Datasoft Technologies logo

VDOT Application Security Architect

Datasoft Technologies
  • Richmond, VA
  • Instant Apply
1 day ago

Job Description

VDOT Application Security Architect (810287)
Start Date: 09/21/2026
End Date: 06/30/2027
Deadline: N/A
Location: 1221 E. Broad St. Richmond, VA
Work Location Requirements
  • Local candidates only please
  • Candidate must be able to work onsite 4 days/week during an initial 90-day probationary period; there is a possibility of reduced onsite commitment after successful probation, though some onsite presence will continue to be required weekly.
Position Overview
VDOT is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem. Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. Support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs, and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
Bachelor s degree in computer science, cybersecurity, engineering, or a related field (or equivalent practical experience) is required. Certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant vendor credentials are highly desired.
Core Responsibilities
  • Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
  • Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
  • Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
  • Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
  • Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
  • Evaluate and guide use of security tools such as SAST, DAST, software composition analysis (SCA), container/image scanning, API security testing, secret scanning, and runtime protection.
  • Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
  • Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
  • Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
  • Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
  • Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
  • Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Qualifications
  • Bachelor s degree in computer science, cybersecurity, engineering, or a related field or equivalent practical experience.
  • 10+ years in software engineering, application security, security engineering, or related technical roles, including 2+ years designing security architecture for systems.
  • Strong understanding of secure software-development principles and common application risks, including the OWASP Top 10, insecure authorization, injection, deserialization, and API abuse.
  • Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS platforms, utilizing automated classification (e.g., Microsoft Purview), robust encryption, DLP rules, and privacy risk assessments (DPIAs) to protect sensitive state transportation and infrastructure assets.
  • Enforce granular data access controls (including RBAC, Row-Level Security, Column-Level Encryption, and dynamic masking) and establish centralized database audit logging and activity monitoring pipelines to ensure strict alignment with VITA SEC 530 security standards.
  • Demonstrated experience with threat modeling and security architecture reviews.
  • Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads.
  • Working knowledge of secure coding in one or more common ecosystems, such as Java, .NET, JavaScript/TypeScript, Python platforms.
  • Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices.
  • Ability to explain technical risks and tradeoffs clearly to engineers, product managers, executives, and nontechnical stakeholders.
  • Strong written communication skills, including the ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans.
Preferred Qualifications
  • Experience in a regulated environment such as financial services, healthcare, government, or payments.
  • Experience implementing DevSecOps programs and security automation at scale.
  • Familiarity with privacy engineering, data classification, and compliance frameworks relevant to the organization.
  • Certifications such as CISSP, CSSLP, CCSP, GIAC, cloud-security certifications, or relevant vendor credentials.
  • Experience conducting or coordinating penetration testing and translating results into durable architectural improvements.
Required / Desired Skills
Skill Required / Desired Amount of Experience
Software engineering, application security, security engineering, or related technical roles Required 10 Years
Experience in designing and implementing security architecture for IT systems Required 6 Years
Secure software-development principles and common risks, including the OWASP Top 10, insecure authorization, injection, deserialization and API abuse Required 6 Years
Design and implement end-to-end security architectures for data-at-rest, in-transit, and in-use for full MS stack (Azure, O365, Power Platform, D365) Required 6 Years
Demonstrated experience with threat modeling and security architecture reviews Required 6 Years
Experience securing APIs, web applications, distributed systems, cloud platforms, CI/CD pipelines, and containerized workloads Required 6 Years
Experience with identity, OAuth 2.0, OpenID Connect, SAML, JWTs, authorization design, PKI/TLS, encryption, and secrets-management practices Required 6 Years
Strong written communication skills, including ability to create architecture diagrams, standards, risk assessments, and actionable remediation plans Required 10 Years
Experience in a regulated environment such as financial services, healthcare, government, or payments Highly desired 6 Years
Experience conducting or coordinating penetration testing and translating results into durable architectural improvements Highly desired 6 Years
Experience implementing DevSecOps programs and security automation at scale Highly desired 4 Years
Familiarity with privacy engineering, data classification, and compliance frameworks Highly desired 4 Years
Experience with security architectures in Esri's ArcGIS platform Highly desired 2 Years

About our Company
DataSoft Technologies is a highly recognized provider of professional IT Consulting services in the US. Founded in 1994, DataSoft Technologies, Inc. provides staff augmentation services for Information Technology and Automotive Services. Our team member benefits include:

Paid Holidays/Paid Time Off (PTO)
Medical/Dental Insurance Group
Accident/Critical Illness Insurance
Life Insurance
401 (K)

Numbers & Facts

LocationRichmond, VA
IndustryComputer/IT Services
Company Size20 to 49 employees
Year Founded1994
Websitehttp://www.datasoft-tech.com

About Company

Incorporated in 1994, DataSoft Technologies, Inc. is a customer-focused consulting and staffing services organization that provides solutions across all disciplines of business, including Engineering, Finance, Information Technology, Professional, Consulting, and software development. Its staff augmentation and business solutions provide a flexible, integrated workforce available for contract to hire—or permanent placement—with companies in the private and public business sectors. The company serves a broad range of businesses in the automotive, financial services, insurance, manufacturing, media and entertainment, software and telecommunications industries.

Skills

  • Access Controlunmatched
  • Analysis Skillsunmatched
  • Application Hostingunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • ArcGISunmatched
  • Architectural Servicesunmatched
  • Artificial Intelligence (AI)unmatched
  • Authenticationunmatched
  • Automationunmatched
  • Automotive Repair and Maintenanceunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Cryptographyunmatched
  • Distributed Computingunmatched
  • Ecosystemsunmatched
  • Enterprise Protectionunmatched
  • Financial Servicesunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • Geographic Information Systems (GIS)unmatched
  • Governmentunmatched
  • Healthcareunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology Consultingunmatched
  • Information/Data Security (InfoSec)unmatched
  • Injectionsunmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Javaunmatched
  • JavaScriptunmatched
  • Maintain Complianceunmatched
  • Microservicesunmatched
  • Microsoft .NETunmatched
  • Microsoft Product Familyunmatched
  • Microsoft SQL Serverunmatched
  • Microsoft Windows Azureunmatched
  • Multiplatform/Cross-Platformunmatched
  • OAuthunmatched
  • Open Sourceunmatched
  • OpenIDunmatched
  • Penetration Testingunmatched
  • Privacy Controlsunmatched
  • Production Controlunmatched
  • Professional Servicesunmatched
  • Public Key Infrastructure (PKI)unmatched
  • Python Programming/Scripting Languageunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Secure Codingunmatched
  • Securities and Exchange Commission (SEC)unmatched
  • Security Architectureunmatched
  • Security Assertion Markup Language (SAML)unmatched
  • Security Monitoringunmatched
  • Security Softwareunmatched
  • Security System Designunmatched
  • Service Level Agreement (SLA)unmatched
  • Single Sign-On (SSO)unmatched
  • Software Developmentunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Software Engineeringunmatched
  • Software as a Service (SaaS)unmatched
  • Spatial Dataunmatched
  • System Architectureunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Unstructured Dataunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder