improvements.
  • 4+ years of experience developing or supporting DevSecOps programs and security automation at scale.
  • 4+ years of experience with privacy engineering, data classification, and compliance frameworks.
  • 2+ years of experience designing or implementing Esri ArcGIS security architectures.
  • Experience with certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security, or relevant vendor certifications.

Benefits

Compensation:

  • Pay Rate: $81–$101/hour.

Schedule:

  • Full-time contract assignment.
  • Hybrid work arrangement.
  • Initial 90-day probationary period requires onsite work 4 days per week.
  • After successful completion of the initial 90-day probationary period, the onsite requirement may be reduced.
  • Some weekly onsite presence will continue after the probationary period.
  • Candidates must be able to meet the required onsite schedule.

Work Location:

  • Richmond, VA.
Bereit, sich bei TOMORROW HIRE zu bewerben?
Bei TOMORROW HIRE bewerben

Wie sich dieses Gehalt für Architect vergleicht

Diese Stelle zahlt $189,280/yrim Einklang mit der üblichen Spanne für Architect Stellen.

$113,450 dem Median $171,700 $237,500

Übliche Spanne $142,400–$204,000/yr, aus 2,792 vergleichbaren Architect Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Architect ansehen →

Über TOMORROW HIRE

At TOMORROW HIRE, we believe every hire matters. Every hire drives innovation, builds success, and shapes the future of work. That’s why we’re committed to making hiring smarter, faster, and better for every business we serve. We’re not just solving staffing challenges-we’re creating a movement for smarter hiring.

Alle Jobs bei TOMORROW HIRE ansehen →

Ähnliche Jobs

AGE Solutions
Storage Architect
AGE Solutions
⚡ Früh bewerben Battle Creek, Michigan, United... Vor Ort $105,000–$105,000
● Neu 👁 Gesehen ✓ Beworben vor 2 Mon.
CACI
Product Architect/Full Stack Developer
CACI
⚡ Früh bewerben Ashburn, VA, US Vor Ort $113,200–$237,800
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
RSM
Azure Cloud Architect
RSM
⚡ Früh bewerben San Salvador Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
Gartner
Sr Network Architect
Gartner
⚡ Früh bewerben Gurgaon Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
PwC
IN_Senior Associate _IRM Architect_ Strategy &Governance Advisory_ Mumbai
PwC
⚡ Früh bewerben Mumbai Shivaji Park Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
PwC
IN_Manager _IRM Architect_Identity Management_ Advisory_ Mumbai
PwC
⚡ Früh bewerben Airoli Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
Example Corp
Architect
Example Corp
⚡ Früh bewerben United States Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
CR
Microsoft Dynamics 365 ERP Solution Architect
Crowe
⚡ Früh bewerben Chicago IL USA Vor Ort $103,200–$210,900
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
EG
Software and Solution Architect
EQT Group
⚡ Früh bewerben Stockholm, Stockholm, Sweden Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei TOMORROW HIRE

Alle Jobs bei TOMORROW HIRE ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos