Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud Platform
About the role
- Develop, implement, and maintain a robust cybersecurity architecture strategy to support enterprise security objectives.
- Leverage emerging and existing technologies to strengthen defenses, including cloud security, identity and access management, encryption, and threat detection solutions.
- Evaluate, recommend, and implement tools that enhance the organization’s security posture.
- Serve as the primary security point of contact for assigned federal information systems throughout the DevSecOps life cycle.
- Ensure compliance with NIST 800-53, FedRAMP, and agency-specific cybersecurity frameworks.
- Coordinate with system owners, engineers, developers, and stakeholders to implement security controls and remediation strategies.
- Conduct and support security assessments, continuous monitoring, and vulnerability management activities.
- Participate in risk assessments, threat modeling, and incident response planning.
- Track and report on the status of security findings, POA&Ms, and audit activities.
- Support the development and delivery of security training and awareness for program staff.
- Handle Controlled Unclassified Information (CUI) and adhere to safeguarding and compliance requirements.
- Support proposal efforts as needed, including resume formatting, skills alignment summaries, meetings, and solutioning contributions.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
- 5+ years of experience in cybersecurity roles, including direct Cybersecurity Architecture experience supporting federal systems.
- Strong knowledge of NIST SP 800-53, FISMA, and FedRAMP frameworks.
- Hands-on experience preparing and maintaining ATO packages and supporting RMF processes.
- Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys), SIEMs, and security dashboards.
- Excellent documentation, communication, and coordination skills.
- Must be able to work as a W-2 employee (no C2C).
- Only U.S. citizens eligible due to federal contract requirements.
- Preferred: Professional certifications such as CISSP, CISM, CAP, or Security+.
- Preferred: Experience using eMASS, CSAM, or other compliance management platforms.
- Preferred: Understanding of cloud security controls in AWS, Azure, or GCP environments.
- Preferred: Background in supporting applications or systems within government, finance, or healthcare sectors.
- Preferred: Knowledge of incident response, audit readiness, or insider threat programs.