> Markdown version of [/jobs/ext/2571408-cloud-cybersecurity-architect-defense-manager](https://www.wearedevelopers.com/jobs/ext/2571408-cloud-cybersecurity-architect-defense-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Cybersecurity Architect-Defense Manager - **Company:** Sagetech Solutions, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $155,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Information Systems, Continuous Integration, Data Security, Multi-Factor Authentication, Enterprise Architecture Framework, Federated Identity Management, Infrastructure as a Service (IaaS), Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Network Security, Platform as a Service (PAAS), Systems Development Life Cycle, Role-Based Access Control, Cloud Services, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Policy as Code, Data Logging, Google Cloud, SARS Software Products, Cloud Platform System, Software Security, Multi-Cloud, HybridCloud, Togaf, Information Technology, Deployment Automation, Cloud Migration, CIS Benchmarks, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** August 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=04cd7b6b5787311d ## About the Role The candidate should possess advanced working knowledge of federal cybersecurity regulations, frameworks, policies, and standards, including: · SABSA · NIST Risk Management Framework (RMF) · NIST SP 800-53 · NIST SP 800-37 · NIST SP 800-30 · NIST SP 800-137 · NIST Cybersecurity Framework (CSF) · FedRAMP · FISMA · Federal Zero Trust Architecture requirements · OMB cybersecurity requirements · CISA cybersecurity guidance and directives · DISA Security Technical Implementation Guides (STIGs), where applicable · DoD cybersecurity and RMF requirements, where applicable · CIS Controls and CIS Benchmarks · Cloud Security Alliance (CSA) guidance and Cloud Controls Matrix Identity, Access Management and Zero Trust, · Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related technical discipline. Master's degree preferred. · 5-10 years of progressively responsible cybersecurity experience, with significant experience in cloud security architecture, security engineering, or enterprise security architecture. · Prior experience supporting GSA, VA, IRS, DoD, or another large and complex federal government or enterprise organization. · Demonstrated experience implementing or applying the SABSA framework within enterprise cybersecurity architecture. · Extensive experience with NIST RMF and FedRAMP. · Demonstrated federal A&A and ATO experience. · Experience developing and reviewing SSPs, POA&Ms, SARs, SAPs, risk assessments, security control documentation, and related authorization artifacts. · Strong knowledge of NIST SP 800-53 security controls and control implementation. · Experience designing security architectures for AWS, Azure, GCP, or equivalent government cloud environments. · Experience securing enterprise hybrid-cloud and multi-cloud environments. · Strong understanding of Zero Trust Architecture, ICAM/IAM, network security, data security, application security, vulnerability management, encryption, logging, monitoring, and incident response. · Demonstrated ability to communicate complex cybersecurity risks and architectural decisions to both technical and executive stakeholders. Required Certification Candidate must possess a current certification meeting the applicable federal/DoD cybersecurity workforce requirements for a senior architecture or management role, such as an IAT/IAM Level III or IASAE Level III-equivalent qualification, as required by the contract. Other certifications will increase salary range to $210K. · SABSA Chartered Security Architect certification · AWS Certified Security - Specialty · Microsoft Certified: Azure Security Engineer Associate · Other qualifying advanced cybersecurity/cloud certifications accepted under the applicable federal or DoD workforce framework. Preferred Qualifications · 10+ years of cybersecurity experience in large federal enterprise environments. · Previous direct support to GSA, VA, IRS, DoD, DHS, HHS, or another Cabinet-level federal agency. · Experience supporting High Value Assets (HVAs) and mission-critical federal information systems. · Experience with FedRAMP Moderate and/or High environments. · Experience with DoD Impact Level cloud environments. · Experience developing enterprise security reference architectures and security architecture roadmaps. · Experience integrating SABSA with TOGAF or other enterprise architecture frameworks. · Experience with continuous ATO/cATO and automated compliance approaches. · Experience implementing Infrastructure as Code and policy-as-code security controls. · Experience supporting large-scale cybersecurity modernization and cloud transformation programs. Core Competencies · Enterprise Cloud Security Architecture · SABSA Security Architecture · Federal A&A / ATO · NIST RMF · FedRAMP · Zero Trust Architecture · Cloud Security Engineering · IAM / ICAM / PAM · Security Control Assessment · Enterprise Risk Management · DevSecOps Security · Vulnerability and Configuration Management · Security Automation · Continuous Monitoring · Federal Cybersecurity Compliance · Executive and Technical Communication Security Clearance Must be able to obtain and maintain the federal background investigation, Public Trust, Secret, Top Secret, or other security clearance required by the applicable contract or agency. ## Description SageTech Solutions a SDVOSB, Woman Owned Small Business is seeking a highly qualified, certified professional