Amatriot logo

Senior Cyber Tools Architect/Engineer

Salary
$190K–$220K
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Location: Quantico, VA. Hybrid 2 days onsite.
Security Clearance: Active TS or higher [Required]
Job Type: Full-Time

Target Salary Range*: $190,000 - $220,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary


Position Overview

Amatriot is hiring a Senior Cyber Tools Architect/Engineer to support the Defense Counterintelligence Security Agency (DCSA) program in Quantico, VA 22134, USA.

This role serves as the technical authority for cybersecurity tools, platforms, and frameworks, leading enterprise security architecture and tooling initiatives that protect critical assets, data, and systems across hybrid and multi-cloud environments.

The architect/engineer selects, integrates, and optimizes security technologies; designs incident response and threat analysis architectures; ensures regulatory compliance; and oversees security systems from acquisition through modernization. The role partners with Application, Data, Infrastructure, and Security Operations teams to develop scalable, resilient security solutions aligned with business objectives.


Key Responsibilities

Tool Integration and Platform Management

  • Lead the selection, evaluation, testing, and integration of enterprise security software, SIEM/SOAR platforms, firewalls, endpoint defenses, and other cybersecurity tools.

  • Design integration strategies that support interoperability between security tools and enterprise systems.

  • Architect data flows and correlation rules to support threat detection and response.

  • Develop and maintain security tool roadmaps aligned with organizational strategy and emerging threats.

  • Optimize tool configurations for effectiveness, performance, and cost efficiency.

  • Establish and enforce tool governance, change management, and configuration standards.

Security Frameworks and Architecture

  • Develop security strategies for hybrid environments that maintain a consistent security posture across platforms.

  • Create reference architectures and design patterns for secure application deployment, data protection, and infrastructure hardening.

  • Develop security architecture blueprints for cloud-native applications, IoT, and edge computing.

  • Design resilient architectures that support business continuity, disaster recovery, and high availability.

  • Establish architecture principles, standards, and guidelines aligned with industry best practices and organizational objectives.

Risk Management and Compliance

  • Align security architectures with NIST RMF, FISMA, FedRAMP, CMMC, ISO 27001, and DoD STIGs.

  • Develop and maintain a Security Risk Management Plan supporting program and mission objectives.

  • Conduct security assessments, architecture reviews, and audits to identify vulnerabilities, gaps, and compliance deficiencies.

  • Lead threat modeling, vulnerability analysis, and impact assessments.

  • Implement remediation plans and compensating controls.

  • Prepare security authorization packages and support Authority to Operate (ATO) processes.

  • Report security posture, risk metrics, and compliance status to senior leadership.

Security System Lifecycle Management

  • Oversee security architecture throughout acquisition, design, development, deployment, operations, and modernization.

  • Develop security requirements and evaluation criteria for technology acquisitions and vendor selection.

  • Plan and execute tool upgrades, migrations, and modernization with minimal operational impact.

  • Establish procedures for secure data disposal and system retirement.

  • Manage technical debt and develop strategies to enhance or replace legacy systems.

Policy, Standards, and Governance

  • Establish, document, and oversee security policies, standards, procedures, and guidelines.

  • Develop architecture standards for cloud adoption, application development, data protection, and infrastructure deployment.

  • Maintain security baselines and hardening guides for operating systems, databases, applications, and network devices.

  • Define security metrics, key performance indicators (KPIs), and key risk indicators (KRIs).

  • Establish governance processes for design reviews, exception management, and variance tracking.

  • Align security policies with federal regulations, industry frameworks, and organizational risk tolerance.

Technical Leadership and Innovation

  • Serve as the subject matter expert and technical authority for cybersecurity architecture and security tools.

  • Resolve complex security tool integration and operational issues.

  • Lead proof-of-concept initiatives to evaluate emerging technologies and solutions.

  • Analyze emerging threats, attack vectors, and security trends to inform architecture decisions.

  • Drive improvements in security posture, operational efficiency, and cost optimization.

  • Present security architectures and recommendations to senior leadership, technical teams, and business stakeholders.

Training and Enablement

  • Develop and deliver training on security architecture, tools, and best practices.

  • Mentor junior architects, engineers, and analysts, providing technical and career development guidance.

  • Lead knowledge transfer during tool implementations and architecture transitions.

  • Maintain current knowledge of security technologies, threats, compliance requirements, and industry best practices.


