Cloud Cybersecurity Architect-Defense Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+34 more
Job description
SageTech Solutions a SDVOSB, Woman Owned Small Business is seeking a highly qualified, certified professional to serve as the Cloud Security Architect. The position will serve as a senior technical cybersecurity leader responsible for designing, implementing, and governing secure cloud architecture within a large, complex federal government enterprise. The successful candidate will have prior experience supporting organizations such as GSA, Department of Veterans Affairs (VA), Internal Revenue Service (IRS), Department of Defense (DoD), or another large federal/enterprise organization.
The Cloud Security Architect will provide architecture and engineering leadership across cloud, hybrid-cloud, and enterprise environments and ensure solutions comply with SABSA, NIST Risk Management Framework (RMF), FedRAMP, Federal Information Security Modernization Act (FISMA), Zero Trust principles, and federal Authorization & Assessment (A&A) and Authority to Operate (ATO) requirements.
The position requires 5-10 years of cybersecurity/cloud security experience, including substantial experience developing and implementing security architectures and supporting federal system authorization activities.
Key ResponsibilitiesCloud Security Architecture
· Design, develop, and maintain secure enterprise cloud and hybrid-cloud architectures supporting mission-critical federal systems.
· Develop security architecture patterns, reference architectures, standards, security guardrails, and technical implementation guidance.
· Apply SABSA (Sherwood Applied Business Security Architecture) principles to align business and mission requirements with security architecture and controls, knowledge to TOGAFF is also preferred.
· Integrate security requirements into enterprise architecture and cloud solution design processes.
· Evaluate existing and proposed cloud solutions for security risks, vulnerabilities, architectural weaknesses, and compliance gaps.
· Provide architectural guidance for IaaS, PaaS, SaaS, containerized, serverless, and hybrid-cloud environments.
· Support cloud security architectures within AWS, Microsoft Azure, Google Cloud Platform (GCP), and/or federal government cloud environments.
· Ensure cloud architecture incorporates Zero Trust principles, including identity, device, network, application/workload, and data security.
Federal A&A and ATO
· Provide expert technical leadership for federal Assessment & Authorization (A&A) and Authority to Operate (ATO) activities.
· Lead or support development, review, and maintenance of authorization documentation and security artifacts.
· Work with System Owners, ISSOs, ISSMs, Security Control Assessors, Authorizing Officials, engineers, developers, and program leadership throughout the authorization lifecycle.
· Support development and maintenance of:
o System Security Plans (SSPs)
o Security Assessment Plans (SAPs)
o Security Assessment Reports (SARs)
o Plans of Action and Milestones (POA&Ms)
o Risk Assessments
o Security Control Implementation Statements
o Continuous Monitoring Strategies
o System Boundary and Data Flow Diagrams
o Interconnection Security Agreements and related security documentation
· Assess security controls and technical implementations against federal requirements.
· Identify control deficiencies and develop technically sound remediation strategies.
· Support initial ATOs, ATO renewals, significant-change assessments, continuous authorization, and ongoing authorization activities.
FedRAMP and RMF
· Apply the NIST Risk Management Framework (RMF) throughout the system development and cloud service lifecycle.
· Provide expertise across RMF activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
· Support evaluation and implementation of FedRAMP security requirements for cloud services.
· Review Cloud Service Provider security capabilities and FedRAMP authorization packages.
· Perform security impact and risk analyses associated with implementation of cloud services.
· Develop control inheritance strategies for enterprise and cloud environments.
· Support implementation of common, hybrid, and system-specific security controls.
· Ensure security controls are properly mapped, implemented, documented, tested, and continuously monitored.
Cybersecurity Framework and Compliance Expertise, · Design architectures supporting privileged access management, least privilege, role-based access control, attribute-based access control, multifactor authentication, and identity federation.
· Integrate cloud security architecture with federal Zero Trust strategies.
· Develop security approaches for service accounts, privileged accounts, machine identities, APIs, and workload identities.
· Evaluate and recommend IAM/PAM technologies appropriate for large federal enterprise environments.
Cloud Security Engineering
· Provide technical leadership for implementation of cloud-native security controls.
· Develop security requirements for cloud network segmentation, encryption, key management, secrets management, logging, monitoring, and incident response.
· Ensure encryption requirements are appropriately implemented for data at rest and data in transit.
· Establish cloud security logging and telemetry requirements supporting enterprise SIEM and SOC operations.
· Provide security architecture guidance for DevSecOps and CI/CD environments.
