> Markdown version of [/jobs/ext/2295100-ics-security-architect-remote-nationwide](https://www.wearedevelopers.com/jobs/ext/2295100-ics-security-architect-remote-nationwide). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICS Security Architect - Remote/Nationwide - **Company:** Signature Performance, Inc. - **Location:** Little Rock, AR, United States (Remote available) - **Experience:** Expert - **Salary:** $135,000.0 - $151,000.0 - **Contract:** Permanent contract - **Skills:** User Authentication, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Federal Information Processing Standards (FIPS), Identity and Access Management, OpenID, Public Key Infrastructure, Role-Based Access Control, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Software, Security Information and Event Management, Data Streaming, Software Vulnerability Management, Data Logging, Computer Networking Systems, Software Security, Multi-Cloud, Devsecops, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 29, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18128020?backUrl=%2Fcareer%2F18128020%2FIcs-Security-Architect-Remote-Nationwide-Arkansas-Little-Rock ## About the Role You are a person who is passionate about leading security architecture planning and design recommendations for regulated SaaS, cloud, on-premises, hybrid, and future multi-cloud environments, including Azure Government and other federal or high-compliance environments. We need someone who has experience translating FedRAMP Moderate/High, NIST, FIPS, HIPAA, FISMA, CMMC, and other applicable security requirements into technical designs, implementation guidance, standards, and audit-ready evidence, with depth in identity, authentication and authorization, password less access, PIV/CAC, federal integrations, encryption, segmentation, logging, DevSecOps, and continuous monitoring)., * Must be able to meet applicable federal background, credentialing, and access requirements, including NACLC or successor federal suitability/clearance requirements when applicable. * Bachelor's degree in a relevant technical field or equivalent experience. * CISSP, CCSP, CISM, or comparable advanced certification strongly preferred. * Eight (8)+ years of progressive experience in information security, security architecture, application security, cloud security, or related regulated-technology environments. * Deep expertise: FedRAMP Moderate/High; NIST 800-53/171; CMMC; FIPS; HIPAA; FISMA. * Azure/Azure Government, on-premises, and hybrid experience; multi-cloud preferred. * Expert IAM: OIDC/SAML, MFA/passwordless, PIV/CAC, PKI, RBAC/ABAC, and PAM. * Experience with VA or other federal-customer integrations. * Architecture artifacts: boundaries, data flows, threat models, interconnections, and ADRs. * Experience with SSPs, POA&Ms, ConMon, 3PAO/audit, assessments, and evidence. * Experience supporting security architecture for SaaS offerings operating in regulated or federally authorized environments, including shared-responsibility models, inherited controls, customer responsibility matrices, system interconnections, evidence support, and continuous monitoring obligations. * Experience designing security patterns for configurable workflow, case management, or business process automation platforms that may be deployed across cloud, on-premises, hybrid, or customer-managed environments. * SIEM, vulnerability management, DevSecOps, API security, Zero Trust, segmentation, and keys. * Proficient understanding of computer and network systems, security protocols, vulnerability assessment tools, security software, and secure system design. * Skilled in technical writing, including IT security policies, procedures, standards, reports, control narratives, and architectural drawings. * Strong decision leadership, risk communication, vendor management, and prioritization. ## Description In the role of ICS Security Architect, you will be responsible for supporting regulated cloud, SaaS, federal enclave, and high-compliance architecture priorities. Secondary support may include corporate and enterprise security architecture initiatives as business priorities require, consistent with the position's responsibility to advance Signature's security posture across cloud, on-premises, hybrid, and SaaS environments. * Tell us about your experience with Information, Security & Architecture. * Are you a team player and a self-motivator? * We are counting on you to manage multiple projects using your problem-solving skills. * We are looking for someone UNCOMMON. What is uncommon about you? Are you highly committed? Are you team-oriented? Do you value professionalism, trust, honesty, and integrity? If so, we cannot wait to meet you. About The Position * Lead security architecture planning, design recommendations, and implementation guidance for regulated SaaS solutions, federal cloud environments, high-compliance enclaves, and hybrid/on-premises deployments. * Define authorization boundaries, trust zones, data flows, interconnections, and inheritance. * Translate FedRAMP Moderate/High, NIST, CMMC, HIPAA, FISMA, FIPS, and other applicable security requirements into secure designs, standards, implementation guidance, and evidence. * Design IAM, least privilege, passwordless, PIV/CAC, privileged/service access, and federal integrations. * Define and recommend FIPS-aligned cryptography, PKI, key/secret management, TLS/mTLS, and encryption patterns. * Establish secure Azure, Azure Government, on-premises, hybrid, and multi-cloud patterns. * Design reusable security architecture patterns that can be adapted across customer-managed, company-managed, SaaS, cloud-hosted, on-premises, and hybrid deployment models. * Evaluate deployment models, shared-responsibility boundaries, authorization boundaries, inherited controls, customer-managed responsibilities, and interconnection risks to ensure security requirements are clearly defined and supportable. * Lead threat modeling, security design reviews, risk assessments, and development of security architecture artifacts. * Embed SAST/SCA/DAST, SBOM, secrets, IaC, container, and release gates into DevSecOps. * Define logging, SIEM, audit, continuous monitoring, vulnerability management, incident response, and POA&M requirements in coordination with responsible operational teams. * Develop SSPs, control narratives, diagrams, interconnections, standards, and evidence. * Support SaaS, federal, corporate, and enterprise security architecture initiatives as business priorities require, with primary focus on regulated technology environments and high-compliance architecture needs. * Assess vendor, contractor, supply-chain, and shared-responsibility risk; recommend action. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)