CYBERSECURITY ARCHITECT

Confidential - Job Hiring
Arlington, VA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Shift work
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Amazon S3 Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Continuous Integration Hypervisor
+25 more
Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection Systems Information Systems Security Architecture Professional Network Security Platform as a Service (PAAS) Cloud Services Zero Trust Network Access Service Development Studio Security Information and Event Management Software Engineering Systems Integration Virtualization Technology Wide Area Networks Multi-Cloud HybridCloud Firewalls (Computer Science) Information Technology Hardware Infrastructure Cloudwatch Amazon Simple Queue Service (SQS) Ddos Splunk Serverless Computing Microservices

Job description

Zermount Inc. is seeking a highly talented, technical hands-on Cybersecurity Architect to help accelerate our Cybersecurity Program for a Government Agency. The Agency operates a complex hybrid environment spanning on-premises and cloud infrastructure and services, with a mandate to modernize its security posture in alignment with Executive Order 14028, NIST Zero Trust Architecture guidance, and the Federal Zero Trust Strategy.

This role is the technical design authority on the contract. The Cybersecurity Architect owns the architectural direction for Zero Trust implementation across the hybrid environment, leads the development of Continuous Authorization to Operate (cATO) capabilities to accelerate and automate the current ATO process, and provides hands-on engineering leadership supporting network security, cloud security, and compliance.

The right candidate brings deep cybersecurity architecture experience, hands-on engineering capability, and the credibility to operate across both technical working groups and executivelevel discussions with government leadership and authorizing officials.

Du es and Responsibilities

  • Develop and maintain Enterprise Security Architecture (ESA), cybersecurity roadmap in alignment with EO 14028 implementa on priori es: Zero Trust, Supply Chain Risk Management (SCRM), cri cal so ware security, and secure cloud adop on.
  • Design and lead implementa on of Zero Trust Architecture (ZTA) across the hybrid environment spanning on-premises infrastructure and cloud services, aligned with NIST SP 800-207 and the Federal Zero Trust Strategy (OMB M-22-09)
  • Research and evaluate emerging security capabili es - including AI/ML-assisted detec on and automa on for applicability to the agency requirements and poten al Zermount service development.
  • Lead architecture and implementa on of cATO capability replacing periodic assessment snapshots with automated, real- me security control monitoring and evidence collec on.
  • Plansconducts Proof of Concept (PoC) deployments within the client enterprise and/or in external vendor environments.
  • Understandsevaluates business, technicalfunctional requirements, translating mission goalsoperational directives into actionable recommendations.
  • Understand requirements, use cases, implementation challenges, client road mapsoperational pain points.
  • Designs solutions for existingongoing implementationssupports implementation efforts. This includes tool evaluation, adoption, implementationphase-out; system integration development and implementation; and feature/content development.
  • Assist in developing schedules, work breakdown structures (WBS’s)project schedules with the Technical Project Manager.
  • Collaborates with internalexternal teamsensures clientNIST compliance.
  • Serves as a technical leadership role and provides services as a cross functional team member supporting other Task Areas as required., * This is a primarily remote position. Candidates must be able to travel occasionally to Zermount headquarters and customer sites based on program needs, meetings, workshops, and deployment activities.

Requirements

Do you have experience in WAN?, * High level of attention to detail, needs minimal guidance, effective verbal, and written communications.

  • Equally adept at strategic planning and operational/technical level.
  • Able to adapt to new and changing requirements or priorities and manage work and resources accordingly.
  • At least 10 years of hands-on technical IT and cybersecurity experience. To include experience with:
  • LAN/WAN, WAF/CDN/DDoS, Network Firewalls, IDS/IPS, inline decryption. o Experience with NIST RMF, FedRAMP, FISMA, and NIST SP 800-53 control implementation. o Experience with SIEM platforms (Splunk preferred) - log architecture, ingestion design, detection tuning.
  • Virtualization, hypervisor, and container security. o Application development, serverless security, microservices, CI/CD.
  • Designing and/or implementing security in Cloud (AWS required, Azure or GCP optional): Multi-Cloud, Hybrid Cloud, IaaS, PaaS, SaaS, shared responsibility model. AWS IAM, KMS, S3, RDS, SNS/SQS, Organization, Guard Duty, Security Hub, Detective, Config, CloudTrail, CloudWatch, Lambda.

EDUCATION:

  • A minimum of a Bachelor of Science in one of the following: Computer Science, Engineering, Information Technology, Cybersecurity or similar field. Years of experience will be taken into consideration, in place of a degree.

CERTIFICATIONS:

  • One or more industry-recognized cybersecurity certifications aligned with DoD 8570/8140 IAM Level III or IAT Level III baseline requirements.

Ideal candidate would also have:

  • Certified Cloud Security Professional (CCSP), AWS Certified Solutions Architect Associate, AWS Certified Security-Specialty.

CLEARANCE:

  • Must be able to obtain and maintain a Public Trust background investigation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all