> Markdown version of [/jobs/ext/2181616-cyber-security-architect](https://www.wearedevelopers.com/jobs/ext/2181616-cyber-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Architect - **Company:** PRECISE SOFTWARE SOLUTIONS INC. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Audit Trail, Cloud Engineering, Cyber Security, Information Systems Security Architecture Professional, Role-Based Access Control, Cloud Services, Zero Trust Network Access, Systems Integration, Data Logging, Multi-Cloud, Information Technology, Marketplace - **Published:** August 22, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18034102?backUrl=%2Fcareer%2F18034102%2FCyber-Security-Architect ## About the Role * Education: Bachelor's degree in computer science, engineering, cybersecurity, or equivalent architecture experience (OPM IT/cyber roles commonly recognize multiple education/experience pathways). * Experience: 10-15+ years in security engineering/architecture; 5+ years designing security architectures in regulated federal environments with NIST control baselines and formal ATO constraints. * Demonstrated ability to translate policy and controls into implementable architecture patterns (defense-in-depth, least privilege) consistent with CMS ARS framing. * Recommended Certifications: one senior security credential and/or cloud architecture credential demonstrating architecture competency (e.g., CISSP with architecture concentration, CCSP, cloud solutions architect), with hiring emphasis on demonstrated architecture artifacts and outcomes. Knowledge / Skills / Abilities * Ability to produce architecture artifacts that are consumable by delivery teams: reference architectures, guardrails, standards, and decision logs tied to policy and controls. * Deep knowledge of NIST control ecosystem and how it constrains design: SP 800-53 controls, SP 800-53A assessment evidence expectations, and RMF lifecycle. Systems security engineering approach for building trustworthy secure systems across life cycles (NIST SP 800-160). * Working knowledge of federal security programs relevant to the contract's cybersecurity support scope (CDM, TIC 3.0, Zero Trust) and the ability to integrate them into a Marketplace roadmap, * Zero Trust implementation experience in multi-cloud/hybrid architectures guided by NIST SP 800-207, including identity-centric access patterns and segmentation aligned with federal guidance. * Experience enabling TIC 3.0-aligned boundary modernization and integrating enterprise security services without duplicating SOC functions. * Experience designing security automation and "paved road" guardrails that reduce manual O&M and improve evidence collection consistency. ## Description Provides technical strategy and Marketplace security reference architectures, evaluates and enables enterprise security tools/services, designs reusable security patterns and guardrails, advises engineering teams, and drives integration of security requirements into delivery roadmaps., Operational (architecture delivery) Develops and maintains Marketplace security reference architectures and implementation playbooks that engineering teams can apply consistently, reducing manual overhead ("build once ? reuse everywhere" as the broader team value proposition). Performs architecture reviews and technical design advisories that incorporate CMS ARS minimum controls and policy expectations into system designs. Managerial (enablement and alignment) Coordinates with enterprise security service providers to consume and properly integrate shared security platforms (e.g., logging, scanning, identity) while respecting contract guardrails (no duplicate SOC/monitoring). Aligns security architecture work to Agile roadmaps and PI planning cycles, ensuring delivery teams have actionable guardrails and backlog-ready requirements. Security-specific (Zero Trust, CDM, TIC, secure engineering) Guides Marketplace adoption of federal Zero Trust principles and architectures: NIST SP 800-207 defines Zero Trust Architecture components and transition steps; OMB M-22-09 sets federal agency Zero Trust expectations; and TIC 3.0 guidance supports modern network boundary/security approaches in federal environments. Supports cybersecurity risk reduction patterns such as Continuous Diagnostics and Mitigation (CDM), which CISA describes as delivering tools and dashboards to improve agency security posture; CMS also provides CDM educational framing. Applies systems security engineering principles to architect defensible, survivable systems, consistent with NIST SP 800-160's emphasis on engineering-driven security across system life cycles. Ensures forensic readiness and investigative support enablement by designing for audit logging, traceability, and evidence preservation needs described in the operational investigative approach. ## Related Videos - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)