Overview
Responsibilities:
- Lead the development and implementation of robust security architecture strategies for hybrid cloud solutions across private and public cloud technologies.
- Collaborate closely with federal client stakeholders to comprehend technical requirements, business objectives, and security mandates.
- Design and oversee the integration of security measures into cloud-based systems, ensuring compliance with NIST 800-53 standards and the cybersecurity framework.
- Evaluate and select appropriate security technologies, tools, and practices to safeguard data, applications, and infrastructure within hybrid cloud environments.
- Provide expert guidance to cross-functional teams, including architecture, engineering, operations, and compliance, to ensure security considerations are embedded in all stages of project lifecycles.
- Conduct comprehensive risk assessments, threat modeling, and vulnerability analysis to identify potential security gaps and develop mitigation strategies.
- Develop and document security architecture blueprints, guidelines, and best practices for consistent implementation across projects.
- Serve as a subject matter expert on security matters, representing the organization in client meetings, industry events, and regulatory discussions.
- Collaborate with internal teams to create and deliver security training programs to enhance security awareness and ensure compliance.
- Stay up-to-date with emerging security threats, industry trends, and federal regulations to continuously adapt and improve security strategies.
- Manage communication with federal clients, providing regular updates on security initiatives, risks, and milestones.
Qualifications:
- Bachelor’s degree in Information Security, Computer Science, or a related field.
- 5 years of experience in security architecture, with a focus on hybrid cloud solutions.
- 10 years of experience supporting large federal agencies in the DC Metro area demonstrating a strong understanding of their security needs and compliance requirements.
- Must possessd several industry-accepted security certification (e.g., CISSP, CISM, CCSP)
- 5 years of experience using NIST 800-53 security standards, the NIST Cybersecurity Framework, and other relevant federal security guidelines.
- 8 years of experience with security assessment tools, vulnerability management, and penetration testing methodologies.
- Must live a commutable distance to the client site in NoVa.
- Must be a US citizen
Job Type: Full-time
Benefits:
- 401(k)
- Dental insurance
- Health insurance
Experience:
- penetration testing: 8 years (Required)
- NIST 800-53: 5 years (Required)
License/Certification:
- CISSP (Required)
- U.S. Citizenship (Required)
Work Location: In person
Job Type:Full Time