Qualifications

Education

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems Management, or a related field. An equivalent combination of military service and/or at least ten (10) years of significant, relevant work experience may be considered in lieu of the degree requirement. [Required]

Experience

  • Minimum of 10 years of progressive cybersecurity architecture and engineering experience, including at least 5 years of hands-on experience designing and implementing enterprise security tools and platforms in large-scale, complex environments. [Required]

Skills

  • Deep expertise in enterprise security architecture frameworks, including SABSA, TOGAF, and Zachman. [Required]

  • Proven experience designing and implementing cybersecurity architectures and principles. [Required]

  • Advanced knowledge of defense-in-depth strategies and layered security controls. [Required]

  • Experience with on-premises and cloud security architectures. [Required]

  • Expertise in secure network architecture, segmentation, and micro-segmentation. [Required]

  • Extensive experience with enterprise SIEM solutions, such as Splunk, IBM QRadar, Microsoft Sentinel, and LogRhythm, and SOAR platforms, including Palo Alto Cortex XSOAR, Splunk Phantom, and IBM Resilient. [Required]

  • Deep knowledge of EDR/XDR solutions, including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, and Carbon Black. [Required]

  • Advanced experience with next-generation firewalls, including Palo Alto, Fortinet, and Cisco Firepower; IDS/IPS; web application firewalls (WAF); and network access control (NAC). [Required]

  • Expertise with vulnerability scanning and management platforms, including Tenable, Qualys, and Rapid7. [Required]

  • Experience with cloud-native security tools, including AWS Security Hub, Azure Security Center, and GCP Security Command Center, and CASB solutions. [Required]

  • Strong understanding of IAM platforms, PAM solutions, and identity governance. [Required]

  • Comprehensive understanding of NIST CSF, NIST RMF, NIST 800-53, FISMA, FedRAMP, CMMC, DFARS, ISO 27001/27002, and DoD STIGs. [Required]

  • Experience with security assessment and authorization (SA&A) processes and ATO procedures. [Required]

  • Strong knowledge of risk assessment methodologies and tools. [Required]

  • Proficiency in scripting and automation using Python, PowerShell, and Bash. [Required]

  • Experience with Infrastructure as Code (IaC) and security automation using Terraform, Ansible, and CloudFormation. [Required]

  • Strong understanding of DevSecOps principles and CI/CD security integration. [Required]

  • Knowledge of Docker and Kubernetes security. [Required]

  • Experience with API security and microservices architectures. [Required]

  • Ability to communicate complex technical architectures, security concepts, and risk assessments to diverse audiences, including senior leadership, verbally and in writing. [Required]

Certifications

  • Meet 8570 IASAE III certification requirements at the time of hire, such as CISSP-ISSAP or CISSP-ISSEP. [Required]

Clearance

  • Active Top-Secret clearance, with eligibility to be upgraded to TS/SCI. [Required]

Working Conditions

  • Primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base, VA. [Required]

  • The source also specifies that this is primarily a Telework position with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base, VA. [Required]

  • If the alternate worksite is outside DCSA facilities or corporate office space, reliable voice communication capability and a stable, capable internet connection are required. [Required]

  • May require occasional travel to other DCSA locations, vendor sites, or training, estimated at <10%.

  • Ability to work flexible hours as needed for critical security incidents, maintenance windows, and emergency response activities. [Required]

  • Ability to participate in an on-call rotation for critical security architecture support. [Required]


Preferred Qualifications

  • Master’s degree.

  • Experience in DoD or Federal Government environments.

  • Previous support of DCSA, DoD, or Intelligence Community programs.

  • Advanced knowledge of DoD cybersecurity requirements, RMF processes, and authorization procedures.

  • Experience with the Continuous Diagnostics and Mitigation (CDM) program and tools.

  • Background in penetration testing, red team operations, or offensive security.

  • Experience with SOAR development.

  • Familiarity with threat intelligence platforms and frameworks, including MITRE ATT&CK and STIX/TAXII.

  • Experience with data loss prevention (DLP) and insider threat detection solutions.

  • Knowledge of software-defined networking (SDN) and network function virtualization (NFV) security.

  • Previous experience in a leadership, principal architect, or chief architect role.

  • Published research, white papers, or presentations on cybersecurity architecture.

  • Active participation in cybersecurity professional organizations and communities.

  • Cell phone preferred for voice communication at an alternate worksite.

Similar jobs

Apply for this job