> Markdown version of [/jobs/ext/1855783-mid-level-applied-security-architect](https://www.wearedevelopers.com/jobs/ext/1855783-mid-level-applied-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Level Applied Security Architect - **Company:** Koniag Services, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Salary:** $120,000.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing Security, Configuration Management, Cyber Security, Data Stores, File Transfer, Monitoring of Systems, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Role-Based Access Control, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, Cloud Platform System, Infrastructure Automation Frameworks, Information Technology, Data Analytics, Tools for Reporting, Data Pipelines, Devsecops, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://dejobs.org/x/x/51267345C3B24311A10477A847229F35/job/ ## About the Role * Bachelor's degree in computer science, information security, engineering, or a related field. * 4-6 years of experience in cybersecurity engineering/architecture, security operations, or compliance in federal or regulated environments. * Practical experience implementing controls for cloud and hybrid systems (identity, encryption, logging, least privilege, hardening). * Handson familiarity with SIEM/monitoring tools, vulnerability scanners, endpoint protection, and configuration management. * Strong understanding of protecting sensitive data (e.g., proposal content, PII) and operationalizing privacy/security requirements. * Clear written and verbal communication skills for technical documentation, diagrams, and leadership briefings. * Demonstrated ability to collaborate with cross-functional teams and deliver secure solutions on schedule. * U.S. citizenship and ability to meet federal suitability requirements if needed. Security Requirement: * Ability to obtain a Public Trust, * Experience supporting DOE SBIR/STTR or other federal research/innovation programs. * Working knowledge of federal cybersecurity frameworks and standards (e.g., NIST SP 800 series, FISMA), zero trust principles, and control baselines. * Exposure to FedRAMP aligned cloud environments and securing SaaS platforms used for collaboration, workflow, and data analytics. * Certifications such as Security+, SSCP, CySA+, CCSP, or GIAC (e.g., GSEC, GCSA); progress toward CISSP or CISM is a plus. * Familiarity with secure DevSecOps practices, automation, infrastructure as code, and compliance as code concepts. * Background or interest in energy technologies or scientific R&D environments. Key Competencies: * Security Architecture & Control Implementation * Risk Identification and Mitigation * Data Protection and Access Governance * Continuous Monitoring and Incident Readiness * Stakeholder Collaboration and Communication * Process and Workflow Improvement * Analytical and Critical Thinking * Technical Documentation and Standards Knowledge, Skills, and Abilities (KSAs) Knowledge: * Understanding of federal cybersecurity requirements, control frameworks, and DOE mission context for research programs. * Knowledge of secure cloud/hybrid architectures, IAM models, encryption methods, logging/telemetry, and vulnerability management. Skills: * Designing diagrams and control mappings; implementing technical safeguards across program workflows. * Performing risk assessments, threat modeling, configuration hardening, and remediation tracking * Building monitoring dashboards, alert logic, and concise security reports for leadership and auditors. * Using security tools (SIEM, EDR, scanners, CM baselines) and integrating them with operational processes. Abilities: * Ability to translate requirements into actionable, auditable designs that balance security with usability and performance. * Ability to collaborate with technical and nontechnical stakeholders and drive consensus on security priorities. * Ability to manage multiple tasks, deadlines, and change requests in a dynamic program environment. * Ability to contribute to a mission driven team and take ownership of deliverables from design through implementation. ## Description The Mid-Level Applied Security Architect provides hands-on cybersecurity architecture, control implementation, and compliance support for systems and workflows that enable the DOE Office of Technology Commercialization's SBIR/STTR programs. This role helps design secure solutions for proposal intake/review platforms, data repositories, analytics/reporting tools, and collaboration environments; implements technical safeguards for sensitive information; and contributes to continuous monitoring activities. The architect partners with senior security leadership, program managers, IT teams, reviewers, and contractors to translate requirements into practical, auditable controls that advance DOE's mission while protecting program data., * Design, document, and implement security controls across SBIR/STTR systems (cloud, onprem, and hybrid), aligned with program requirements. * Support development of secure architectures for applicant portals, proposal review workflows, data pipelines, and reporting dashboards. * Configure and maintain identity and access management (IAM), rolebased access, leastprivilege settings, and privileged access management. * Implement data protection safeguards (encryption at rest/in transit, key management, DLP policies, secure file transfer, tokenization where needed). * Contribute to vulnerability management and secure configuration baselines; perform assessments, track remediation, and update POA&Ms. * Assist with logging/telemetry design and SIEM use cases; tune alerts, create dashboards, and support continuous monitoring. * Participate in risk assessments and threat modeling for new features, integrations, and vendor tools supporting SBIR operations. * Draft and maintain technical procedures, configuration standards, and build/run books that codify secure operational practices. * Support compliance documentation (control narratives, diagrams, evidence collection) and ATO package preparation under senior guidance. * Coordinate with stakeholders to ensure security requirements are embedded early (secure-by-design) and do not impede mission delivery. * Contribute to incident response readiness (playbooks, tabletop exercises, post incident reviews) and implement corrective actions. * Recommend pragmatic process improvements that strengthen security posture and user experience across the program., This is a hybrid position requiring periodic onsite participation at DOE headquarters or designated facilities. Remote work is supported for routine responsibilities. Travel may be required for meetings, workshops, security assessments, or program coordination. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)