
Cyber Security Architect
Posted Jul 20

Posted Jul 20
This is a fully remote position, open to applicants in United States.
• In the role of CACI Cyber Security Architect, you will serve as the technical leader accountable for the vision, design, and ongoing enhancement of security boundaries within the enterprise's Google Cloud environment.
• Security Architecture: Create and sustain scalable, security-first architectural blueprints for GCP landing zones, IAM hierarchies, and hybrid networking, in alignment with the DoD Cloud Computing Security Requirements Guide (SRG).
• Compliance as Code: Spearhead the conversion of intricate regulatory requirements (NIST SP 800-53, FedRAMP, CMMC) into technical controls, authoring and enforcing security policies within Infrastructure as Code (IaC) (Terraform) templates.
• Identity and Access Architecture: Formulate and oversee the enterprise IAM strategy, utilizing Workload Identity, Just-In-Time (JIT) access, context-aware controls, and MFA/CAC/PIV integration.
• Data Protection & Encryption: Establish the strategic vision for data protection by designing key management strategies across Cloud KMS/HSM/EKM and architecting data encryption protocols to secure data both at-rest and in-transit.
• Network Security Design: Supervise the architectural design of network security controls, including VPC Service Controls, Cloud Armor policies, and firewalls, to reduce risks of data exfiltration.
• Technical Leadership: Function as the primary technical advisor and final point of escalation for cloud security threats, risk models, and architectural design choices.
• Mentor engineers and developers on secure cloud methodologies.
• Security Automation: Design secure, automated telemetry and audit logging pipelines that integrate seamlessly into SIEM systems (e.g., Google Security Operations/Chronicle).
• Must be a U.S. Citizen with an active TS/SCI security clearance.
• Bachelor's degree in Computer Science, Cyber Security, or a related STEM discipline (or equivalent practical experience).
• CISSP certification (or equivalent, to satisfy DoD 8570/8140 IAM/IASAE Level III criteria).
• Over 8 years of technical experience in positions such as Cybersecurity Architect, Infrastructure Engineer, or a similar senior technical role.
• At least 5 years of focused experience in designing, migrating, and securing workloads on Google Cloud Platform (GCP), with profound expertise in networking, IAM, and security services.
• Established proficiency in writing and securing Terraform deployments and automating security workflows within CI/CD pipelines.
• Proven experience in architecting solutions to comply with stringent frameworks (e.g., NIST SP 800-53, FedRAMP, DoD SRG) and supporting the Risk Management Framework (RMF) process to achieve an Authority to Operate (ATO).
• Google Cloud Professional Cloud Security Engineer certification.
• Google Cloud Professional Cloud Architect certification.
• Healthcare
• Wellness
• Financial
• Retirement
• Family support
• Continuing education
• Time off benefits
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.