Senior Azure Government Security & Compliance Architect

CHAMELEON TECHNOLOGY PARTNERS, INC.
Tallahassee, FL, United States
23 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Application Configuration Access Protocols Software System Penetration Testing Audit Trail Microsoft Azure Chameleon Cloud Computing Cloud Computing Security Cyber Security System Configuration Database Storage Structures Multi-Factor Authentication
+20 more
Data Flow Control Identity and Access Management Instant Messaging Technology Key Management Raw Data Role-Based Access Control Power BI Azure Data Lake Data Streaming Software Vulnerability Management Information Security Management System Cloud Platform System System Availability Information Technology Data Analytics Patch Management Crosswalk Security Orchestration, Automation & Response Databricks Vulnerability Analysis

Job description

  • Position Type: Part-Time Consultant / Technical Vetting & Compliance Authority
  • Target Allocation: 8-10 hours/week average (Note: Workload rises substantially during security engineering phases, technical readiness reviews, and the structural execution of Deliverables 10, 11, and 12).
  • Technical Reality: This is an elite compliance role. The security architecture, authorization documentation, and continuous monitoring controls are too complex to distribute casually among traditional software developers. You will hold complete technical ownership over the platform’s defensive validation strategy.
  • Compensation Type: Milestone / Deliverable-Based Fixed-Price Engagement., Chameleon is seeking a Senior Azure Government Security & Compliance Architect to serve as the absolute authority for the security baseline of a high-visibility contract with the Florida Office of the Chief Inspector General (OCIG). In this role, you will take complete engineering and administrative ownership over defining, documenting, and validating the security controls transforming a data analytics Proof of Concept (POC) into a secure, multi-agency, enterprise-ready Decision Intelligence Platform. This platform will unify statewide oversight, tracking abnormal spending patterns, contract vulnerabilities, and fraud/waste/abuse risks across up to 35 state agencies. Because this is a high-visibility, firm-fixed-price (FFP) state government contract, you will maintain absolute technical accountability for establishing an infrastructure that aligns perfectly with state and federal statutory requirements, preparing the system for full production authorization and independent validation. Principal Responsibilities

  • Compliance Gap Analysis: Develop a comprehensive security compliance control crosswalk to identify, map, and remediate technical gaps against strict federal and state high-control baselines.
  • Identity & Access Architecture: Define and enforce a granular, role-based access control (RBAC) framework and end-to-end user lifecycle management model aligned strictly to least-privilege principles and multi-factor authentication (MFA) enforcement.
  • Audit Logging & Monitoring: Architect comprehensive audit logging, monitoring, and retention specifications for user actions, administrative events, system configurations, and raw data access layers to ensure absolute traceability.
  • Configuration Assessment: Conduct exhaustive, formal reviews of cloud, network, storage, and application configuration baselines to actively identify, catalog, and fix misconfigurations.
  • Vulnerability & Pentest Coordination: Manage internal and external vulnerability scanning protocols, orchestrate formal penetration testing events, and document the rigorous technical evidence confirming the resolution of high or critical findings.
  • Supply Chain Vetting: Perform comprehensive third-party risk assessments, map vendor/sub-vendor code dependencies, and produce a verified Software Bill of Materials (SBOM) alongside a critical service provider register.
  • Privilege Access Governance: Develop and execute structured privilege-access reviews to monitor elevated account allocations, analyze account activities, and mitigate credential risk exposure.
  • Incident Response Integration: Design and integrate actionable incident response workflows, contact escalation paths, security event reporting routines, and vulnerability patch management lifecycles that conform to state policies.
  • Authorization Package Compilation: Compile and validate all technical security artifacts, data-flow diagrams, system security plans (SSP-style), and readiness review dossiers required to clear independent state testing and ensure a seamless handover to the State., The State of Florida strictly evaluates and verifies all named staff experience for this contract. Generic resumes that only list generalized cybersecurity buzzwords or generic compliance tool lists without specific government framework context will be automatically rejected. To be considered for this role, your resume must explicitly detail the following metadata for your past contract positions: * The Government Customer: Explicitly name the agency and the high-control environment context (e.g., Federal Agency, Military Branch, State Department).

