VDOT Application Security Architect

TOMORROW HIRERichmond, VA
$81 - $101Hybrid

About The Position

VDOT is seeking an experienced Application Security Architect to define, implement, and oversee application security architecture across enterprise IT environments. The role will establish security principles, standards, patterns, reference implementations, and technical guardrails across complex applications and technology platforms. The position will support secure software development, cloud-native applications, GIS solutions, low-code/no-code platforms, Agentic AI, APIs, data platforms, and enterprise applications. The Application Security Architect will work closely with architecture, development, cybersecurity, and technology teams to identify and reduce security risks. The role will also support data protection, data governance, privacy, threat modeling, secure design, and compliance with Commonwealth of Virginia and VITA security requirements.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, a related field, or equivalent practical experience.
  • 10+ years of experience in software engineering, application security, security engineering, or related technical roles, including experience designing and implementing security architecture.
  • 6+ years of experience designing and implementing security architecture for IT systems, including end-to-end security architectures for data at rest, data in transit, and data in use.
  • 6+ years of experience applying secure software development principles and addressing application security risks, including OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • 6+ years of experience with Microsoft technology environments, including Azure, Microsoft 365/O365, Power Platform, and Dynamics 365, as well as automated data classification, Microsoft Purview, encryption, DLP, and DPIAs.
  • 6+ years of experience with threat modeling and security architecture reviews.
  • 6+ years of experience with APIs, web applications, distributed systems, cloud environments, CI/CD, and container workloads.
  • 6+ years of experience with identity and authentication technologies, including OAuth2, OIDC, SAML, JWT, authorization, PKI/TLS, encryption, and secrets management.
  • 10+ years of experience producing architecture diagrams, standards, risk assessments, remediation plans, and other technical documentation.
  • Experience implementing granular access controls, including RBAC, Row-Level Security, Column-Level Encryption, dynamic masking, and centralized database audit/activity monitoring aligned with VITA SEC 530.
  • Experience with secure coding practices in Java, .NET, JavaScript, TypeScript, and Python.
  • Ability to explain technical security risks, business impacts, and architectural tradeoffs to technical and non-technical stakeholders.
  • Strong written and verbal communication skills.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
  • Candidates must be local to the Richmond, Virginia area.
  • Candidates must physically reside within the United States for the duration of the assignment.
  • Candidates must provide a valid email address.
  • Candidates must provide their permanent city and state of residence.
  • Candidates must confirm their ability to meet the required onsite schedule.
  • Candidates should indicate how soon they can start after receiving an offer.

Nice To Haves

  • 6+ years of experience working in regulated environments such as financial services, healthcare, government, or payments.
  • 6+ years of experience with penetration testing and translating findings into architectural improvements.
  • 4+ years of experience developing or supporting DevSecOps programs and security automation at scale.
  • 4+ years of experience with privacy engineering, data classification, and compliance frameworks.
  • 2+ years of experience designing or implementing Esri ArcGIS security architectures.
  • Experience with certifications such as CISSP, CSSLP, CCSP, GIAC, cloud security, or relevant vendor certifications.

Responsibilities

  • Define and maintain application security architecture principles, standards, patterns, and reference implementations.
  • Conduct architecture and design reviews for applications, platforms, integrations, APIs, and cloud solutions.
  • Perform threat modeling and identify application, infrastructure, data, and identity-related security risks.
  • Define security requirements for authentication, authorization, encryption, secrets, logging, privacy, APIs, and data protection.
  • Support secure coding practices and security reviews across Java, .NET, JavaScript, TypeScript, and Python applications.
  • Integrate security controls into CI/CD pipelines and DevSecOps processes.
  • Evaluate and implement application security testing and monitoring tools.
  • Support vulnerability identification, prioritization, remediation, and risk acceptance.
  • Establish secure identity and access-management patterns using modern authentication and authorization technologies.
  • Design security controls for Azure, cloud-native workloads, containers, Kubernetes, serverless applications, and enterprise platforms.
  • Support data protection and privacy requirements across structured, unstructured, and spatial data.
  • Develop and maintain architecture diagrams, security standards, risk assessments, exception documentation, and remediation plans.
  • Support incident response and root-cause analysis for application security issues.
  • Evaluate third-party, open-source, and SaaS security risks.
  • Provide guidance to development and architecture teams on secure application design and implementation.
  • Ensure application security practices align with applicable VDOT, Commonwealth of Virginia, VITA, and organizational security requirements.

Benefits

  • Pay Rate: $81–$101/hour.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service