· Support integration of security testing, vulnerability scanning, configuration management, and compliance validation into automated deployment pipelines.
· Work with engineering teams to remediate vulnerabilities, misconfigurations, and security architecture deficiencies.
Requirements
The candidate should possess advanced working knowledge of federal cybersecurity regulations, frameworks, policies, and standards, including:
· SABSA
· NIST Risk Management Framework (RMF)
· NIST SP 800-53
· NIST SP 800-37
· NIST SP 800-30
· NIST SP 800-137
· NIST Cybersecurity Framework (CSF)
· FedRAMP
· FISMA
· Federal Zero Trust Architecture requirements
· OMB cybersecurity requirements
· CISA cybersecurity guidance and directives
· DISA Security Technical Implementation Guides (STIGs), where applicable
· DoD cybersecurity and RMF requirements, where applicable
· CIS Controls and CIS Benchmarks
· Cloud Security Alliance (CSA) guidance and Cloud Controls Matrix
Identity, Access Management and Zero Trust, · Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related technical discipline. Master’s degree preferred.
· 5-10 years of progressively responsible cybersecurity experience, with significant experience in cloud security architecture, security engineering, or enterprise security architecture.
· Prior experience supporting GSA, VA, IRS, DoD, or another large and complex federal government or enterprise organization.
· Demonstrated experience implementing or applying the SABSA framework within enterprise cybersecurity architecture.
· Extensive experience with NIST RMF and FedRAMP.
· Demonstrated federal A&A and ATO experience.
· Experience developing and reviewing SSPs, POA&Ms, SARs, SAPs, risk assessments, security control documentation, and related authorization artifacts.
· Strong knowledge of NIST SP 800-53 security controls and control implementation.
· Experience designing security architectures for AWS, Azure, GCP, or equivalent government cloud environments.
· Experience securing enterprise hybrid-cloud and multi-cloud environments.
· Strong understanding of Zero Trust Architecture, ICAM/IAM, network security, data security, application security, vulnerability management, encryption, logging, monitoring, and incident response.
· Demonstrated ability to communicate complex cybersecurity risks and architectural decisions to both technical and executive stakeholders.
Required Certification
Candidate must possess a current certification meeting the applicable federal/DoD cybersecurity workforce requirements for a senior architecture or management role, such as an IAT/IAM Level III or IASAE Level III-equivalent qualification, as required by the contract.
Other certifications will increase salary range to $210K.
· SABSA Chartered Security Architect certification
· AWS Certified Security - Specialty
· Microsoft Certified: Azure Security Engineer Associate
· Other qualifying advanced cybersecurity/cloud certifications accepted under the applicable federal or DoD workforce framework.
Preferred Qualifications
· 10+ years of cybersecurity experience in large federal enterprise environments.
· Previous direct support to GSA, VA, IRS, DoD, DHS, HHS, or another Cabinet-level federal agency.
· Experience supporting High Value Assets (HVAs) and mission-critical federal information systems.
· Experience with FedRAMP Moderate and/or High environments.
· Experience with DoD Impact Level cloud environments.
· Experience developing enterprise security reference architectures and security architecture roadmaps.
· Experience integrating SABSA with TOGAF or other enterprise architecture frameworks.
· Experience with continuous ATO/cATO and automated compliance approaches.
· Experience implementing Infrastructure as Code and policy-as-code security controls.
· Experience supporting large-scale cybersecurity modernization and cloud transformation programs.
Core Competencies
· Enterprise Cloud Security Architecture
· SABSA Security Architecture
· Federal A&A / ATO
· NIST RMF
· FedRAMP
· Zero Trust Architecture
· Cloud Security Engineering
· IAM / ICAM / PAM
· Security Control Assessment
· Enterprise Risk Management
· DevSecOps Security
· Vulnerability and Configuration Management
· Security Automation
· Continuous Monitoring
· Federal Cybersecurity Compliance
· Executive and Technical Communication
Security Clearance
Must be able to obtain and maintain the federal background investigation, Public Trust, Secret, Top Secret, or other security clearance required by the applicable contract or agency.
Benefits & conditions
Pulled from the full job description
- 401(k)
- Retirement plan
- Paid time off
- Vision insurance
- Health savings account
- Dental insurance, * 401(k)
- Dental insurance
- Health savings account
- Paid time off
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Best Paying Jobs in Technology
7 Cloud Computing Trends Coming in 2025 for Developers