We are seeking an experienced Security Solution Architect to design and implement end-to-end security architecture across applications, infrastructure, and operations. This role requires strong technical depth in DevSecOps and cloud-native environments, coupled with the ability to drive execution, engage stakeholders, and ensure compliance with enterprise and government standards.
Key Responsibilities
- Design comprehensive security architecture blueprints covering DevSecOps, applications, infrastructure, and operational security.
- Define processes, provisioning standards, security interfaces, and provide actionable recommendations.
- Build detailed workplans, lead project execution, and drive cross-functional security teams.
- Execute and manage security vulnerability scanning activities (HCR, NVA, Pen Testing, SAST, DAST), ensuring timely resolution of findings.
- Implement and operationalize security products including HSMs, EDRs, DLP tools, and enterprise antivirus suites.
- Ensure security in container orchestration platforms (OpenShift, CloudFoundation, Kubernetes), covering container hardening, secure images, repository security, and traffic monitoring.
- Secure enterprise Big Data architectures with RBAC, DLP tools, monitoring systems, and data usage prevention controls.
- Oversee operational security processes: OS/app patching, hardening, archival, and housekeeping aligned with IM8 policy.
- Hands-on expertise with tools such as Thales CipherTrust HSM, DigitalGuardian DLP, VMware CarbonBlack, TrendMicro DeepSecurity, Nessus, and Burp Suite Enterprise.
Must-Have Qualifications
- Minimum 5 years experience as a Security Solution Architect.
- Industry certifications: CISSP, CCSP, CCSK or equivalent.
- Specialization in 12 core cyber domains (e.g., IAM, cloud-native security, container orchestration platform security) with broad understanding of others.
Good-to-Have Skills
- Familiarity with government security standards, including SSAT, compliance checks, vulnerability scanning, DAST & SAST.
- Ability to defend and articulate security posture to ACISO and senior stakeholders.
- Experience working with cloud-native security tools and environments.
This is an initial 2-year full time contract role with visibility for a perm conversion.