> Markdown version of [/jobs/ext/1841255-specialist-director-federal-cyber-security-solutions-architect](https://www.wearedevelopers.com/jobs/ext/1841255-specialist-director-federal-cyber-security-solutions-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Specialist Director, Federal Cyber Security Solutions Architect - **Company:** Kpmg LLP - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Systems Security Architecture Professional, Azure Active Directory, Cloud Services, Security Information and Event Management, Software Engineering, Google Cloud, Cloud Platform System, Okta, Cyberark, Cortex XSOAR Platform, Splunk, Devsecops, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.kpmguscareers.com/jobdetail/?jobId=135849 ## About the Role * A minimum of eight years of cyber security engineering / solutions architecture experience; U.S. Federal government consulting experience preferred * Bachelor's degree from an accredited college/university * Preferred Certifications: CISSP (Certified Information Systems Security Professional), other relevant certifications (e.g. - CCSP, AWS Certified Security, Azure Security Engineer) * Experience working within federal, DoD, or highly regulated environments with a strong understanding of federal compliance frameworks (NIST, RMF, FedRAMP) * Experience planning and executing secure cloud migrations and managing native cloud security controls * Experience / knowledge implementing and managing SIEM and SOAR platforms (e.g. - Splunk, Sentinel, Cortex XSOAR) * Strong background in Identity and Access Management (e.g. - Okta, CyberArk, Microsoft Entra ID) * Ability to travel as required to support firm engagements * Applicant must possess a U.S. Government Secret clearance ## Description * Assist in the design, engineering, and implementation of Zero Trust architectures (ZTA) across enterprise environments, ensuring alignment with CISA Zero Trust Maturity Models and federal mandates * Collaborate with senior architects to integrate security controls into systems design, evaluating new tools / technologies to support a comprehensive defense-in-depth strategy * Integrate security controls into the software development lifecycle (DevSecOps), perform application vulnerability assessments, and establish secure application onboarding processes for enterprise environments * Support secure cloud migration initiatives, ensuring on-premise infrastructures and applications are safely transitioned to cloud environments (AWS, Azure, GCP) without compromising security postures or compliance requirements * Implement / manage robust identity solutions, focusing on Identity, Credential, and Access Management (ICAM), Multi-Factor Authentication (MFA), and least-privilege access frameworks * Ensure all security architectures and implementations comply with federal frameworks / standards, including NIST SP 800-53, NIST SP 800-207, Risk Management Framework (RMF), and Dod Cloud Computing Security Requirements Guide (SRG) * Develop and tune use cases for Security Information and Event Management (SIEM) platforms and automate incident response workflows using Security Orchestration, Automation, and Response (SOAR) tools * Monitor enterprise environments for anomalous activity, analyze security alerts, and assist in incident remediation efforts ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)