Application Security Architect (Hybrid)

Smart IMSRichmond, VA
Hybrid

About The Position

As an Application Security Architect, you will lead the design and implementation of enterprise application security strategies, secure software development practices, and data protection frameworks across cloud, web, GIS, AI, and modern application platforms. This role focuses on embedding security throughout the SDLC, ensuring compliance with security standards, and protecting critical enterprise data through secure architecture, threat modeling, and governance initiatives.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles.
  • 2+ years of experience designing and implementing enterprise security architectures.
  • Strong expertise in Secure Software Development Lifecycle (SSDLC), DevSecOps, and secure coding practices.
  • Deep understanding of OWASP Top 10, API security, threat modeling, vulnerability management, and application security assessments.
  • Experience securing cloud platforms, distributed systems, web applications, microservices, containers, Kubernetes, and CI/CD environments.
  • Strong knowledge of data protection, encryption, privacy controls, data classification, governance, and compliance frameworks.
  • Hands-on experience with Azure, SQL Server, Dynamics 365, Power Platform, ArcGIS, IAM, OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, and secrets management.
  • Proven experience with security tools including SAST, DAST, Software Composition Analysis, container security, and runtime protection solutions.

Nice To Haves

  • Professional certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security certifications, or equivalent credentials are highly preferred.

Responsibilities

  • Define application security architecture standards, patterns, reference models, and security guardrails.
  • Conduct architecture reviews, identify security risks, and recommend effective mitigation strategies.
  • Lead threat modeling activities for applications, integrations, cloud solutions, and high-risk system changes.
  • Establish security requirements for authentication, authorization, encryption, secrets management, and data protection.
  • Integrate security practices throughout the SSDLC, including CI/CD pipelines, code reviews, and testing processes.
  • Evaluate and guide the implementation of security tools such as SAST, DAST, SCA, container scanning, and API security testing.
  • Design identity and access management solutions utilizing MFA, SSO, OAuth, OpenID Connect, RBAC, and ABAC.
  • Secure cloud-native, containerized, and enterprise application environments across modern platforms.
  • Develop vulnerability management processes, remediation standards, and security governance frameworks.
  • Collaborate with engineering, architecture, operations, and security teams to strengthen enterprise security posture.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service