> Markdown version of [/jobs/ext/1133337-lead-security-architect](https://www.wearedevelopers.com/jobs/ext/1133337-lead-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Architect - **Company:** Maximus, Inc. - **Location:** Randolph Air Force Base, TX, United States - **Experience:** Expert - **Salary:** $145,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Identity and Access Management, Reliability Engineering, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Policy as Code, SC Clearance, Cyber Warfare, Splunk, Devsecops, Big Ip - **Published:** July 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9008641/lead-security-architect ## About the Role Active Secret clearance. - Ability to commute as needed to the work location in San Antonio. - 8+ years cybersecurity engineering/architecture. - Cloud security certification (CCSP, AWS Security Specialty). - Active IAT/IAM Level II baseline certification - Experience with boundary tech (e.g., F5 BIG-IP). Preferred Skills and Qualifications: - Experience with Zero Trust Architecture (ZTA) and DoD ZT strategies. - Expertise in IL5/IL6 accreditation and Authority to Operate (ATO) processes. - Hands-on knowledge of CNAPP, SIEM, SOAR tools (Splunk, Sentinel). - Experience automating security compliance (IaC + policy-as-code). - Understanding of cross-domain solutions (CDS) and data protection. #techjobs #clearance #veteransPage ## Description Maximus is seeking a Lead Security Architect whi will be responsible for designing and implementing secure cloud architectures aligned with DoD and Air Force requirements, including RMF, FedRAMP, and DISA compliance. The Lead Security Architect leads the security architecture and implementation across the MCE, ensuring compliance with DoD cybersecurity standards and enabling automated, scalable security controls. Works hand-in-hand with Lead Cloud Architect and Site Reliability Engineer to deliver secure cloud solutions for the Government. This role is Hybrid at our San Antonio office and requires a Secret security clearance. Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS040, T4, Band 7 Job-Specific Essential Duties and Responsibilities: - Design and implement enterprise cloud security architecture. - Enforce boundary protection, monitoring, and cyber defense. - Lead compliance automation (RMF, NIST 800-53, FedRAMP). - Integrate security into CI/CD (DevSecOps). - Oversee vulnerability management, POA&M development, and remediation efforts. - Architect and implement SIEM solutions and security monitoring capabilities - Support ATO and RMF artifact development and lifecycle management - Collaborate with SOC and engineering teams to respond to incidents while leveraging threat detection capabilities - Implement identity, access controls, and least privilege architectures - Deliver security recommendations and compliance reporting to leadership ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)