Senior/Principal Cyber Assurance Architect - Cyber Special Programs, Onsite
Role details
Job location
Tech stack
Job description
You will serve as an Information System Security Engineer (ISSE) for multiple systems, configuring and maintaining cybersecurity tools while working hand-in-hand with Information Security Site Managers (ISSMs), System Security Officers (ISSOs), and system administrators. Together, you'll interpret and implement NIST/JSIG standards, conduct validation testing, and ensure compliance across the board.
On any given day, you might:
- Collaborate with key external partners such as the Department of Energy and Intelligence Community agencies to securely enable new programs and maintain existing ones.
- Partner with information assurance teams to define and refine system security requirements.
- Analyze sponsor cyber policies and align them with solution designs.
- Identify potential cyber risks and architect resilient, effective alternatives.
- Integrate robust cybersecurity controls into new and existing tools and infrastructures.
- Explore and evaluate emerging technologies to enhance cyber risk management.
- Advise senior leadership with clear, actionable recommendations that influence strategic decisions.
- Due to the nature of the work, this candidate must be able to work onsite with some travel required.
Salary Range
$117,500 - $235,700, This posting will be open for application submissions for a minimum of three (3) calendar days, including the 'posting date'. Sandia reserves the right to extend the posting date at any time. Security Clearance
Sandia is required by DOE to conduct a pre-employment drug test and background review that includes checks of personal references, credit, law enforcement records, and employment/education verifications. Applicants for employment need to be able to obtain and maintain a DOE Q-level security clearance and SCI access, both of which require US citizenship. SCI access may also require a polygraph examination. If you hold more than one citizenship (i.e., of the U.S. and another country), your ability to obtain these levels of access may be impacted.
Applicants offered employment with Sandia are subject to a federal background investigation to meet the requirements for access to classified information or matter if the duties of the position require a DOE security clearance. Substance abuse or illegal drug use, falsification of information, criminal activity, serious misconduct or other indicators of untrustworthiness can cause a clearance to be denied or terminated by the DOE, resulting in the inability to perform the duties assigned and subsequent termination of employment. EEO
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status and any other protected class under state or federal law. NNSA Requirements for MedPEDs
If you have a Medical Portable Electronic Device (MedPED), such as a pacemaker, defibrillator, drug-releasing pump, hearing aids, or diagnostic equipment and other equipment for measuring, monitoring, and recording body functions such as heartbeat and brain waves, if employed by Sandia National Laboratories you may be required to comply with NNSA security requirements for MedPEDs.
Requirements
- Bachelor's degree in Management Information Systems, Information Assurance, Computer Science or relevant discipline, plus five years' experience; or equivalent (AS + 9.)
- Demonstrated experience supporting cybersecurity programs within the U.S. Government or government contracting environments.
- Proven experience utilizing continuous monitoring tools such as Splunk, ACAS, Nessus, Security Center, and HBSS.
- Active Certified Information System Security Professional (CISSP) or ability to obtain a CISSP certification within the first 9 months of employment.
- Ability to obtain and maintain a DOE Q and SCI clearances, which may require a polygraph.
Qualifications We Desire
- Understanding of the Risk Management Framework (RMF) and/or NIST 800-53 security controls.
- Ability to apply cyber security standards, directives, guidance, and policies to an architectural framework.
- System administration experience, to include a detailed understanding of common operating systems (e.g. Windows and Linux) and networking architecture.
- Experience as an Information System Security Officer (ISSO).
- Familiarity of the Risk Management Framework (RMF) and/or the Joint Special Access Program Implementation Guide (JSIG).
- Excellent written, verbal, and interpersonal communication skills.
- Demonstrated commitment to ongoing growth and professional development.
- Active SCI clearance.
Benefits & conditions
*Salary range is estimated, and actual salary will be determined after consideration of the selected candidate's experience and qualifications, and application of any approved geographic salary differential.