> Markdown version of [/jobs/ext/3003708-lead-security-architect](https://www.wearedevelopers.com/jobs/ext/3003708-lead-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Architect - **Company:** ShorePoint, Inc - **Location:** Herndon, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** 3d Models, Agile Methodology, Cyber Security, Information Systems, DevOps, Federal Enterprise Architecture, Identity and Access Management, Virtual Private Networks (VPN), Network Security, Network Segmentation, OAuth, Public Key Infrastructure, Systems Development Life Cycle, Zero Trust Network Access, Security Assertion Markup Language (SAML), TCP/IP, IT Architecture, Firewalls (Computer Science), Togaf, Information Technology, Cybercrime, DODAF - **Published:** September 19, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9178299/lead-security-architect ## About the Role We are seeking a Lead Security Architect who possesses deep technical mastery in designing resilient, enterprise-grade security frameworks. You will serve as the strategic visionary and technical anchor, ensuring our mission-critical systems are inherently secure by design and aligned with evolving federal defense standards. In this role, the Lead Security Architect will bridge the gap between complex engineering requirements and executive risk management orchestrating the transition to a robust Zero Trust environment. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market., * Deep proficiency in describing and documenting IT architectures using frameworks such as TOGAF, DoDAF or FEAF, with a focus on integrating security into the full system development life cycle. * Mastery of Zero Trust Architecture (ZTA) principles, including identity management (PKI, Oauth, SAML), micro-segmentation and secure cloud/hybrid IT delivery models like DevOps and Agile. * Comprehensive knowledge of NIST 800-series, FedRAMP and the Risk Management Framework (RMF) to ensure systems meet stringent federal and defense cybersecurity standards. * Technical expertise in network security (TCP/IP, VPNs, firewalls), encryption algorithms and the ability to design countermeasures against complex cyber threats and vulnerabilities. * Ability to translate operational requirements into technical protection needs and effectively communicate risk and design concepts to both technical experts and executive stakeholders. Must have's: * 10+ years of professional experience in cybersecurity, including 5+ years in security architecture or a senior technical role * One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC Security Enterprise Architect (GSEA) or GIAC Defensible Security Architecture (GDSA). * Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking. * Demonstrated experience architecting secure enterprise systems using Zero Trust Architecture (ZTA) principles. * Applicants must be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements. Beneficial to have: * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related field. ## Description * Lead the design and evaluation of enterprise security architectures, ensuring all systems align with Zero Trust Architecture (ZTA) principles and organizational cybersecurity guidelines. * Serve as the primary technical liaison between enterprise architects and systems security engineers to ensure security controls are correctly allocated and implemented. * Convert complex operational needs and stakeholder security interests into detailed technical requirements and functional specifications. * Provide critical input to the Risk Management Framework (RMF) process, including the development of system life-cycle support plans and operational procedures. * Manage security requirements throughout the acquisition life cycle, from drafting statements of work to evaluating vendor-proposed security designs for adequacy. * Perform regular security reviews and design modeling to identify architecture gaps, developing comprehensive risk management plans to address vulnerabilities. * Categorize systems and define clear security boundaries, documenting the protection needs for information systems and networks. * Advise senior leadership and authorized officials on design concepts, project costs and the potential adverse effects of identified vulnerabilities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)