Security Architect SME at Valiant Solutions LLC
Remote, Oregon, USA -
Full Time


Start Date

Immediate

Expiry Date

24 Oct, 25

Salary

190100.0

Posted On

24 Jul, 25

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Code, Security Controls, Technical Documentation, Cloud, Slide Decks, Interfaces, Enterprise, Microsoft Azure, Risk Management Plans, Diagrams

Industry

Information Technology/IT

Description

Position Description:
Valiant Solutions is seeking a Security Architect SME to join our rapidly growing and innovative cybersecurity team!
The Security Architect SME will lead the development of security architecture guidance, standards, and reference diagrams for on-premise and cloud platforms and systems. This is an exciting role to support both macro and micro security design for a large government agency. You’ll get to support a variety of cloud and on-premise projects, working with leading edge technology. This position requires a deep level of understanding of NIST Special Publications used to secure federal systems, including NIST SP 800-53. This knowledge must be combined with experience designing and assessing security architectures for both cloud and on-premise systems to protect the confidentiality, availability, and integrity of systems and their data using COTS tools, cloud native services, and component-level configuration settings. In this role, you will lead from the front as the key subject matter expert guiding our valued client. The successful candidate will support the design of Zero Trust security architectures and their associated guidance, working in iterations to tighten least privilege access controls and automate Zero Trust controls.
U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation.
Named one of the Best Places to Work in the Washington DC area for 11 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!
This position allows for 100% remote work. Remote work necessitates a high-level trust in our employees and we strictly adhere to the details found below in our Remote Work Policy.

REQUIRED EXPERIENCE

  • 7+ years of experience designing security architectures by referencing NIST security controls, agency policy, and government-wide security requirements. This experience must include the design of on-premise and cloud security fabrics for all layers of the system (application down to CSP).
  • 2+ years of experience designing Zero Trust Architectures to secure cloud and on-premise systems
  • Experience designing security architectures hosted in Microsoft Azure, using a combination of Azure-native services and COTS tooling
  • Experience assessing/reviewing security architectures, writing reports with detailed explanatory findings, and providing briefings on your findings.
  • Developing security architecture guidance to include policy language, Standard Operating Procedures, and as-code hardening standards.
  • Extensive knowledge of NIST 800- 53rev5 and other NIST Special Publications.
  • Current knowledge of government-wide security mandates and CISA Directives
  • Ability to define and document system security boundaries and categorize systems based on security and privacy requirements.
  • Skilled in analyzing user needs to inform and guide secure architecture planning.
  • Proven ability to assess and evaluate enterprise security postures and identify impacts from new systems or interfaces.
  • Experience developing technical documentation, including written documents and diagrams.
  • Experience developing presentation slide decks and presenting to technical and non-technical personnel.
  • Experience identifying and documenting system and organizational security and privacy requirements, including personal data handling.
  • Familiarity with identifying and protecting enterprise and system-level security data.
  • Ability to collaborate with stakeholders and translate functional needs into technical security requirements.
  • Ability to support cost estimation and technical guidance related to secure system design and changes.
  • Skilled in identifying gaps in security architecture and contributing to the development of security risk management plans.
  • Proficiency in documenting and updating security architecture throughout the system development and acquisition lifecycle.
Responsibilities
  • Develop and align system security architectures with organizational cybersecurity guidelines, including defining security boundaries, documenting system categorization, and analyzing user needs and requirements.
  • Develop focused guidance for specific security mechanisms such as encryption for data at rest
  • Assess and evaluate security postures, reviewing candidate architectures, identifying protection needs, and determining how new systems or interfaces impact enterprise security.
  • Identify and document security and privacy requirements, including types of personal information, stakeholder interests, and data that require protection, ensuring proper allocation at both system and organizational levels.
  • Support acquisition and procurement efforts by providing input on security requirements for statements of work, project costs, and translating proposed capabilities into technical specifications.
  • Contribute to risk management and compliance, performing architecture reviews, identifying security gaps, supporting RMF activities, and maintaining documentation throughout the acquisition lifecycle.
  • Provide high-quality technical, engineering, analytical, and planning support to meet the organization’s requirements.
  • Perform architectural review and analysis, developing strategic enterprise solutions that address the evolving business requirements and changing cybersecurity threat landscape.
  • Develop and deliver reports (e.g., reference architectures, white papers, roadmaps, architecture risk analysis) to facilitate the following, including but not limited to:


    • Define and develop security architecture and engineering standards

    • Develop business use cases and design patterns to articulate the organization’s goals and objectives
    • Document the current “as-is” through a holistic review of the agency enterprise
    • Develop an envisioned target “to-be” based on the agency’s needs and threat models
    • Assess the gaps between “as-is” and “to-be”, and provide roadmaps to close gaps.
    • Develop baselines and reference architectures consistent with standard frameworks
    • Perform Architect Risk Analysis (ARA) through systematic and comprehensive reviews
    • Identify, integrate, mature, and communicate key concepts that define continued direct interaction with the agency’s technical and operational leadership.
    • Identify, frame, and support the resolution of critical issues impacting the organization.
    • Update artifacts periodically to meet regulatory, audit, and compliance requirements.
    Loading...