| Title: | Cloud Subject Matter Expert / Cloud Security Architect |
|---|---|
| ID: | 10353 |
| Department: | Information Technology |
| Location : | Rockville, MD |
Position Summary
We are seeking an experienced Cloud Subject Matter Expert (SME) and Cloud Security Architect to design, secure, and govern enterprise cloud environments supporting federal government programs. This individual will provide technical leadership across cloud architecture, migration, cybersecurity, compliance, and operations.
The ideal candidate has extensive experience with AWS and/or Microsoft Azure, Zero Trust Architecture, NIST security frameworks, and the federal Authorization to Operate (ATO) process. The role requires close collaboration with cloud engineers, cybersecurity teams, ISSOs, assessors, application owners, and government stakeholders.
Key Responsibilities
Cloud Architecture and Engineering
- Design secure, scalable, highly available, and resilient cloud architectures.
- Develop cloud reference architectures, technical roadmaps, design patterns, and implementation standards.
- Lead cloud migration and modernization initiatives for applications, platforms, databases, and infrastructure.
- Evaluate cloud services and recommend solutions based on security, performance, cost, availability, and mission requirements.
- Design hybrid-cloud and multi-cloud environments using AWS, Microsoft Azure, and on-premises infrastructure.
- Provide technical guidance on Infrastructure as Code, containerization, microservices, serverless computing, and DevSecOps.
- Review architecture diagrams, technical designs, configurations, and implementation plans.
Cloud Security Architecture
- Develop and maintain enterprise cloud security architecture, standards, guardrails, and security patterns.
- Design identity and access management solutions using least privilege, role-based access control, privileged access management, and multifactor authentication.
- Implement Zero Trust principles across identities, devices, applications, networks, workloads, and data.
- Define security requirements for cloud networking, segmentation, encryption, key management, logging, monitoring, vulnerability management, and incident response.
- Review cloud configurations and identify security weaknesses, misconfigurations, and compliance gaps.
- Establish secure cloud landing zones and account or subscription governance.
- Support the deployment and integration of cloud security tools, including CSPM, SIEM, EDR, vulnerability scanning, secrets management, and data-protection technologies.
Federal Compliance and ATO Support
- Ensure cloud environments comply with NIST SP 800-53, NIST Risk Management Framework, FISMA, FedRAMP, agency policies, and applicable federal requirements.
- Support system categorization, control selection, control implementation, assessment, authorization, and continuous monitoring.
- Develop and review System Security Plans, security control implementation statements, architecture diagrams, Plans of Action and Milestones, risk assessments, and supporting evidence.
- Work with ISSOs, assessors, system owners, and Authorizing Official representatives to obtain and maintain ATOs.
- Translate technical cloud configurations into clear, accurate security-control evidence.
- Support remediation of assessment findings, vulnerabilities, and audit observations.
- Assist with continuous-monitoring activities and periodic security-control assessments.
DevSecOps and Automation
- Integrate security controls into CI/CD pipelines and cloud-development workflows.
- Promote automated security testing, policy-as-code, infrastructure scanning, configuration validation, and compliance reporting.
- Establish secure Infrastructure-as-Code practices using tools such as Terraform, AWS CloudFormation, or Azure Bicep.
- Support container and Kubernetes security, including image scanning, runtime protection, access controls, and secrets management.
- Automate cloud governance, monitoring, evidence collection, and remediation processes where practical.
Leadership and Stakeholder Support
- Serve as the principal technical advisor for cloud and cloud-security matters.
- Lead technical discussions, architecture reviews, risk reviews, and security-design sessions.
- Communicate complex technical and cybersecurity topics to technical teams, executives, and government stakeholders.
- Mentor cloud engineers, security engineers, ISSOs, assessors, and other technical personnel.
- Coordinate with application, infrastructure, network, SOC, governance, and enterprise architecture teams.
- Monitor emerging cloud technologies, security threats, vulnerabilities, and federal cybersecurity requirements.
Required Qualifications
- Bachelor’s degree in computer science, cybersecurity, information systems, engineering, or a related discipline.
- Minimum of 10 years of experience in information technology, including at least five years in cloud architecture or cloud security.
- Demonstrated experience designing and securing enterprise AWS and/or Microsoft Azure environments.
- Strong knowledge of cloud-native networking, identity, encryption, logging, monitoring, backup, disaster recovery, and workload protection.
- Hands-on experience with NIST SP 800-53, NIST RMF, FISMA, FedRAMP, ATO processes, and continuous monitoring.
- Experience developing secure cloud landing zones, governance models, and security guardrails.
- Understanding of Zero Trust Architecture and identity-centric security.
- Experience supporting cloud migration, modernization, or enterprise transformation programs.
- Knowledge of DevSecOps, CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and security automation.
- Ability to develop architecture diagrams, technical documentation, security standards, and executive-level presentations.
- Strong analytical, leadership, communication, and stakeholder-management skills.
- Ability to obtain and maintain the security clearance or public-trust designation required by the contract.
Required Certifications
Candidates should possess one or more advanced cloud certifications and one recognized cybersecurity certification.
Cloud certifications:
- AWS Certified Solutions Architect – Professional
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
- Google Professional Cloud Architect or Professional Cloud Security Engineer
Cybersecurity certifications:
- CISSP
- CCSP
- CISM
Preferred Qualifications
- Master’s degree in cybersecurity, information technology, engineering, or a related discipline.
- Experience supporting NIH, HHS, DoD, DHS, or another federal agency.
- Experience with Government cloud environments, including AWS GovCloud and Azure Government.
- Familiarity with FIPS 140-3, DISA STIGs, CIS Benchmarks, OMB cybersecurity guidance, and CISA Zero Trust requirements.
- Experience with ServiceNow GRC, JCAM, CSAM, or similar governance, risk, and compliance platforms.
- Familiarity with Splunk, Microsoft Sentinel, AWS Security Hub, GuardDuty, Defender for Cloud, Prisma Cloud, Wiz, or comparable security platforms.
- Experience presenting technical risks, architectural decisions, and remediation recommendations to senior government stakeholders.
Key Competencies
- Cloud and security architecture
- Federal cybersecurity compliance
- Strategic and systems-level thinking
- Technical leadership
- Risk-based decision-making
- Architecture documentation
- Stakeholder communication
- Troubleshooting and problem-solving
- Mentoring and knowledge transfer
- Collaboration across technical and business teams

