Title: Security Architect
Location: Richmond, VA (Hybrid)
Duration: 09 Month Contract
Client: State of Virginia
Job Description:
*Local candidates only please
*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.
VDOT is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
Bachelor s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Core responsibilities
Required qualifications
Preferred qualifications
Skills:
Skill
Required / Desired
Amount
of Experience
Software engineering, application security, security engineering, or related technical roles
Required
10
Years
Experience in designing and implementing security architecture for IT systems
Required
6
Years
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse
Required
6
Years
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365)
Required
6
Years
Demonstrated experience with threat modeling and security architecture reviews
Required
6
Years
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads
Required
6
Years
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices
Required
6
Years
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans
Required
10
Years
Experience in a regulated environment such as financial services, healthcare, government, or payments
Highly desired
6
Years
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements
Highly desired
6
Years
Experience implementing DevSecOps programs and security automation at scale
Highly desired
4
Years
Familiarity with privacy engineering, data classification, and compliance frameworks
Highly desired
4
Years
Experience with security architectures in Esri's ArcGIS platform
Highly desired
2
Years