Cloud Security Architect
Job Title:
Cloud Security Architect (Top Secret Cleared)
Location:
Ft. Meade, MD (hybrid)
Position Type:
Full-time, Direct HireSalary Range:
$140-160,000 (or higher/negotiable based on experience)
Summary:
The Cloud Security Architect provides specialized cybersecurity architecture and engineering guidance for modern, distributed, cloud, and cloud-native DoD environments. The position serves as a technical security consultant to architects, developers, ISSMs, and ISSOs and helps ensure security is engineered into cloud solutions.
Responsibilities:
- Design, review, and recommend secure architectures for cloud, hybrid, distributed, and cloud-native environments.
- Perform security architecture and design reviews to identify design-level weaknesses and recommend appropriate mitigations.
- Provide specialized security guidance for APIs, microservices, containerized workloads, Docker, Kubernetes, serverless functions, and software-defined networking.
- Analyze cloud architectures, system interfaces, trust boundaries, network segmentation, and data flows for cybersecurity risk.
- Translate RMF, NIST, DoD cybersecurity, and hardening requirements into actionable cloud engineering solutions.
- Collaborate with system owners, developers, and architects during requirements development, design reviews, modernization efforts, and implementation.
- Recommend practical technical controls such as multi-factor authentication, encryption, secure network zoning, access controls, and other security mechanisms.
- Support vulnerability remediation and development of technically sound mitigation strategies that reduce attack surface while maintaining mission capability.
- Provide technical recommendations to ISSMs/ISSOs and clearly communicate architectural risks and mitigation alternatives to Government stakeholders.
Qualifications:
- Bachelor's degree or additional equivalent professional experience.
- 10+ years of related experience.
- DoD 8140 Work Role 652 - Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
- Must have and maintain a current DoD Top Secret clearance.
- Demonstrated cloud and cloud-native security architecture experience.
- Demonstrated expertise securing APIs, microservices, containerized workloads, Kubernetes/Docker, serverless functions, and software-defined networking.
- Expert knowledge of
RMF, NIST SP
800-37, and NIST SP 800-53.