  • The Specific Compliance Baseline: Detail exactly how you applied security standards, naming the specific NIST families, FedRAMP control layers, or state statutory rules you personally mapped.
  • Architecture Scale & Complexity: Specify the exact size of the cloud network architecture, the number of distinct user roles or environments secure-mapped, and the precise project duration.
  • Personal Engineering Contribution: Detail exactly what you personally built, assessed, or documented (e.g., “Authored the System Security Plan for a FedRAMP High environment,” “Configured least-privilege Entra ID access policies for database storage”).
  • Deployment & Vetting Status: Explicitly state the true production, operational, or steady-state authorization status achieved by platforms under your security oversight.
  • Quantifiable Results: Include the precise metrics achieved under your guidance, such as percentage of vulnerabilities remediated, independent audit pass rates, or system availability uptime markers.

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status” Texting Privacy Policy

  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting “Stop”., We are looking for a Senior Cloud Systems Administrator (AWS + Azure) to support our client based in Tallahassee, FL. US BASED CANDIDATES ONLY. Candidates must be located in Ta…
  • 12 days ago
  • Apply easily

Requirements

We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward thinking candidates that have strong experience in operational support and can help take to the next level in a pro-active stance., * Experience Baseline: 10+ years of comprehensive information security engineering experience.

  • Cloud Depth: 5+ years of dedicated, hands-on cloud security architecture, data environment hardening, or security automation work.
  • Government Control Mastery: Documented history implementing and mapping controls against NIST SP 800-53 and NIST SP 800-171 within federal or state government systems.
  • High-Control Baselines: Direct experience preparing systems for or operating within FedRAMP High or comparable high-control, highly regulated environments.
  • Infrastructure Toolkit: Proven hands-on mastery of Azure and Entra ID security parameters, managed identities, automated secrets/key management, and Azure Key Vault configuration.
  • Threat Management: Strong background executing vulnerability management lifecycles, structured incident response mapping, and formal configuration assessments.
  • Supply Chain Architecture: Practical understanding of third-party risk assessment methodologies and familiarization with Software Bill of Materials (SBOM) compilation frameworks.
  • Testing & Assessment: Verifiable history acting as a security control assessor or leading technical control validation assessments.
  • Vetting & Location: Must be a U.S.-based citizen or resident. Must be able to successfully clear an FDLE Level II background screening (including fingerprinting) within 5 business days of contract award.

Strong Preferences

  • Prior experience navigating Florida state government compliance frameworks, specifically referencing Florida Administrative Code Rule 60GG-2 and Section 282.318, Florida Statutes.
  • Practical security engineering context handling CJIS or HIPAA regulated government data streams.
  • Hands-on security containment and control configuration for Azure Databricks workspaces, Azure Data Lake Storage Gen2 (ADLS Gen2), and Power BI workspaces inside Azure Government environments.
  • Proven experience compiling, submitting, or auditing formal FedRAMP authority to operate (ATO) authorization packages.
  • Active premium industry credentials such as CISSP, CISM, or CCSP.

Benefits & conditions

SMART TECH SKILLS LLC

  • Tallahassee, FL Benefits: Competitive salary Location Onsite: Tallahassee, FL Experience Level Senior Level (10+ years of relevant experience) Role Overview The Applications Developm…

  • 18 days ago +

About the company

Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U. S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

4:09 min

Challenges of interpreting raw data with language models

Clemens Vasters Clemens Vasters · World Congress 2025

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

2:09 min

Uncovering hidden coordinate manipulation communities in binary data

Nolan Royalty · Coffee With Developers

3:48 min

Standardizing data access schemas with OData

Florian Bader Florian Bader · World Congress 2026 Europe

Videos

See all

Related articles

See all