19 days ago
Tysons, VA, USASenior

Responsibilities

  • Architect systems for authorization under FedRAMP, DoD RMF, CMMC, and related federal cybersecurity frameworks.
  • Translate NIST SP 800-53, NIST SP 800-171/172, and DoD security guidance into architecture patterns and engineering implementation strategies.
  • Define secure reference architectures covering identity, network segmentation, platform security, data protection, logging, monitoring, and system boundaries.
  • Guide engineering and DevSecOps teams in embedding security controls into platform architecture, CI/CD pipelines, and operational workflows.
  • Conduct security architecture, design, configuration, and DISA STIG reviews for applications, platforms, infrastructure, and operating systems.
  • Guide control inheritance, system boundary definitions, shared service architectures, automated compliance validation, continuous monitoring, and security telemetry.
  • Support GRC activities including control implementation planning, risk assessments, authorization readiness, SSPs, control narratives, architecture documentation, and POA&Ms.
  • Provide expertise for DoD Cloud Computing environments at IL4/5/6, National Security Systems, and systems handling CUI or National Security Information.
  • Brief engineering teams, leadership, and government stakeholders on architecture and security readiness.
  • Monitor evolving federal cybersecurity policy and translate new requirements into architecture and GRC guidance.

Requirements

  • Top Secret clearance is required, or the applicant must be eligible for a U.S. Government security clearance; only U.S. Citizens are eligible for a clearance.
  • Active CISSP, CISM, GSLC, C|CISO, or comparable senior cybersecurity certification.
  • 10+ years of federal cybersecurity experience in system security engineering, security architecture, or GRC programs aligned with NIST SP 800-53 and the NIST Risk Management Framework.
  • Experience supporting systems pursuing FedRAMP, DoD RMF, or CMMC authorization.
  • Experience managing security controls and compliance activities, including SSP development, POA&M management, and authorization readiness.
  • Strong understanding of modern cloud architectures such as AWS or Azure, hybrid infrastructure, and containerized platforms.
  • Experience translating compliance frameworks into technical guidance for engineering teams and conducting architecture-related risk assessments.
  • Strong communication skills and ability to bridge security, engineering, and government stakeholders.
  • Preferred experience with DoD Cloud Computing SRG IL4/5/6 environments, National Security Systems, classified-adjacent architectures, DevSecOps platforms, compliance automation, GRC platforms, architecture or change advisory boards, CUI environments, and federal consulting, defense, intelligence, or mission-focused work.
  • Master’s degree or bachelor’s degree with equivalent experience.

Tech Stack

Categories

Logistics Management Institute

About Logistics Management Institute

1,001-5,000 employees
Contact me