We are looking for an experienced Application Security Architect & Engineer to join our team on a contract basis in Richmond, Virginia. In this role, you will collaborate closely with application teams to embed security into all stages of the software development lifecycle, ensuring compliance and the implementation of secure coding practices. This position offers an opportunity to make a significant impact by improving the security posture of critical applications while working in a dynamic environment.<br><br>Responsibilities:<br>• Provide comprehensive security guidance and training to development and operations teams to enhance secure software practices.<br>• Evaluate application architecture and design to identify security risks and align them with DevSecOps principles.<br>• Promote and enforce secure coding standards across diverse programming languages such as JavaScript, Java, and C#.<br>• Conduct detailed reviews of source code to identify vulnerabilities and recommend effective remediation strategies.<br>• Assess and secure modern web application frameworks, including cloud technologies, APIs, microservices, and client-server models.<br>• Utilize application security testing tools and platforms, such as Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable, to identify and address security weaknesses.<br>• Ensure compliance with relevant security regulations and standards, including NIST 800-53 and IRS Pub 1075.<br>• Develop and maintain System Security Plans (SSPs) to document security policies and procedures effectively.<br>• Collaborate with cross-functional teams, including QA engineers and operations staff, to integrate security measures into workflows.<br>• Stay updated on emerging threats, technologies, and industry trends to continuously improve security practices.