Demo

Application Security Architect

OnwardPath Technology Solutions LLC
Richmond, VA Contractor
POSTED ON 9/21/2026
AVAILABLE BEFORE 10/22/2026
Job Title: Application Security Architect
Job Location: 
Job Duration: 12 Months
 
Job Overview

 

  • The client is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
  • This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. 
  • Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. 
  • Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. 
  • support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required.  Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.

 

Core responsibilities

  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required qualifications
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10 years in software engineering, application security, security engineering, or related technical roles, including 2 years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
  • Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred qualifications
  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Skill matrix: 
SkillsRequiredAmount Of Experience
Software engineering, application security, security engineering, or related technical roles
Required10
Experience in designing and implementing security architecture for IT systems
Required6
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse
Required6
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)
Required6
Demonstrated experience with threat modeling and security architecture reviews
Required6
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads
Required6
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices
Required6
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans
Required10
Experience in a regulated environment such as financial services, healthcare, government, or payments
Highly desired6
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
Highly desired6
Experience implementing DevSecOps programs and security automation at scale
Highly desired4
Familiarity with privacy engineering, data classification, and compliance frameworks
Highly desired4
Experience with security architectures in Esri's ArcGIS platform
Highly desired2
 
 
 
 

 

 

 

Uday Raj

Director, Talent Solutions at Onwardpath


2701 Larsen Rd #BA142, Green Bay, WI 54303

Contact: 1

 | 

 

Certified WBE & MBE

Salary : $70 - $80

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Architect?

Sign up to receive alerts about other jobs on the Application Security Architect career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$73,727 - $94,067
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$90,707 - $120,959
Income Estimation: 
$91,486 - $118,193
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at OnwardPath Technology Solutions LLC

  • OnwardPath Technology Solutions LLC Denver, CO
  • Sr Power BI Developer Location: Local - Denver, CO (Remote in CO) Candidate Must Be Local Duration: 12 Months State client project Exp: Minimum 10 Years NO... more
  • 1 Day Ago

  • OnwardPath Technology Solutions LLC Reston, VA
  • Salesforce Developer (10 Positions) Location: Reston, VA Salary: $115K Experience Required 6–8 years of Salesforce Development experience Required Skills A... more
  • 1 Day Ago

  • OnwardPath Technology Solutions LLC Atlanta, GA
  • AWS Data Engineer (10 Positions) Location: Atlanta, GA (In-Person Interview Required) Salary: $120K Benefits (Dental/Vision/Paid leaves) Experience Require... more
  • 2 Days Ago

  • OnwardPath Technology Solutions LLC Richmond, VA
  • Title: Infrastructure Solutions Architect 3 Location: Richmond, VA 23219 Duration: 12 Months Job Overview : The FAS Solution Architect serves as a technica... more
  • 2 Days Ago


Not the job you're looking for? Here are some other Application Security Architect jobs in the Richmond, VA area that may be a better fit.

  • TOMORROW HIRE Richmond, VA
  • Job Title: VDOT Application Security Architect Work Type: Hybrid Location: Richmond, VA Salary: $81-$101/hour Start Date: September 21, 2026 End Date: June... more
  • 2 Days Ago

  • MetaSense, Inc. Richmond, VA
  • Title: Application Security Architect 📍 Location: Richmond, VA — 1 day/month ⚠️ Local Candidates Only ⏳ Duration: Long-Term (12 Months) 🎥 Interview: Vide... more
  • 2 Days Ago

AI Assistant is available now!

Feel free to start your new journey!