Cloud Solution Architect

Posted 6 Days Ago
Be an Early Applicant
Slidell, LA, USA
In-Office
Senior level
Other
The Role
Designs and guides deployment of a FedRAMP-authorized cloud environment for a federal grant management portal, dashboards, and knowledge repository. Documents system architecture, authorization boundaries, data flows, and security controls; applies Zero Trust, open-source, containerization, secure CI/CD, interoperability, backup, and disaster recovery principles. Collaborates with ATO/RMF leads and developers, supports federal authorization documentation, reviews implementation, and provides technical inputs for privacy, data security, sustainability, and transition deliverables.
Summary Generated by Built In

The Cloud / Solution Architect designs the technology environment the program runs on and guides its deployment. ACF requires a cloud based MIS with a portal and dashboard for grant recipients to submit performance measures, a centralized knowledge repository, and a hosting environment, FedRAMP authorized at the appropriate impact level or otherwise approved by ACF. The system is categorized FIPS 199 Moderate overall. The architect assesses what ACF already has before proposing anything new, designs the approved environment, documents the architecture in enough detail to support the Authorization to Operate (ATO), and makes sure the build follows ACF's rules on open source, containerization, secure pipelines, and Zero Trust. The architect works most closely with the ATO / Risk Management Framework Lead, who owns the authorization package, and with the CDIT developers who build and operate the platform.

Responsibilities

• Design the cloud environment for the MIS portal, dashboards, and knowledge repository on FedRAMP authorized cloud services at the appropriate impact level, or another ACF approved hosting environment (RFQ Task 6.2), sized for 100,000 to 150,000 adolescents reached per year and for grant recipient performance measure submissions.
• Before any technology selection, engage ACF Tech to evaluate existing ACF enterprise capabilities that meet the need, and write the justification, for COR approval, when an alternative is proposed. Prefer FedRAMP authorized software over software without FedRAMP authorization and over custom development (ACF Tech Section 1.3).
• Document the architecture: system boundary, components, environments, data flows, interconnections, user roles, and the authorization boundary the ATO / RMF Lead will carry into the System Security Plan and the Data Security Plan (RFQ Task 9.4).
• Build security into the design: encryption of data in transit and at rest, multifactor authentication, least privilege and role based access control, audit logging, data quality checks, and the access, security, and activity reports ACF may request (RFQ Task 6.2).
• Design to the Zero Trust pillars of the CISA Zero Trust Maturity Model v2.0 and document the expected maturity level, which ACF Tech requires to be a score of 2.1 or higher before approval (ACF Tech Appendix B).
• Apply ACF's Open Source First approach for operating systems, databases, application servers, and middleware, and prepare the business case, cost benefit analysis, and risk assessment ACF Tech requires if a proprietary product is the better choice (ACF Tech Section 1.5.2).
• Containerize the solution from the start using Docker, Kubernetes, or OpenShift, with image scanning before deployment and documented container security configuration (ACF Tech Section 1.6).
• Define the secure CI/CD pipeline: static and dynamic code analysis, vulnerability scanning of code and dependencies, infrastructure as code, and automated accessibility testing (ACF Tech Section 1.4.1).
• Design for interoperability with ACF enterprise systems, identity and access management, and the identity, authentication, and federation assurance levels the electronic authentication risk assessment produces (RFQ Section 4.0).
• Design backup, disaster recovery, and the technical basis of the Contingency Plan, and support the annual contingency test.
• Guide deployment, review the development team's implementation against the design, and support the continuous incorporation of prioritized enhancements to the MIS (RFQ Task 6.1).
• Follow the ACF Solution Delivery Lifecycle, NIST SP 800-160 Volumes 1 and 2, NIST SP 800-64, and the HHS secure coding policy, and produce the system documentation the ACF Tech Governance Framework requires at each interval and at contract expiration (ACF Tech Section 1.1).
• Review Government repositories such as Code.gov for reusable code before new development and provide the attestation ACF requires (ACF Tech Section 1.5.3).
• Provide the technical content for the Data Security Plan, the Privacy Impact Assessment support package, the Data Inventory and Data Minimization Plan (RFQ Task 6.3), and, if AI is used, the AI Compliance and Risk Management Plan (RFQ Task 11).
• Provide the technical inputs to the Sustainability and Transition strategy (RFQ Task 8) so the environment can be sustained, transitioned, or absorbed into ACF's future operating model.

