What are the responsibilities and job description for the Application Security Architect position at Xcelo Group Inc?
Job Title: Senior Application Security Architect Azure & DevSecOps
Location: Richmond, VA Onsite
Interview: Webcam and In-Person
Work Auth: Any Visa acceptable (No H1 and No Fake Profiles)
Important: Only qualified candidates located in the Richmond, VA area will be considered due to the onsite requirement.
Job Summary
We are seeking a Senior Application Security Architect with extensive experience in Application Security, Azure Security, DevSecOps, Secure Software Development Lifecycle (SSDLC), Cloud Security, and Security Architecture.
This role will define and implement secure application architecture across a hybrid enterprise ecosystem covering web applications, APIs, microservices, Agentic AI solutions, cloud-native applications, Microsoft Azure, O365, Power Platform, Dynamics 365, Kubernetes, CI/CD, and enterprise GIS platforms.
The architect will work closely with application development, cloud/platform, architecture, and cybersecurity teams to establish security standards, perform threat modeling and architecture reviews, strengthen data protection and privacy controls, and integrate security throughout the SDLC.
Required Education
-
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
Required Experience & Skills
-
10 years of experience in software engineering, application security, security engineering, or related technical roles.
-
6 years designing and implementing security architecture for enterprise IT systems.
-
6 years working with secure software-development principles and application vulnerabilities, including OWASP Top 10, injection, insecure authorization, deserialization, and API abuse.
-
6 years designing end-to-end data security for data at rest, in transit, and in use across the Microsoft stack, including Azure, O365, Power Platform, and Dynamics 365.
-
Strong hands-on experience with threat modeling, security architecture reviews, trust boundaries, attack paths, data flows, security gaps, and compensating controls.
-
Experience securing APIs, web applications, distributed systems, microservices, cloud platforms, CI/CD pipelines, Kubernetes, and containerized workloads.
-
Strong knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, RBAC/ABAC, MFA/SSO, PKI/TLS, encryption, authorization design, and secrets management.
-
Experience implementing security throughout SSDLC/DevSecOps, including code reviews, Infrastructure as Code, automated security testing, release controls, and production monitoring.
-
Experience with security tooling such as SAST, DAST, SCA, container/image scanning, API security testing, secret scanning, and runtime protection.
-
Strong experience with vulnerability management, remediation SLAs, security exceptions, risk assessment, and verification of fixes.
-
Strong written communication skills with experience producing architecture diagrams, security standards, risk assessments, remediation plans, risk registers, and architecture documentation.
Key Responsibilities
-
Define enterprise application-security architecture principles, standards, patterns, guardrails, and reference implementations.
-
Conduct application architecture and design reviews to identify security risks and recommend appropriate controls.
-
Lead threat-modeling exercises for new applications, integrations, major
Salary : $85