Enterprise Security Architect – Senior

Posted 11hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Enterprise Security Architect securing DHS ICAM applications and services. Integrating controls, supporting ATO activities, remediating vulnerabilities, and managing POA&Ms for federal environments.

Responsibilities:

  • Design and maintain enterprise security architecture for assigned ICAM applications and services
  • Translate DHS security requirements into implementable architecture and technical controls
  • Contribute to or oversee secure application and configuration development
  • Integrate security controls into application, infrastructure, cloud, and DevSecOps environments
  • Lead or support system security assessments and technical control validation
  • Develop, update, or support documentation required for Authorization to Operate activities
  • Identify and remediate vulnerabilities within DHS-required timeframes
  • Develop and manage remediation actions and POA&M items when findings cannot be immediately resolved
  • Work with development and testing teams to ensure security requirements are incorporated throughout the SDLC
  • Support development, integration, testing, and release activities within the assigned workstream
  • Review technical designs, code, configurations, security scan results, and implementation evidence
  • Help ensure medium- and high-severity static and dynamic application vulnerabilities are resolved before production release
  • Support incident investigation, root-cause analysis, and corrective action when security issues affect production systems
  • Maintain architecture, security, assessment, and remediation documentation

Requirements:

  • Experience designing or maintaining enterprise application or system security architecture
  • Experience integrating cybersecurity controls into software, cloud, infrastructure, or DevSecOps environments
  • Experience supporting security assessments or authorization activities
  • Experience identifying, documenting, and remediating technical vulnerabilities
  • Experience developing or managing POA&M remediation actions
  • Ability to work with software engineering and testing teams throughout the SDLC
  • Ability to interpret security requirements and translate them into technical controls
  • Ability to obtain and maintain favorable DHS EOD, suitability, and required system access
  • Prior DHS or federal civilian agency clearance or experience preferred
  • Experience supporting federal ATO packages or NIST Risk Management Framework activities preferred
  • Experience with ICAM, IAM, PIV, PKI, PAM, SSO, OAuth, OIDC, or access-control systems preferred
  • Experience with AWS, Azure, hybrid-cloud, or on-premises federal environments preferred
  • Experience with secure CI/CD pipelines and automated security gates preferred
  • Experience with SonarQube, Jenkins, GitHub Enterprise, Splunk, container security, STIGs, or hardened images preferred
  • CISSP, CSSLP, CCSP, AWS/Azure security certification, or comparable security credential preferred
  • Must be able to obtain and maintain required DHS access and suitability

Benefits:

  • 401(k)
  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance
  • Military Spouse Employment Partnership (MSEP)
  • Virginia Values Veterans (V3) Program
  • Inclusive hiring practices