Cyber Security Architect - SOCEUR

Caci Inc
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$105,100.0 - $231,100.0
Working hours
Regular working hours

Tech stack

Audit Trail Cloud Computing Cloud Computing Security Cyber Security Data Security Identity and Access Management Key Management Network Security Zero Trust Network Access Security Information and Event Management Google Cloud Istio
+5 more
Amazon Virtual Private Cloud (VPC) Kubernetes Information Technology Terraform Security Orchestration, Automation & Response

Job description

As a CACI Cyber Security Architect you will be the technical leader responsible for the vision, design, and continuous improvement of security boundaries across the enterprise’s Google Cloud environment. This role sits inside the Special Operations Command Europe (SOCEUR) Hybrid Threat Action Platform (HTAP) program team and is responsible for championing secure-by-default blueprints, establishing zero-trust identity perimeters, and ensuring compliance with the most stringent federal security baselines. The individual will act as the senior technical advisor for all cloud security matters, translating high-level regulatory mandates into automated, secure-by-design Infrastructure as Code (IaC) for Allied, partner, and US operations.

  • Security Architecture: Design and maintain scalable, secure-by-default architectural blueprints for GCP landing zones, IAM hierarchies, and hybrid networking, in accordance with the DoD Cloud Computing Security Requirements Guide (SRG).
  • Compliance as Code: Lead the translation of complex regulatory requirements (NIST SP 800-53, FedRAMP, CMMC) into technical controls, authoring and enforcing security policies within IaC (Terraform) templates.
  • Identity and Access Architecture: Develop and govern the enterprise IAM strategy, leveraging Workload Identity, Just-In-Time (JIT) access, context-aware controls, and MFA/CAC/PIV integration.
  • Data Protection & Encryption: Define the strategic vision for data protection, designing key management strategies across Cloud KMS/HSM/EKM and architecting data encryption protocols to secure data at-rest and in-transit.
  • Network Security Design: Oversee the architectural design of network security controls, including VPC Service Controls, Cloud Armor policies, and firewalls, to mitigate data exfiltration risks.
  • Technical Leadership: Act as the primary technical advisor and final point of escalation for cloud security risks, threat models, and architectural design decisions. Mentor engineers and developers on secure cloud practices.
  • Security Automation: Architect secure, automated telemetry and audit logging pipelines that route seamlessly into SIEM systems (e.g., Google Security Operations/Chronicle).

Requirements

  • Must be a US Citizen possessing an active TS/SCI security clearance.
  • Bachelor’s degree in Computer Science, Cyber Security, or a related STEM field (or equivalent practical experience).
  • CISSP certification (or equivalent, to meet DoD 8570/8140 IAM/IASAE Level III requirements).
  • 8+ years of technical experience in roles such as Cybersecurity Architect, Infrastructure Engineer, or a similar senior technical position.
  • 5+ years of dedicated experience designing, migrating, and securing workloads on Google Cloud Platform (GCP), including deep expertise in networking, IAM, and security services.
  • Proven expertise in writing and securing Terraform deployments and automating security workflows in CI/CD pipelines.
  • Demonstrated experience architecting solutions to meet strict compliance frameworks (e.g., NIST SP 800-53, FedRAMP, DoD SRG) and supporting the Risk Management Framework (RMF) process to achieve an Authority to Operate (ATO).
  • Google Cloud Professional Cloud Security Engineer certification.
  • Google Cloud Professional Cloud Architect certification.

  • Hands-on experience securing Kubernetes clusters (GKE) and utilizing service mesh technologies.
  • Deep familiarity with GCP-native threat defense tools like Security Command Center (SCC) Premium

Benefits & conditions

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is: $105,100-$231,100

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

About the company

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose - to ensure the safety of our nation.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

Together, we will advance our nation’s most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · WWC Europe 2026

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all