Required qualifications

• Bachelor's degree.
• At least 7 years designing and delivering cloud hosted solutions, including at least 3 years as the lead architect for a system in production.
• FedRAMP cloud architecture on AWS GovCloud, Microsoft Azure Government, or an equivalent authorized environment, including the shared responsibility model and control inheritance.
• Containerization and orchestration with Docker and Kubernetes or OpenShift, and infrastructure as code with a tool such as Terraform.
• Secure design: encryption, identity and access management, multifactor authentication, role based access, logging, and network segmentation.
• Integration and interoperability: REST APIs, data exchange, and identity federation.
• Open source platforms such as Linux, PostgreSQL, NGINX or Tomcat, and message brokers such as Kafka or RabbitMQ.
• Ability to write architecture documentation that a security assessor and a Government reviewer can follow.
• Public Trust Tier 2 clearance, held or obtainable.

Desired qualifications (CDIT additions, not conditions of the subcontract)

• AWS Certified Solutions Architect Professional, Microsoft Certified Azure Solutions Architect Expert, or equivalent.
• CISSP, CCSP, or another recognized security certification.
• Prior architecture work on a system that achieved a federal ATO, preferably at HHS or an HHS operating division.
• Experience designing to the CISA Zero Trust Maturity Model and producing Zero Trust scorecards.
• Experience with performance measurement, grant management, or data collection portals serving a national program.

Deliverables this position owns or supports

• Architecture documentation and the authorization boundary description used in the System Security Plan.
• Technical content of the Data Security Plan and the Privacy Impact Assessment support package (draft due 30 days after award, Task 9.4).
• Enterprise capability assessment and any alternative solution justification for ACF Tech.
• Zero Trust implementation approach and maturity documentation.
• System documentation at ACF Tech Governance Framework intervals and at contract expiration.

Skills Required

  • Bachelor's degree
  • At least 7 years designing and delivering cloud-hosted solutions
  • At least 3 years serving as lead architect for a production system
  • FedRAMP cloud architecture experience with AWS GovCloud, Microsoft Azure Government, or an equivalent authorized environment
  • Knowledge of the cloud shared responsibility model and control inheritance
  • Experience with Docker and Kubernetes or OpenShift containerization and orchestration
  • Infrastructure as code experience with Terraform or a similar tool
  • Secure design experience covering encryption, identity and access management, multifactor authentication, role-based access, logging, and network segmentation
  • Integration and interoperability experience with REST APIs, data exchange, and identity federation
  • Experience with open-source platforms including Linux, PostgreSQL, NGINX or Tomcat, and Kafka or RabbitMQ
  • Ability to write architecture documentation for security assessors and government reviewers
  • Public Trust Tier 2 clearance, held or obtainable
  • AWS Certified Solutions Architect Professional, Microsoft Certified Azure Solutions Architect Expert, or equivalent certification
  • CISSP, CCSP, or another recognized security certification
  • Prior architecture work on a system that achieved a federal Authority to Operate, preferably at HHS or an HHS operating division
  • Experience with the CISA Zero Trust Maturity Model and Zero Trust scorecards
  • Experience with performance measurement, grant management, or national data collection portals
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto
115 Employees
Year Founded: 2003

What We Do

CDIT, headquartered in Slidell, LA, has provided technical services for both commercial and Federal customers for the past 18 years. We deliver high-value services with our Agile integrated approach, consisting of Lean-Agile frameworks, process maturity, best practices combined with information security and quality management standards. This integrated approach is paired with the principles of accountability, collaboration, and delivery established our core CDIT execution model. This model allows us to successfully deliver and perform on small to large-scale programs remotely and on-site. CMMI III DEV | ISO 9001:2015 | ISO 27001:2015

Similar Jobs

Ensono Logo Ensono

Architect

Cloud • Information Technology
Easy Apply
Remote or Hybrid
United States
3000 Employees
150K-204K Annually

Microsoft Logo Microsoft

Architect

Software • Quantum Computing • Metaverse • Infrastructure as a Service (IaaS)
In-Office or Remote
2 Locations
206870 Employees
131K-272K Annually

Perficient Logo Perficient

Architect

Information Technology
In-Office or Remote
2 Locations
3295 Employees
82K-150K Annually

Inoapps Logo Inoapps

Architect

Cloud • Software
Remote or Hybrid
United States
342 Employees
5-5 Annually

Similar Companies Hiring

T-Mobile Thumbnail
Other • Utilities
Bellevue, WA
89016 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
OmniCable Thumbnail
Other
West Chester, Pennsylvania
815 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account