Enter a job title or keyword

VDOT Application Security Architect


Job Location:

Richmond, VA - USA

Monthly Salary: Not provided by the employer
Posted: 15 September 2026 (23 hours ago)
Application Deadline: 13 December 2026
Vacancies: 1 Vacancy

Job Summary

Position: VDOT Application Security Architect

Location : 1221 E. Broad VA

Interview :  Both Web Cam and In Person Interview

Job : Hybrid

 

*Local candidates only please

*Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation though some onsite presence will continue to be required weekly.

 

VDOT is seeking an Application Security Architect to define embed and oversee application security strategies across enterprise IT initiatives.

This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem spanning complex web applications Agentic AI solutions cloud-native solutions enterprise GIS platforms low-code no-code and create patterns. Lead the data protection strategy data governance frameworks and privacy posture across our state-wide transportation ecosystem. Define how structured unstructured and spatial data (GIS) are classified encrypted stored and accessed across cloud data platforms. support architecture development and cybersecurity teams to perform threat modeling secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.

Bachelors degree in computer science cybersecurity engineering or a related field (or equivalent practical experience) is required.  Certifications such as CISSP CSSLP CCSP GIAC or relevant vendor credentials are highly desired.

Core responsibilities

Define application-security architecture principles standards patterns reference implementations and guardrails for web mobile API microservice and cloud-native systems.

Perform architecture and design reviews identify trust boundaries attack paths data flows security gaps and compensating controls.

Lead or facilitate threat modeling for new applications major features integrations and high-risk changes.

Establish repeatable security requirements for authentication authorization session management encryption secrets management logging privacy API protection and data protection.

Partner with software engineers to integrate security throughout the SDLC including code review CI/CD pipelines infrastructure as code testing release approval and production monitoring.

Evaluate and guide use of security tools such as SAST DAST software composition analysis container/image scanning API security testing secret scanning and runtime protection.

Define a vulnerability-management approach for applications and dependencies including severity criteria remediation SLAs exception processes and verification of fixes.

Assess third-party libraries open-source dependencies SaaS integrations and vendor-provided components for security risk.

Design identity and access-control patterns including least privilege MFA/SSO integration service-to-service authentication RBAC/ABAC and privileged-access controls.

Work with cloud and platform teams to secure application hosting environments including Kubernetes serverless containers CI/CD cloud IAM network segmentation and secrets storage.

Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.

Maintain architecture documentation security decision patterns risk registers and exception documentation.

Required qualifications

Bachelors degree in computer science cybersecurity engineering or a related field or equivalent practical experience.

10 years in software engineering application security security engineering or related technical roles including 2 years designing security architecture for systems.

Strong understanding of secure software-development principles and common application risks including the OWASP Top 10 insecure authorization injection deserialization and API abuse.

Design and implement end-to-end security architectures for data-at-rest in-transit and in-use across Azure SQL Server Dynamics 365 Power Platform and ArcGIS platforms utilizing automated classification (e.g. Microsoft Purview) robust encryption DLP rules and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.

Enforce granular data access controls (including RBAC Row-Level Security Column-Level Encryption and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.

Demonstrated experience with threat modeling and security architecture reviews.

Experience securing APIs web applications distributed systems cloud platforms CI/CD pipelines and containerized workloads.

Working knowledge of secure coding in one or more common ecosystems such as JavaScript/TypeScript Python platforms.

Experience with identity OAuth 2.0 OpenID Connect SAML JWTs authorization design PKI/TLS encryption and secrets-management practices.

Ability to explain technical risks and tradeoffs clearly to engineers product managers executives and nontechnical stakeholders.

Strong written communication skills including the ability to create architecture diagrams standards risk assessments and actionable remediation plans.

Preferred qualifications

Experience in a regulated environment such as financial services healthcare government or payments.

Experience implementing DevSecOps programs and security automation at scale.

Familiarity with privacy engineering data classification and compliance frameworks relevant to the organization.

Certifications such as CISSP CSSLP CCSP GIAC cloud-security certifications or relevant vendor credentials.

Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.

 

 

Regards

 

Manoj Goud

Derex Technologies INC

Contact : Ext 206


Additional Information :

All your information will be kept confidential according to EEO guidelines.


Remote Work :

No


Employment Type :

Full-time


About Company

Derex Technologies Inc specializes in providing IT consulting, staffing solutions and software services. Globally headquartered in Harrison New Jersey since 1996 Derex delivers the highest quality technology professionals and an array of customized IT talent solutions designed to impr ... View more

View Profile View Profile