Cyber Security Architect

CACI International Inc.
United States
28 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$105,100.0 - $231,100.0
Working hours
Regular working hours

Tech stack

Audit Trail Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Delivery Continuous Integration Data Security Cryptographic Protocols Identity and Access Management Internet Security Key Management
+12 more
Network Security Zero Trust Network Access Security Information and Event Management Software Engineering Google Cloud Istio Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Kubernetes Information Technology Terraform Security Orchestration, Automation & Response

Job description

As a CACI Cyber Security Architect you will be the technical leader responsible for the vision, design, and continuous improvement of security boundaries across the enterprise’s Google Cloud environment. This role sits inside the Special Operations Command Europe (SOCEUR) Hybrid Threat Action Platform (HTAP) program team and is responsible for championing secure-by-default blueprints, establishing zero-trust identity perimeters, and ensuring compliance with the most stringent federal security baselines. The individual will act as the senior technical advisor for all cloud security matters, translating high-level regulatory mandates into automated, secure-by-design Infrastructure as Code (IaC) for Allied, partner, and US operations., * Security Architecture: Design and maintain scalable, secure-by-default architectural blueprints for GCP landing zones, IAM hierarchies, and hybrid networking, in accordance with the DoD Cloud Computing Security Requirements Guide (SRG).

  • Compliance as Code: Lead the translation of complex regulatory requirements (NIST SP 800-53, FedRAMP, CMMC) into technical controls, authoring and enforcing security policies within IaC (Terraform) templates.
  • Identity and Access Architecture: Develop and govern the enterprise IAM strategy, leveraging Workload Identity, Just-In-Time (JIT) access, context-aware controls, and MFA/CAC/PIV integration.
  • Data Protection & Encryption: Define the strategic vision for data protection, designing key management strategies across Cloud KMS/HSM/EKM and architecting data encryption protocols to secure data at-rest and in-transit.
  • Network Security Design: Oversee the architectural design of network security controls, including VPC Service Controls, Cloud Armor policies, and firewalls, to mitigate data exfiltration risks.
  • Technical Leadership: Act as the primary technical advisor and final point of escalation for cloud security risks, threat models, and architectural design decisions. Mentor engineers and developers on secure cloud practices.
  • Security Automation: Architect secure, automated telemetry and audit logging pipelines that route seamlessly into SIEM systems (e.g., Google Security Operations/Chronicle).
  • .

Requirements

  • Must be a US Citizen possessing an active TS/SCI security clearance.
  • Bachelor’s degree in Computer Science, Cyber Security, or a related STEM field (or equivalent practical experience).
  • CISSP certification (or equivalent, to meet DoD 8570/8140 IAM/IASAE Level III requirements).
  • 8+ years of technical experience in roles such as Cybersecurity Architect, Infrastructure Engineer, or a similar senior technical position.
  • 5+ years of dedicated experience designing, migrating, and securing workloads on Google Cloud Platform (GCP), including deep expertise in networking, IAM, and security services.
  • Proven expertise in writing and securing Terraform deployments and automating security workflows in CI/CD pipelines.
  • Demonstrated experience architecting solutions to meet strict compliance frameworks (e.g., NIST SP 800-53, FedRAMP, DoD SRG) and supporting the Risk Management Framework (RMF) process to achieve an Authority to Operate (ATO).
  • Google Cloud Professional Cloud Security Engineer certification.
  • Google Cloud Professional Cloud Architect certification.

Desired:

  • Hands-on experience securing Kubernetes clusters (GKE) and utilizing service mesh technologies.
  • Deep familiarity with GCP-native threat defense tools like Security Command Center (SCC) Premium, Architectural Design, Architectural Services, Automation, Blueprints, Cloud Architecture, Cloud Computing, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Cryptographic Protocols, Cryptography, Federal Contracts, Federal Government, Firewalls, GCP (Good Clinical Practices), Government Contracts, Information/Data Security (InfoSec), Internet Security, Just in Time (JIT), Maintain Compliance, Management Strategy, Mentoring, Network Security Design, Protective Services, Regulations, Regulatory Requirements, Risk Management, Risk Management Framework (RMF), Risk Modeling, Safety/Work Safety, Security Architecture, Security Attacks, Security Clearance, Security Design, Security Information and Event Management (SIEM), Security Monitoring, Sensitive Compartmented Information (SCI), Software Engineering, Technical Leadership, Telemetry, Threat Modeling, Top Secret Clearance, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Defense (DoD), Willing to Travel

Benefits & conditions

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is: $105,100-$231,100

About the company

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose - to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation’s most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy., CACI provides information solutions and services in support of national security missions and government transformation for Intelligence, Defense, and Federal Civilian customers. A member of the Fortune 1000 Largest Companies, the Russell 2000 Index, and the S&P SmallCap 600 Index, CACI provides dynamic careers for over 15,800 employees working in over 120 offices worldwide. Visit www.caci.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:15 min

Deploying local container pods to Kubernetes clusters

Stevan Le Meur Stevan Le Meur · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all