Find A Job  ▶
Find Talent  ▶

Apply

Application Security Architect & Engineer

Richmond, Virginia - Posted on March 4, 2026
Published By Bo Mendoza

Our client is seeking an Application Security Engineer (ASE) with 5+ years of experience.

In this role, the ASE serves as a dedicated security partner to application teams, providing guidance on secure design, vulnerability management, and secure development practices. The ASE works collaboratively across the SDLC to ensure security is embedded into application design, development, testing, and deployment. This includes supporting compliance requirements, delivering training and education, and assisting teams with vulnerability remediation efforts.

The successful candidate will identify and recommend improvements to improve the security of all applications, promote secure coding and development practices, and contribute to ongoing initiatives that reduce risk and strengthen the company’s overall security posture.

Responsibilities include but not limited to:
-Provide security guidance, training, and best practices for development and operations teams.
-Support secure software development by applying knowledge of SDLC, Agile, and Scrum methodologies.
-Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
-Promote and enforce secure coding standards and guidelines.
-Review source code to identify vulnerabilities and recommend remediation strategies.
-Assess security risks across multiple programming languages (e.g., JavaScript, C#, Java, Ruby, SQL).
-Analyze and secure modern web application architectures, including cloud, APIs, microservices, and client–server models.
-Identify and address common vulnerabilities, including those outlined in the OWASP Top 10.
-Support vulnerability remediation, patch management, and continuous improvement efforts.
-Utilize application security testing tools such as SAST, DAST, IAST, and platforms like Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable.
-Interpret and act on findings from SIEM systems, including Splunk.
-Apply knowledge of common security controls and frameworks.
-Ensure compliance with relevant security regulations and standards (e.g., NIST 800?53, IRS Pub 1075, PCI?DSS).
-Implement and evaluate AWS cloud security controls and best practices.
-Create, maintain, and review System Security Plans (SSPs).
-Troubleshoot and resolve complex technical and security-related issues.
-Stay current with evolving threats, technologies, and industry trends.
-Develop detailed plans and communicate risks, impacts, and recommendations effectively.
-Collaborate with application teams, QA engineers, and operations teams to integrate security into workflows.
-Provide constructive, actionable feedback to application teams.
-Communicate technical concepts clearly to both technical and non-technical audiences.
-Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
-Manage multiple tasks, prioritize effectively, and meet deadlines.
-Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.

Pay rate is $61/hour. Apply now!

Required Skills/Experience:
-Five or more years’ experience in application security.
-Two or more years’ network or firewall/AWS Security Groups.
-Experience with log collection, vulnerability scans and remediation, or privileged access management.
-Strong understanding of security concepts, network protocols, and threat vectors.
-Proficiency in SIEM,IDS/IPS, EDR,and other relevant security tools.
-Excellent analytical and problem-solving skills.
-Strong communication, collaboration, and documentation skills.
-Ability to work independently and as part of a team in a fast-paced environment.

Have experience and a strong knowledge of the following:
-Splunk, Insigh tVM Rapid7, Tenable, CyberArk, Jenkins, Veracode
Linux and Windows Operating Systems, Baseline hardening of operating systems
-IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall

At least one of these certs below is REQUIRED:
-CompTIA Security+
-ISC2 CC (Certified in Cybersecurity)
-Offensive Security Certified Professional (OSCP)
-CCSP (Certified Cloud Security Professional)
-CSSLP (Certified Secure Software Lifecycle Professional)

 At least one of these certs below is highly DESIRED (Independently and or with one of the above)
-AWS Solutions Architect (Associate/Professional)
-AWS Security Specialty

 At least one of the any is DESIRED
-CompTIA PenTest+
-Certified Ethical Hacker (CEH), GIAC Certified Intrusion Analyst (GCIA)


Trillium has been recruiting and placing professionals for over 30 years. From Fortune 100 companies to small businesses, our philosophy remains the same: to achieve excellence by providing quality employees and an uncompromising level of service. We believe in honesty, integrity, and a simple philosophy of providing value to our customers and our employees. We strive to be unsurpassed in the recruitment and placement of quality and skilled professionals. Trillium is an Equal Opportunity Employer.

Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for the employers and the California Fair Chance Act.

By applying to this job, I agree to receive electronic communications including SMS text and email regarding future opportunities, referral bonus incentives, and other promotions from Trillium. You may opt out at any time from future communications by responding STOP to any electronic communication. You may view our full privacy policy at https://trilliumstaffing.com/jobs/privacy/.

Trillium offers a comprehensive benefit package that includes the ability to participate in health insurance and retirement plans, paid holidays, state required leave, and other leave, if applicable. Trillium’s offerings are dependent on the state in which the assignment is located, length of time worked, and may change depending on assignment. Benefit packages for direct hire placements vary based on the client company.

Want to apply for Application Security Architect & Engineer?

  • To apply for Application Security Architect & Engineer enter your email address below.

  • If you have an account with indeed.com, you can also

       

      Contact Us if you have any questions


      Contact

      Our intentions are to fill job vacancies as quickly as possible with qualified candidates. We are always accepting applications if a time sensitive job has an application deadline it is noted in the job description. Click on "Apply" to begin the apply process.

      Logo
      They have consistently met our needs by providing qualified employees in a very prompt time frame.
      Mark