Original listing text, shown exactly as published by the company.
Key Responsibilities
Security Architecture and Strategy
- Define the security architecture for AWS GovCloud workloads spanning identity, zero-trust access, network segmentation, encryption, monitoring, and data protection
- Design and own the zero-trust access architecture, leveraging Zscaler (ZTNA/SASE) to broker secure access to applications and infrastructure
- Design defense-in-depth control frameworks aligned to DoD and DISA requirements
- Produce security architecture documentation, control mappings, and decision records
- Establish security standards and reference patterns for engineering teams
Compliance and Authorization
- Lead security alignment with RMF, NIST 800-53, STIGs, and ATO and authorization processes
- Define control implementation and evidence strategies for audits and assessments
- Assess and communicate security risk to technical and non-technical stakeholders
- Guide POA&M development and remediation prioritization
Design Governance and Guidance
- Review architectures and designs to ensure security is embedded from the outset
- Set standards for least-privilege IAM, zero-trust secure access (Zscaler/ZTNA), and hardened baselines
- Guide engineers implementing security controls, detection, and response capabilities
- Lead security and threat-model reviews
Collaboration and Leadership
- Partner with cloud and solutions architects to ensure secure-by-design platforms
- Advise leadership on security strategy, posture, and risk trade-offs
- Mentor engineers and promote a strong security culture
Required Qualifications
- U.S. Citizenship required (for clearance purposes)
- 6+ years of security experience, including 3+ years in a security architecture or lead role
- Experience designing zero-trust architectures, ideally with Zscaler or a comparable ZTNA or SASE platform
- Deep expertise in cloud security architecture (AWS), identity, and network segmentation
- Strong command of security frameworks including NIST 800-53, RMF, and DISA STIGs
- Experience guiding systems through ATO and authorization in federal or DoD environments
- Strong understanding of defense-in-depth, zero-trust principles, and least-privilege design
- Ability to produce clear security architecture documentation and risk assessments
- Experience leading security across multidisciplinary teams
Preferred Qualifications
- Extensive experience in AWS GovCloud or other federal or regulated environments
- Deep experience architecting Zscaler or comparable ZTNA/SASE solutions and integrating them with identity and conditional access
- Experience with continuous monitoring, SIEM strategy, and incident response programs
- Experience with data security and protection of analytics and Medallion platforms…