安全架构负责人
Lead Security Architect
我们是谁:
ShorePoint 是一家快速发展的、在行业内获得认可并屡获殊荣的网络安全服务公司,专注于高知名度、高威胁的公共和私营部门客户,这些客户要求具备丰富经验和经过验证的安全模型来保护他们的数据。我们秉持“努力工作,尽情享受”的理念,庆祝个人和公司的成功。我们对我们的使命充满热情,致力于超越预期为客户提供服务,同时营造一个支持创造力、责任感、任务成功、批判性思维以及回馈社区的环境。
福利待遇:
作为网络安全精英的一员,我们携手合作,保护国家关键基础设施,同时在一个注重个人技术和职业成长的文化中,打造有意义且令人兴奋的职业发展机会。我们坚信,当团队成员感到快乐并受到良好照顾时,他们才能发挥最佳水平。为了践行这一理念,我们提供全面的福利包,包括主要医疗保险公司。突出的福利包括 144 小时带薪休假、11 天节假日、85% 的保险费用报销、401(k) 计划、继续教育、认证维护及报销等。
我们寻找的人:
我们正在寻找一位高级安全架构师,他应具备在设计稳健的企业级安全框架方面的深厚技术能力。你将担任战略愿景制定者和技术核心,确保我们的关键任务系统在设计上具有内在安全性,并与不断演进的联邦防御标准保持一致。在此职位中,高级安全架构师将弥合复杂工程需求与高管风险管理之间的差距,推动向强大零信任环境的转型。这是在网络安全市场中一家充满活力且快速发展的公司中塑造其增长、发展和文化的一次独特机会。
你的职责:
- 领导企业安全架构的设计和评估,确保所有系统符合零信任架构(ZTA)原则和组织的网络安全指南。
- 作为企业架构师和系统安全工程师之间的主要技术联络人,确保安全控制措施被正确分配和实施。
- 将复杂的运营需求和利益相关者的安全需求转化为详细的技术需求和功能规范。
查看英文原文
Who we are:
ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.
Who we’re looking for:
We are seeking a Lead Security Architect who possesses deep technical mastery in designing resilient, enterprise-grade security frameworks. You will serve as the strategic visionary and technical anchor, ensuring our mission-critical systems are inherently secure by design and aligned with evolving federal defense standards. In this role, the Lead Security Architect will bridge the gap between complex engineering requirements and executive risk management orchestrating the transition to a robust Zero Trust environment. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you’ll be doing:
- Lead the design and evaluation of enterprise security architectures, ensuring all systems align with Zero Trust Architecture (ZTA) principles and organizational cybersecurity guidelines.
- Serve as the primary technical liaison between enterprise architects and systems security engineers to ensure security controls are correctly allocated and implemented.
- Convert complex operational needs and stakeholder security interests into detailed technical requirements and functional specifications.
- Provide critical input to the Risk Management Framework (RMF) process, including the development of system life-cycle support plans and operational procedures.
- Manage security requirements throughout the acquisition life cycle, from drafting statements of work to evaluating vendor-proposed security designs for adequacy.
- Perform regular security reviews and design modeling to identify architecture gaps, developing comprehensive risk management plans to address vulnerabilities.
- Categorize systems and define clear security boundaries, documenting the protection needs for information systems and networks.
- Advise senior leadership and authorized officials on design concepts, project costs and the potential adverse effects of identified vulnerabilities.
What you need to know:
- Deep proficiency in describing and documenting IT architectures using frameworks such as TOGAF, DoDAF or FEAF, with a focus on integrating security into the full system development life cycle.
- Mastery of Zero Trust Architecture (ZTA) principles, including identity management (PKI, Oauth, SAML), micro-segmentation and secure cloud/hybrid IT delivery models like DevOps and Agile.
- Comprehensive knowledge of NIST 800-series, FedRAMP and the Risk Management Framework (RMF) to ensure systems meet stringent federal and defense cybersecurity standards.
- Technical expertise in network security (TCP/IP, VPNs, firewalls), encryption algorithms and the ability to design countermeasures against complex cyber threats and vulnerabilities.
- Ability to translate operational requirements into technical protection needs and effectively communicate risk and design concepts to both technical experts and executive stakeholders.
Must have’s:
- 10+ years of professional experience in cybersecurity, including 5+ years in security architecture or a senior technical role
- One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC Security Enterprise Architect (GSEA) or GIAC Defensible Security Architecture (GDSA).
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Demonstrated experience architecting secure enterprise systems using Zero Trust Architecture (ZTA) principles.
- Applicants must be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Beneficial to have:
· Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related field.
Where it’s done:
· Remote (Herndon, VA).
Originally posted on Himalayas