SECURITY ARCHITECT
Job Description
Executive Order (EO) 14028 "Improving the Nation's Cybersecurity" in terms of: Implementing Zero Trust; Enhancing Supply Chain Risk Management (SCRM); Addressing critical software; and Developing secure Cloud adoption.
Security Architecture Reviews
Develop, and integrate with other Cybersecurity workflow to include: ATO Intake, assessment, and Vulnerability Scanning process.
Integrate with Enterprise Architecture (EA) review process.
Perform security reviews based on RMF controls compliance, clients, and security best practices.
Develop security architectural patterns to enable faster ATO or assessment process by creating architectural designs that already meet compliance controls.
Develop Security Architecture Standards in Cybersecurity SharePoint site and cross-link with Cloud Operations (SSB) and Enterprise Architecture (EA) sites.
Provide security input on Cloud Center of Excellence (CCOE) and Cloud Advisory Council (CAC) agenda items by participating in technical working groups, providing security analysis, and providing recommendations.
Provide security architecture input for DevSecOps security strategy and roadmap including application and infrastructure vulnerability scanning, automated assessments, and security controls.
Research, document, and publish a Cloud Security Codex to include security best practices based on security architecture patterns or Cloud services guidance's such as security configuration or use-cases and design.
Recommends security requirements, architectural direction, and assists in pilot testing of key enterprise-wide initiatives to include:
Zero Trust Architecture (ZTA),
Secure Access Service Edge (SASE) including Cloud Access Security Broker (CASB),
Zero Trust Network Access (ZTNA),
Secure Web Gateway (SWG)
Trusted Internet Connection (TIC) 3.0
Identity, Credential, and Access Management (ICAM) - OKTA
Configuration Management Database (CMDB).
Evaluate a subset of the agency's High Value Asset (HVA) security posture to determine whether the agency has properly architected its cybersecurity solutions and provides agency leadership the risks inherent in the implemented cybersecurity solution.
Performs architecture design reviews including configuration and log reviews and perform network traffic analyses.
Produces a SAR Report to include HVAs architecture strengths and findings.
Cloud Security Engineering
Drive the pilot and adoption of Cloud Security Posture Management (CSPM).
Design and deploy native Cloud security services in AWS, Microsoft Azure, and Google Cloud.
Perform proof of value of Cloud-native, COTS, 3rd party, or opensource security capabilities by hands-on deploying and evaluating against security requirements.
Lead the development of scripts or code to perform Cloud Security assessments through Cloud native API or SDK.
Lead the development of enterprise cloud security blueprints to include security in Infrastructure as Code (IaC templates).
Requirements
High level of attention to detail, needs minimal guidance, effective verbal, and written communications.
Equally adept at strategic planning and operational/technical level.
Able to adapt to new and changing requirements or priorities and manage work and resources accordingly.
At least 5 years (preferred 10 years) of network, systems, applications:
LAN/WAN, WAF/CDN/DDOS, Network Firewalls, IDS/IPS.
Virtualization, hypervisor security, container security.
Application development, serverless security, microservices, CICD.
At least 5 years of designing and/or implementing security in Cloud (AWS required, Azure or GCP optional):
Multi-Cloud, Hybrid Cloud, IaaS, PaaS, SaaS, shared responsibility model.
AWS IAM, KMS, S3, RDS, SNS/SQS, Organization, Guard Duty, Security Hub, Detective, Config, CloudTrail, CloudWatch, Lambda.
Azure E3/E5, Active Directory, Blob, Azure Security Center, Key Vault, SSE, Monitor, Log Analytics, Policy.
Experience with DevSecOps strategy and implementation and designing architecture in accordance to RMF, CSF, FISMA, and Fedramp.
Familiarity with: ZTNA and SASE Framework, ICAM (OKTA), CWPP, SOC Operations, Vulnerability Threat Management, and Compliance.
At least 2 years working in or managing Agile Devops, Scrum, Kanban.
Education
Candidate must have a Bachelor of Science (or higher) in one of the following:
Computer engineering
Computer science
Information Technology (IT), or
Cybersecurity
The resume may reference another major, so long as the resume is clear that the degree addressed at a minimum one of the following: cyber security engineering, systems administration, information systems security, software development security, systems engineering, information systems or IT.
Certifications
The candidate must have a:
Certified Information Systems Security Professional (CISSP), and
At least one of the following, or equivalent:
Certified Cloud Security Professional (CCSP),
AWS Certified Solutions Architect Associate,
AWS Certified Security Specialist,
Microsoft Azure Solutions Architect,
Google Professional Cloud Architect.
Clearance
Public Trust
LOCATIONHours
Hybrid - primarly Remote, however, there maybe occasional times that the team could be asked to report to the office.locations are as follows:
USPTO HQ:
600 Dulany Street, Alexandria, Virginia 22314
Zermount HQ:
2111 Wilson Blvd, Ste 200, Arlington, VA 22201
Hours of Operation
8:00 am EDT - 4:30 pm EDT