to serve as the Cloud Security Architect. The position will serve as a senior technical cybersecurity leader responsible for designing, implementing, and governing secure cloud architecture within a large, complex federal government enterprise. The successful candidate will have prior experience supporting organizations such as GSA, Department of Veterans Affairs (VA), Internal Revenue Service (IRS), Department of Defense (DoD), or another large federal/enterprise organization. The Cloud Security Architect will provide architecture and engineering leadership across cloud, hybrid-cloud, and enterprise environments and ensure solutions comply with SABSA, NIST Risk Management Framework (RMF), FedRAMP, Federal Information Security Modernization Act (FISMA), Zero Trust principles, and federal Authorization & Assessment (A&A) and Authority to Operate (ATO) requirements. The position requires 5-10 years of cybersecurity/cloud security experience, including substantial experience developing and implementing security architectures and supporting federal system authorization activities. Key ResponsibilitiesCloud Security Architecture · Design, develop, and maintain secure enterprise cloud and hybrid-cloud architectures supporting mission-critical federal systems. · Develop security architecture patterns, reference architectures, standards, security guardrails, and technical implementation guidance. · Apply SABSA (Sherwood Applied Business Security Architecture) principles to align business and mission requirements with security architecture and controls, knowledge to TOGAFF is also preferred. · Integrate security requirements into enterprise architecture and cloud solution design processes. · Evaluate existing and proposed cloud solutions for security risks, vulnerabilities, architectural weaknesses, and compliance gaps. · Provide architectural guidance for IaaS, PaaS, SaaS, containerized, serverless, and hybrid-cloud environments. · Support cloud security architectures within AWS, Microsoft Azure, Google Cloud Platform (GCP), and/or federal government cloud environments. · Ensure cloud architecture incorporates Zero Trust principles, including identity, device, network, application/workload, and data security. Federal A&A and ATO · Provide expert technical leadership for federal Assessment & Authorization (A&A) and Authority to Operate (ATO) activities. · Lead or support development, review, and maintenance of authorization documentation and security artifacts. · Work with System Owners, ISSOs, ISSMs, Security Control Assessors, Authorizing Officials, engineers, developers, and program leadership throughout the authorization lifecycle. · Support development and maintenance of: o System Security Plans (SSPs) o Security Assessment Plans (SAPs) o Security Assessment Reports (SARs) o Plans of Action and Milestones (POA&Ms) o Risk Assessments o Security Control Implementation Statements o Continuous Monitoring Strategies o System Boundary and Data Flow Diagrams o Interconnection Security Agreements and related security documentation · Assess security controls and technical implementations against federal requirements. · Identify control deficiencies and develop technically sound remediation strategies. · Support initial ATOs, ATO renewals, significant-change assessments, continuous authorization, and ongoing authorization activities. FedRAMP and RMF · Apply the NIST Risk Management Framework (RMF) throughout the system development and cloud service lifecycle. · Provide expertise across RMF activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring. · Support evaluation and implementation of FedRAMP security requirements for cloud services. · Review Cloud Service Provider security capabilities and FedRAMP authorization packages. · Perform security impact and risk analyses associated with implementation of cloud services. · Develop control inheritance strategies for enterprise and cloud environments. · Support implementation of common, hybrid, and system-specific security controls. · Ensure security controls are properly mapped, implemented, documented, tested, and continuously monitored. Cybersecurity Framework and Compliance Expertise, · Design architectures supporting privileged access management, least privilege, role-based access control, attribute-based access control, multifactor authentication, and identity federation. · Integrate cloud security architecture with federal Zero Trust strategies. · Develop security approaches for service accounts, privileged accounts, machine identities, APIs, and workload identities. · Evaluate and recommend IAM/PAM technologies appropriate for large federal enterprise environments. Cloud Security Engineering · Provide technical leadership for implementation of cloud-native security controls. · Develop security requirements for cloud network segmentation, encryption, key management, secrets management, logging, monitoring, and incident response. · Ensure encryption requirements are appropriately implemented for data at rest and data in transit. · Establish cloud security logging and telemetry requirements supporting enterprise SIEM and SOC operations. · Provide security architecture guidance for DevSecOps and CI/CD environments. · Support integration of security testing, vulnerability scanning, configuration management, and compliance validation into automated deployment pipelines. · Work with engineering teams to remediate vulnerabilities, misconfigurations, and security architecture deficiencies. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)