> Markdown version of [/jobs/ext/1206083-security-architect](https://www.wearedevelopers.com/jobs/ext/1206083-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Wintrio Llc - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Information Systems, Data Security, Github, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Network Segmentation, OpenShift, Role-Based Access Control, Azure Active Directory, Fortify (Software), Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Content Automation Protocol, Software Engineering, SonarQube, Software Vulnerability Management, Data Logging, Webinspect, Cloud Platform System, Okta, Software Security, HybridCloud, Gitlab, Togaf, Kubernetes, Information Technology, Nessus, CIS Benchmarks, SailPoint, Splunk, Devsecops, Docker, Security Orchestration, Automation & Response, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 8, 2026 - **Apply:** https://www.wintrio.com/careers/security-architect-zero-trust-cloud-security/ ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field. * Minimum ten (10) years of experience in cybersecurity, security architecture, cloud security, enterprise architecture, or related disciplines. * Experience designing and implementing security architectures within Federal, regulated, or mission-critical environments. * Strong knowledge of Zero Trust Architecture, NIST SP 800-207, NIST SP 800-53, FedRAMP, FISMA, and Risk Management Framework (RMF) requirements. * Experience supporting AWS, Microsoft Azure, or hybrid cloud security architectures. * Strong understanding of identity and access management, encryption, network segmentation, logging, vulnerability management, and secure software development lifecycle (SDLC) practices. * Strong written and verbal communication skills. * Strong analytical, leadership, and problem-solving abilities. * Ability to communicate complex technical concepts to both technical and executive audiences. Technical Areas Zero Trust Architecture * NIST SP 800-207 * CISA Zero Trust Maturity Model * Identity-Centric Security * Least Privilege Access * Micro-Segmentation * Continuous Verification * Device Trust * Workload Protection Cloud Security Architecture * AWS GovCloud * Microsoft Azure Government * Hybrid Cloud Security * Cloud Security Controls * FedRAMP Compliance * Cloud Authorization Support * Cloud Control Inheritance Identity & Access Management * Active Directory * Microsoft Entra ID (Azure AD) * Okta * SailPoint * PIV/CAC Integration * Role-Based Access Control (RBAC) * Attribute-Based Access Control (ABAC), * Threat Modeling * Security Design Reviews * Encryption & Key Management * Secure Data Exchange * API Security * Microservices Security * Enterprise Security Architecture Tools & Platforms Cloud Security Platforms * AWS Security Hub * Amazon GuardDuty * AWS Key Management Service (KMS) * Microsoft Defender for Cloud * Azure Policy * Azure Key Vault DevSecOps & Security Automation * GitHub Advanced Security * GitLab * Jenkins * Azure DevOps * SAST Platforms * DAST Platforms * Software Composition Analysis (SCA) * Infrastructure-as-Code Scanning Tools Container & Platform Security * Docker * Kubernetes * OpenShift * Helm Security Assessment & Monitoring * Splunk * Tenable * Nessus * ACAS * Fortify * WebInspect * SonarQube Compliance & Governance * NIST RMF * FedRAMP * FISMA * STIGs * SCAP * CIS Benchmarks Preferred Certifications * Certified Information Systems Security Professional (CISSP) * Certified Cloud Security Professional (CCSP) * Certified Information Security Manager (CISM) * AWS Certified Security - Specialty * AWS Certified Solutions Architect - Professional * Microsoft Azure Solutions Architect Expert * Microsoft Azure Security Engineer Associate * Zero Trust Architecture Certifications * SABSA Certification * TOGAF Certification * CompTIA Advanced Security Practitioner (CASP+) Preferred Qualifications * Experience supporting Federal Zero Trust modernization initiatives. * Experience supporting FedRAMP-authorized cloud environments and cloud ATO packages. * Experience implementing identity governance, privileged access management, or enterprise IAM solutions. * Experience supporting DevSecOps transformation initiatives and secure cloud migration programs. * Experience working within Federal civilian, defense, or intelligence community environments. * Experience supporting large-scale cybersecurity modernization and digital transformation efforts. ## Description WINTrio LLC is seeking an experienced Security Architect - Zero Trust / Cloud Security to support Federal cybersecurity modernization, enterprise architecture, cloud adoption, and Zero Trust transformation initiatives. This role is responsible for designing, assessing, and implementing secure architectures across cloud, hybrid, on-premises, application, data, and network environments. The successful candidate will provide technical leadership in the development of secure solutions that align with Federal cybersecurity requirements, Zero Trust Architecture principles, FedRAMP requirements, and agency-specific compliance frameworks. The ideal candidate will possess deep expertise in cloud security, identity-centric security, secure application design, enterprise architecture, and Federal cybersecurity governance. This position requires close collaboration with enterprise architects, cloud engineers, developers, ISSOs, cybersecurity teams, and executive leadership. Job Responsibilities * Design and assess enterprise security architectures across cloud, hybrid, on-premises, application, data, and network environments. * Develop and implement Zero Trust Architecture strategies aligned with identity, device, network, application, workload, and data security principles. * Support cloud security architecture and modernization initiatives within AWS GovCloud, Microsoft Azure Government, and hybrid environments. * Define secure patterns for identity and access management, role-based access control (RBAC), privileged access management (PAM), encryption, logging, monitoring, and network segmentation. * Review application, infrastructure, and cloud architectures to ensure compliance with NIST SP 800-53, FedRAMP, FISMA, RMF, and agency-specific requirements. * Support secure DevSecOps implementations, including pipeline security, secrets management, infrastructure-as-code security scanning, container security, and automated compliance validation. * Develop security architecture documentation, technical reference architectures, control mappings, implementation roadmaps, and design standards. * Support ATO activities, cloud authorization efforts, control inheritance analysis, security assessments, and compliance reviews. * Collaborate with enterprise architects, cloud engineers, cybersecurity teams, developers, ISSOs, and operational stakeholders. * Conduct security architecture reviews, threat modeling exercises, and risk assessments. * Advise executive leadership on cybersecurity modernization, risk reduction strategies, compliance requirements, and emerging technologies. * Support continuous improvement initiatives that strengthen enterprise security posture and architecture maturity. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)