> Markdown version of [/jobs/ext/1212793-security-architect-nih-hhs-experience](https://www.wearedevelopers.com/jobs/ext/1212793-security-architect-nih-hhs-experience). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect (NIH/HHS Experience) - **Company:** Greenbrier Government Solutions Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $188,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, User Authentication, Microsoft Azure, Border Gateway Protocol, Ubuntu (Operating System), Cisco PIX, Cisco Routers, Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Linux, Disaster Recovery, Federal Information Processing Standards (FIPS), Identity and Access Management, Internet Protocol Security (IP SEC), Intrusion Detection Systems, Information Systems Security Architecture Professional, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Network Architecture, Routing, Network Protocols, Open Shortest Path First (OSPF), Public Key Infrastructure, Systems Development Life Cycle, Ansible, Zero Trust Network Access, Security Information and Event Management, Systems Integration, TCP/IP, Virtualization Technology, VMware VSphere, Scripting, Computer Networking Systems, Google Cloud, Cloud Platform System, SolarWinds (Software), ArcSight Event Correlation, ISO/IEC 27002, Terraform, Splunk, Devsecops, Vulnerability Analysis - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b96509aac782e9b0 ## About the Role Education / Experience: Bachelor's Degree + 10+ years security engineering/architecture (on-prem + cloud) Required Certifications: CISSP, Preferred: CISSP-ISSAP; CCSP/cloud security; Zero Trust per OMB M-22-09 / CISA ZTMM; enterprise SIEM/EDR/DLP/PAM operations with availability SLAs, * 10+ years security engineering/architecture (on-premesis + cloud) * Proven experience designing security architectures within NIH or HHS federal agencies or similar health-focused government organizations. * Extensive knowledge of computer networking concepts including routing protocols (OSPF, BGP), network protocols (TCP/IP, IPsec), and network infrastructure components such as Cisco routers/switches. * Strong understanding of information security standards including ISO 27001/27000 series, ISO 27002 best practices, FIPS compliance, and NIST cybersecurity frameworks. * Hands-on experience with firewall management (Cisco ASA), IDS/IPS deployment, SIEM implementation (Splunk or equivalent), and intrusion detection systems (IDS). * Proficiency in cloud computing platforms such as AWS or Azure alongside virtualization tools like VMware vSphere. * Familiarity with DevSecOps practices for integrating security into SDLC processes using tools like Ansible, Terraform, Jenkins CI/CD pipelines. * Knowledge of encryption methods, openSUSE/Linux/Ubuntu system administration skills, and scripting languages such as Python or Bash for automation tasks. * Ability to perform thorough vulnerability assessments, risk analysis investigations, and develop mitigation strategies aligned with federal cybersecurity policies. * Excellent communication skills to articulate complex security concepts clearly across technical teams and executive stakeholders. ## Description We are seeking a highly skilled and motivated Security Architect with specialized experience in NIH (National Institutes of Health) and HHS (Health and Human Services) Federal IT environments. In this pivotal role, you will design, implement, and oversee comprehensive cybersecurity cloud frameworks that safeguard sensitive health data and comply with federal standards. Your expertise will drive the development of resilient cloud security architectures, ensuring the integrity, confidentiality, and availability of critical information systems., * Design authority (NIST SP 800-53 Rev. 5); 95% monthly availability of contractor-managed tooling; Zero Trust baseline reference architecture due Day 90; Government provides all tool licensing and infrastructure - an operate-and-modernize role, not buy-and-build. * Develop and implement robust IT security architectures aligned with NIH/HHS guidelines, including NIST standards and FISMA compliance. * Conduct comprehensive security risk assessments, vulnerability research, and incident investigations to identify potential threats within complex health IT environments. * Lead the integration of security controls across diverse network infrastructures including LAN, WAN, cloud platforms like AWS and Google Cloud, and virtualization environments such as VMware vSphere. * Manage access control management systems utilizing IAM architecture design principles, SSO protocols, LDAP directories, and PKI implementations for secure authentication. * Implement SIEM solutions like Splunk or SolarWinds for real-time security monitoring, event correlation, and incident response coordination. * Collaborate with cross-functional teams to develop system security plans (SSPs), disaster recovery strategies, and incident recovery procedures ensuring compliance with FISMA, FedRAMP, and other federal mandates. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)