Develop, design, and implement cloud security strategies, policies, and best practices.
Identify security risks, areas of weakness, and specify/plan for the security tools needed to respond to security threats and breaches.
Establish strategic security architecture direction for cloud service adoption aligned with overall business strategy.
Evaluate existing enterprise architecture with cloud integration progress and create solutions, processes, and best practices for IAM, encryption keying (PKI, SSH), auditing and logging, continuous monitoring, and network connectivity.
Perform Analysis of Alternatives (AoA) researching product and strategy options and presenting recommendations and analysis to government leadership.
Develop solutions to a variety of moderate to complex security problems.
Promote awareness of present and emerging security threats and risks and communicate with client leadership; identify and assess attack vectors and create mitigation solutions.
Identify and develop new cloud architecture standards for secure cloud adoption and work with stakeholders to gain approval.
Develop architecture roadmaps for delivering new capabilities across managed dependencies.
Provide guidance on initiatives such as Zero Trust, control automation, authentication enhancements, and log management.
Review and create documentation, processes, and technical procedures to identify and recommend improvements.
Responsible for accrediting and maintaining security authorization (ATO) of cloud-based systems, including implementing and monitoring security controls, conducting risk assessments, performing continuous monitoring, documenting compliance, and supporting audits.
Work alongside cross-functional teams to design diverse security controls and facilitate their translation into engineering implementation.
Maintain awareness of new technologies and trends and bring solutions to the client.
Able to work independently with minimal guidance.
Other related duties assigned by the program manager and government leadership.
Requirements
8+ years of experience with designing, testing, and deploying complex Cybersecurity solutions in an enterprise environment.
8+ years of experience in networking and endpoint security architecture.
Security Architect experience with a focus in IT cloud solutions.
Possess advanced technical proficiency.
FedRAMP and Cloud experience (e.g., Azure, AWS, Oracle (OCI)).
Ability to evaluate agency environments for security improvements.
Knowledgeable on various security-related NIST publications (e.g., SP 800-53r5, SP 800-18r1, etc.).
Knowledge of zero-trust security architecture.
Ability to obtain and maintain a customer Top Secret (TS) clearance required; qualified candidates can be sponsored and must obtain interim TS within six months of hire.
Certifications: CISSP required.
Preferred: Knowledge of Splunk and other similar SIEM tools.
Preferred: FISMA/FedRAMP responsibilities of cloud systems.
Preferred: Implement security controls (NIST 800-53) for cloud-based systems (SaaS, PaaS, IaaS), perform self-assessments, create and gather supporting artifacts, and prepare Authority to Operate (ATO) packages.