Skip to main content
Tallo logoTallo logo
Apply for this opportunity

This job application is on an outside website. Be sure to review the job posting there to verify it's the same.

Solutions Architect - FDIC Enterprise DevSecOps

Job

Leidos

Arlington, VA (In Person)

Full-Time

Posted 5 days ago (Updated 22 hours ago) • Actively hiring

Expires 7/23/2026

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
84
out of 100
Average of individual scores

Were these scores useful?

Skill Insights

Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.

Job Description

•Description•The Solutions Architect is a Key Personnel role on the FDIC Enterprise DevSecOps program, supporting the client's CIO organization (CIOO). The architect owns the target-state design of the FDIC DevSecOps platform - a hybrid estate spanning Azure/AKS, AWS, mainframe z/OS/Endevor, and enterprise middleware (WebLogic/WebSphere, Oracle, PeopleSoft, SAP, MuleSoft, Appian, Salesforce, Power Platform) across a large, complex enterprise DevSecOps environment at DevSecOps maturity Level 2 of 5. The architect translates FDIC Enterprise Architecture (EA) directives and enterprise architecture governance requirements into actionable, repeatable platform blueprints that enable development teams to ship securely with minimal client intervention. This role demands recent, hands-on design authority over the exact FDIC self-managed toolchain - GitHub Enterprise Server, GitHub Cloud/Actions, GitHub Advanced Security (GHAS), JFrog Artifactory/Xray, SonarQube, and Subject7 on Azure/AKS - and a demonstrated ability to harden that platform to FISMA-moderate, NIST 800-53/800-207, OMB M-22-09, and CISA Zero Trust Maturity Model 2.0 (target: Optimal) standards.
PRIMARY RESPONSIBILITIES
+ Platform Architecture and Target-State Design + Own the DevSecOps platform architecture across the FDIC hybrid estate (Azure primary - AKS, ACR, App Gateway, Key Vault; plus AWS, mainframe z/OS/Endevor, WebLogic/WebSphere, Oracle, PeopleSoft, SAP Data Services, MuleSoft, Appian, Salesforce, Power Platform); produce and maintain Architecture Decision Records (ADRs) aligned to FDIC target-state EA. + Design self-managed platform deployments for JFrog Artifactory/Xray, SonarQube, GitHub Enterprise Server (GHES), GitHub Advanced Security (GHAS)/CodeQL, and Subject7 on AKS; define upgrade paths under the n/n-1 version strategy. + Establish immutable-infrastructure and GitOps patterns (Flux, Helm) for the AKS platform; author Terraform IaC modules and Bicep templates for repeatable, policy-compliant provisioning across Azure and AWS landing zones. + Design pipeline architecture for a large CI/CD pipeline estate (GitHub Actions; on-prem, cloud, hybrid, multicloud patterns), integrating blocking security gates:
SAST/SCA
on Critical/High, IaC scan on Critical, DAST on Critical, container scan on Critical/High, SonarQube quality gate on fail. + Define architecture for GitHub Copilot (SaaS) integration and AI-assisted development workflows within FDIC compliance constraints. + Security Architecture and Zero Trust + Architect Zero Trust controls aligned to OMB M-22-09 and
CISA ZTMM 2.0
at Optimal maturity; map identity (Entra/CyberArk), device, network, application, and data pillars to the DevSecOps toolchain. + Design policy-as-code enforcement (OPA/Gatekeeper, Azure Policy) for Kubernetes admission control and IaC guardrails; ensure CyberArk and Azure Key Vault secrets management patterns meet FIPS 140-2/3 and PQC (FIPS 203/204/205) requirements. + Define cATO (continuous ATO) architecture: continuous compliance monitoring via Splunk and DynaTrace, automated evidence collection, and alignment to
NIST 800-37/800-53/800-88/800-207
control families for FISMA-moderate boundary. + Establish container security architecture integrating Aqua, Trivy, Trufflehog, and GHAS/CodeQL scanning into build and release pipelines; ensure secrets + peer-review gates at Develop stage are architecturally enforced. + Lead architecture reviews through enterprise architecture and change governance boards (EA fitness gate), CCB, ISSM/ISSO, and OCISO coordination bodies; produce fitness-gate artifacts that prevent rework. + Hybrid and Mainframe Integration Architecture + Design integration patterns connecting Azure/AKS cloud pipelines to mainframe z/OS/Endevor build and deploy workflows; ensure CI/CD coverage spans both cloud and mainframe application portfolios within the full enterprise application scope. + Architect API and event-driven integration patterns for MuleSoft, Appian, Salesforce, and Power Platform workloads; define DevSecOps onboarding playbooks for each platform tier. + Produce reference architectures for WebLogic/WebSphere, Oracle, PeopleSoft, and SAP Data Services application pipelines, covering build, scan, test (Selenium/Playwright/JMeter/Subject7), and release stages. + SLA, Observability, and Reliability Architecture + Architect the observability stack (Splunk, DynaTrace, Azure Monitor) to enforce >99.5% availability SLAs for the 83 Mission Essential/Critical applications and Critical/High security-finding remediation within