VDOT Application Security Architect
Core
Define, implement, and oversee application security architecture across enterprise IT environments, establishing security principles, standards, and technical guardrails for complex applications, cloud-native workloads, GIS solutions, and Agentic AI.
Role type
Senior Application Security Architect
Builds
Secure software development lifecycle (SSDLC) patterns, secure architecture for cloud-native/GIS/AI applications, and integrated security controls for data and identity.
Domain
Public Sector (Virginia Department of Transportation) / Cybersecurity / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security architecture, Secure Software Development Lifecycle (SSDLC), Threat modeling, Identity and Access Management (IAM), Data protection and governance, CI/CD integration, Vulnerability management, API security, Cloud security (Azure/Kubernetes), Secure coding practices
Preferred skills
Experience with Agentic AI security, Low-code/no-code platform security, GIS application security, Microsoft Purview/DLP expertise
Technologies
Azure, SQL Server, Microsoft Dynamics 365, Microsoft Power Platform, ArcGIS, Kubernetes, Serverless, Java, .NET, JavaScript, TypeScript, Python, SAST, DAST, SCA
Responsibilities
Define and maintain application security architecture principles and standards; Conduct architecture reviews and threat modeling; Integrate security controls into CI/CD pipelines; Design secure identity and access-management patterns; Support data protection, privacy, and compliance requirements; Evaluate third-party and open-source security risks; Provide guidance on secure application design.
Seniority
Senior, hands-on IC