| 810287 |
Application Security Architect |
Yakshna Solutions, Inc., (YSI) is a CMMI Level 3 assessed, ISO 9001, 20000:1, 27001 certified, woman-owned small business enterprises, headquartered in Herndon, Virginia, USA. YSI provides professional IT solutions and services to business corporations and government organizations. YSI is committed to serve its business communities as a leading IT vendor providing innovative, quality, and cost-effective IT business solutions and services.
We offer a competitive benefits package that includes the following: 401(k), health, dental, and vision insurance, Life insurance, short-term and long-term disability insurance, paid time off, training, and professional development assistance.
YSI is seeking an Application Security Architect to define, embed, and oversee application security strategies across enterprise IT initiatives.
This role will be responsible for the solution of Secure Software Development Lifecycle (SSDLC) across a hybrid ecosystem, spanning complex web applications, Agentic AI solutions, cloud-native solutions, enterprise GIS platforms, low-code no-code and create patterns. Other responsibilities include:
- Lead the data protection strategy, data governance frameworks, and privacy posture across our state-wide transportation ecosystem.
- Define how structured, unstructured, and spatial data (GIS) are classified, encrypted, stored, and accessed across cloud data platforms. support architecture, development, and cybersecurity teams to perform threat modeling, secure architectural designs and ensure compliance with Commonwealth of Virginia (COV) and VITA security standards.
- Define application-security architecture principles, standards, patterns, reference implementations, and guardrails for web, mobile, API, microservice, and cloud-native systems.
- Perform architecture and design reviews, identify trust boundaries, attack paths, data flows, security gaps, and compensating controls.
- Lead or facilitate threat modeling for new applications, major features, integrations, and high-risk changes.
- Establish repeatable security requirements for authentication, authorization, session management, encryption, secrets management, logging, privacy, API protection, and data protection.
- Partner with software engineers to integrate security throughout the SDLC, including code review, CI/CD pipelines, infrastructure as code, testing, release approval, and production monitoring.
- Evaluate and guide use of security tools such as SAST, DAST, software composition analysis, container/image scanning, API security testing, secret scanning, and runtime protection.
- Define a vulnerability-management approach for applications and dependencies, including severity criteria, remediation SLAs, exception processes, and verification of fixes.
- Assess third-party libraries, open-source dependencies, SaaS integrations, and vendor-provided components for security risk.
- Design identity and access-control patterns, including least privilege, MFA/SSO integration, service-to-service authentication, RBAC/ABAC, and privileged-access controls.
- Work with cloud and platform teams to secure application hosting environments, including Kubernetes, serverless, containers, CI/CD, cloud IAM, network segmentation, and secrets storage.
- Advise incident-response teams on application-layer threats and contribute to root-cause analysis and security improvements after incidents.
- Maintain architecture documentation, security decision patterns, risk registers, and exception documentation.
Required Skills & Experience
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field, or equivalent experience.
- 10+ years of experience in software, application security, or security engineering, including 2+ years in security architecture.
- Strong knowledge of secure software development, OWASP Top 10, API security, authorization, injection, and related application risks.
- Experience designing security architectures across Azure, SQL Server, Dynamics 365, Power Platform, and ArcGIS, including encryption, DLP, data classification, and privacy assessments.
- Expertise in RBAC, Row-Level Security, encryption, data masking, database auditing, and security monitoring, with knowledge of VITA SEC 530 standards.
- Experience with threat modeling, architecture reviews, cloud security, APIs, web applications, distributed systems, CI/CD, and containers.
- Working knowledge of Java, .NET, JavaScript/TypeScript, or Python.
- Strong understanding of OAuth 2.0, OpenID Connect, SAML, JWT, PKI/TLS, encryption, secrets management, and authorization.
- Strong communication skills with the ability to explain security risks and create architecture diagrams, risk assessments, and remediation plans.
Preferred Qualifications
- Experience in regulated industries such as government, healthcare, financial services, or payments.
- Experience with DevSecOps, security automation, privacy engineering, data classification, and compliance frameworks.
- Security certifications such as CISSP, CSSLP, CCSP, GIAC, or relevant cloud/vendor certifications.
- Experience coordinating penetration testing and applying findings to improve security architecture.
Job Title: Application Security Architect (810287)
Location: 1221 E. Broad St. Richmond, VA (Hybrid)
Status: Full-time, Contract
Salary: $130,000-140,000 annually with benefits
US Citizen or Green card holder only
YSI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
|