> Markdown version of [/jobs/ext/3555616-principal-cyber-security-engineer-and-architect](https://www.wearedevelopers.com/jobs/ext/3555616-principal-cyber-security-engineer-and-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cyber Security Engineer and Architect - **Company:** Verizon Communications Inc. - **Location:** Ashburn, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $132,500.0 - $231,000.0 - **Contract:** Permanent contract - **Skills:** 4G (Telecommunication), Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Internet Protocol Security (IP SEC), Information Systems Security Architecture Professional, Network Security, Windows Servers, Network Architecture, OpenShift, OpenStack, Public Key Infrastructure, Zero Trust Network Access, Systems Architecture, Transmission Control Protocol (TCP), Virtualization Technology, Network Access Control, Delivery Pipeline, Containerization, Kubernetes, CIS Benchmarks - **Published:** October 2, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88499940/1 ## About the Role The Corporate Security team is seeking an experienced, self-motivated System Architecture Engineer to join the National Security Program Office (NSPO). In this high-impact strategic role, you will be responsible for assessing, defining, and establishing core cybersecurity guidelines, guardrails, and technical standards across all sensitive and mission-critical programs., * Bachelor's degree or four or more years of work experience. * Six or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training in system security engineering or network security architecture. * Must be able to have or obtain Top Secret Security Clearance Even better if you have one or more of the following: * Experience with Windows server operating environments and UNIX/Linux systems engineering (variety of variants). * Expertise in TCP/IP networking, 4G/5G call flows (SBI, Diameter, SIP), and virtualization technologies like OpenStack and OpenShift / Kubernetes. * Strong foundational knowledge of incident response lifecycles (NIST or SANS) with experience designing, testing, and maintaining automation playbooks using SOAR platforms. * Hands-on experience translating cybersecurity frameworks, such as NIST (800-53, 800-171, CSF), CIS Benchmarks, CISA directives, and SANS baselines, into enforceable engineering controls and technical guardrails. * Proven experience conducting security assessments against baseline standards to identify architectural gaps, drift, or vulnerabilities, driving remediation plans to enforce compliance. * Hands-on experience with virtualization, containerization, and cloud infrastructure security (e.g., Kubernetes, OpenShift, OpenStack, AWS/Azure government environments). * Expertise in cryptographic controls and data-in-transit / data-at-rest encryption standards (e.g., IPsec, TLS 1.3, MACsec, PKI). * Advanced architecture and security certifications such as CISSP, CISSP-ISSAP (Architecture), CCSP, CISM, or vendor networking/security certifications (e.g., CCNP Security, PCNSE). * Solid understanding of Identity and Access Management (IAM), Least Privilege access frameworks, and Network Access Control (NAC) integration. * Strong analytical skills and attention to detail with a proven track record of managing and delivering results. * Ability to work independently, keeping project teams aware of strategic technical challenges .Experience working within or supporting sensitive/restricted program environments. ## Description Working as a core member of the NSPO, you will bridge organizational security requirements with technical execution. Beyond policy creation, you will directly lead the hands-on implementation and enforcement of these guardrails across critical enterprise infrastructures to ensure all program environments operate strictly according to guidelines published by CISA, CIS, NIST, and SANS., * Guardrail & Baseline Creation: Assess program requirements and author technical security guidelines, policy baselines, and architectural guardrails for all sensitive and mission-critical program environments based on CISA, CIS Benchmarks, NIST (e.g., CSF, 800-53, 800-171), and SANS guidance. * Architecture & Hands-On Implementation: Translate abstract security guidelines into concrete engineering controls. Lead the technical implementation of hardened network architectures, microsegmentation, zero-trust patterns, and secure configurations across classified infrastructures. * Security Assessments & Compliance: Evaluate existing program systems against published CISA/CIS/NIST baselines to identify architectural gaps, drift, or vulnerabilities, driving remediation plans to enforce compliance. * Cross-Functional & Security Partnership: Partner directly with Corporate Security, Cybersecurity teams, the Network and Security Operations Center (NSOC), infrastructure groups, and program leadership to align program guardrails with enterprise security strategy, report on compliance posture, mitigate architectural risks, and embed mandatory controls into build patterns, deployment pipelines, and operational workflows., Where you'll be workingIn this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)