Demo

Application Security Architect & Engineer

Intellibee Inc
Richmond, VA Full Time
POSTED ON 6/25/2026
AVAILABLE BEFORE 7/24/2026
Application Security Architect & Engineer, Richmond, VA, US

Application Security Architect & Engineer

About The Role

Virginia Tax is seeking an Application Security Engineer (ASE) with 5 years of experience to join the Office of Technology under Joint Security Operations. In this role, the ASE serves as a dedicated security partner to application teams, providing guidance on secure design, vulnerability management, and secure development practices. The ASE works collaboratively across the SDLC to ensure security is embedded into application design, development, testing, and deployment. This includes supporting compliance requirements, delivering training and education, and assisting teams with vulnerability remediation efforts.

The successful candidate will identify and recommend improvements to improve the security of all Virginia Tax applications, promote secure coding and development practices, and contribute to ongoing initiatives that reduce risk and strengthen the agency’s overall security posture.

Responsibilities Include But Not Limited To

  • Provide security guidance, training, and best practices for development and operations teams.
  • Support secure software development by applying knowledge of SDLC, Agile, and Scrum methodologies.
  • Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
  • Promote and enforce secure coding standards and guidelines.
  • Review source code to identify vulnerabilities and recommend remediation strategies.
  • Assess security risks across multiple programming languages (e.g., JavaScript, C#, Java, Ruby, SQL).
  • Analyze and secure modern web application architectures, including cloud, APIs, microservices, and client–server models.
  • Identify and address common vulnerabilities, including those outlined in the OWASP Top 10.
  • Support vulnerability remediation, patch management, and continuous improvement efforts.
  • Utilize application security testing tools such as SAST, DAST, IAST, and platforms like Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable.
  • Interpret and act on findings from SIEM systems, including Splunk.
  • Apply knowledge of common security controls and frameworks.
  • Ensure compliance with relevant security regulations and standards (e.g., NIST 800‑53, IRS Pub 1075, PCI‑DSS).
  • Implement and evaluate AWS cloud security controls and best practices.
  • Create, maintain, and review System Security Plans (SSPs).
  • Troubleshoot and resolve complex technical and security-related issues.
  • Stay current with evolving threats, technologies, and industry trends.
  • Develop detailed plans and communicate risks, impacts, and recommendations effectively.
  • Collaborate with application teams, QA engineers, and operations teams to integrate security into workflows.
  • Provide constructive, actionable feedback to application teams.
  • Communicate technical concepts clearly to both technical and non‑technical audiences.
  • Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
  • Manage multiple tasks, prioritize effectively, and meet deadlines.
  • Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.

Required Skills/Experience

  • Five or more years’ experience in application security.
  • Two or more years’ network or firewall/AWS Security Groups.
  • Experience with log collection, vulnerability scans and remediation, or privileged access management.
  • Strong understanding of security concepts, network protocols, and threat vectors.
  • Proficiency in SIEM, IDS/IPS, EDR, and other relevant security tools.
  • Excellent analytical and problem-solving skills.
  • Strong communication, collaboration, and documentation skills.
  • Ability to work independently and as part of a team in a fast-paced environment.

Have Experience And a Strong Knowledge Of The Following

  • Splunk, Insigh tVM Rapid7, Tenable, CyberArk, Jenkins, Veracode
  • Linux and Windows Operating Systems, Baseline hardening of operating systems
  • IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall

At Least One Of These Certs Below Is REQUIRED

  • CompTIA Security
  • ISC2 CC (Certified in Cybersecurity)
  • Offensive Security Certified Professional (OSCP)
  • CCSP (Certified Cloud Security Professional)
  • CSSLP (Certified Secure Software Lifecycle Professional)

At least one of these certs below is highly DESIRED (Independently and or with one of the above)

  • AWS Solutions Architect (Associate/Professional)
  • AWS Security Specialty

At least one of the any is DESIRED

  • CompTIA PenTest
  • Certified Ethical Hacker (CEH), GIAC Certified Intrusion Analyst (GCIA

Skill Matrix

  • Application Security Required 5 Years
  • Network or Firewall/AWS security Groups Required 2 Years
  • Infrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning. Required 2 Years
  • Experience with log collection, vulnerability scans and remediation, or privileged access management Required 4 Years
  • Proficiency in SIEM, IDS/IPS, EDR, and other relevant security tools. Required 4 Years
  • Networking & Hybrid Connectivity: Solid understanding of routing, firewalls, AWS Direct Connect, and VPNs in a hybrid cloud environment. Required 4 Years
  • One REQUIRED: CompTIA Security , ISC2 CC (Certified in Cybersecurity), Offensive Security Certified Professional (OSCP), CCSP, or CCLP. UPLOAD COPY!! Required
  • CI/CD & DevOps: Experience with GitLab CI/CD, Jenkins, or AWS CodePipeline for automated, secure deployments. Highly desired 5 Years
  • Splunk, InsightVM Rapid7, Tenable, CyberArk, Jenkins, Veracode Highly desired 2 Years
  • Linux and Windows Operating Systems, Baseline hardening of operating systems Highly desired 2 Years
  • IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall Highly desired 2 Years
  • One highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty Highly desired
  • One of these is DESIRED: CompTIA PenTest , Certified Ethical Hacker (CEH), or GIAC Certified Intrusion Analyst (GCIA) Highly desired

Benefits At IntelliBee

  • Long-Term Stability: Join us on a multi-year opportunities with room to grow.
  • Comprehensive Health Coverage: Access quality healthcare benefits to keep you and your family well.
  • Future Planning: Enroll in our 401(k) program and invest in your financial security.
  • GC Assistance: We support immediate Green Card processing, if required.

Salary.com Estimation for Application Security Architect & Engineer in Richmond, VA
$107,417 to $136,283
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Architect & Engineer?

Sign up to receive alerts about other jobs on the Application Security Architect & Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Intellibee Inc

  • Intellibee Inc Richmond, VA
  • Individual is able to work without assistance; is able to manage medium complexity work efforts; has some industry experience; can provide limited leadersh... more
  • Just Posted

  • Intellibee Inc Raleigh, NC
  • Business Analyst- Mid Level, Raleigh, NC, US Business Analyst- Mid Level DCDEE is seeking to procure an enterprise Electronic Document Management System (e... more
  • Just Posted

  • Intellibee Inc Tallahassee, FL
  • Application Development Manager, Tallahassee, FL, US Application Development Manager - Advanced Qualifications And Experience Contractor staff assigned to ... more
  • Just Posted

  • Intellibee Inc Santa, NM
  • Automation tester, Santa Fe, NM, US Automation tester At least 3-6 years of performing Testing activities, including experience with all phases of testing:... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Application Security Architect & Engineer jobs in the Richmond, VA area that may be a better fit.

  • Genworth Richmond, VA
  • At Genworth, we empower families to navigate the aging journey with confidence. We are compassionate, experienced allies for those navigating care with gui... more
  • 9 Days Ago

  • AgileEngine Richmond, VA
  • AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17 industries. We rank amon... more
  • 5 Days Ago

AI Assistant is available now!

Feel free to start your new journey!