The Enterprise Security Architect III will design, develop, and maintain security architecture and application components supporting an assigned ICAM workstream. The role combines enterprise security architecture with practical delivery responsibilities, including integration of security controls, security assessment support, Authorization to Operate activities, vulnerability remediation, POA&M management, and participation in application development, integration, and testing.
This position is best suited to a hands-on security architect who can work directly with software engineers, testers, DevSecOps personnel, system owners, and federal security stakeholders. It is not a governance-only or policy-only architecture role.
Key Responsibilities:
Design and maintain enterprise security architecture for assigned ICAM applications and services.
Translate DHS asecurity requirements into implementable architecture and technical controls.
Contribute to or oversee secure application and configuration development.
Integrate security controls into application, infrastructure, cloud, and DevSecOps environments.
Lead or support system security assessments and technical control validation.
Develop, update, or support documentation required for Authorization to Operate activities.
Identify and remediate vulnerabilities within DHS-required timeframes.
Develop and manage remediation actions and POA&M items when findings cannot be immediately resolved.
Work with development and testing teams to ensure security requirements are incorporated throughout the SDLC.
Support development, integration, testing, and release activities within the assigned workstream.
Review technical designs, code, configurations, security scan results, and implementation evidence.
Help ensure medium- and high-severity static and dynamic application vulnerabilities are resolved before production release.
Support incident investigation, root-cause analysis, and corrective action when security issues affect production systems.
Maintain architecture, security, assessment, and remediation documentation.
Required Qualifications:
Experience designing or maintaining enterprise application or system security architecture.
Experience integrating cybersecurity controls into software, cloud, infrastructure, or DevSecOps environments.
Experience supporting security assessments or authorization activities.
Experience identifying, documenting, and remediating technical vulnerabilities.
Experience developing or managing POA&M remediation actions.
Ability to work with software engineering and testing teams throughout the SDLC.
Ability to interpret security requirements and translate them into technical controls.
Ability to obtain and maintain favorable DHS EOD, suitability, and required system access.
Preferred Qualifications:
Prior DHS or federal civilian agency clearance or experience.
Experience supporting federal ATO packages or NIST Risk Management Framework activities.
Experience with ICAM, IAM, PIV, PKI, PAM, SSO, OAuth, OIDC, or access-control systems.
Experience with AWS, Azure, hybrid-cloud, or on-premises federal environments.
Experience with secure CI/CD pipelines and automated security gates.
Experience with SonarQube, Jenkins, GitHub Enterprise, Splunk, container security, STIGs, or hardened images.
CISSP, CSSLP, CCSP, AWS/Azure security certification, or comparable security credential.
Skills Required
- Experience designing or maintaining enterprise application or system security architecture.
- Experience integrating cybersecurity controls into software, cloud, infrastructure, or DevSecOps environments.
- Experience supporting security assessments or authorization activities.
- Experience identifying, documenting, and remediating technical vulnerabilities.
- Experience developing or managing POA&M remediation actions.
- Ability to work with software engineering and testing teams throughout the SDLC.
- Ability to interpret security requirements and translate them into technical controls.
- Ability to obtain and maintain favorable DHS EOD, suitability, and required system access.
- Prior DHS or federal civilian agency clearance or experience.
- Experience supporting federal ATO packages or NIST Risk Management Framework activities.
- Experience with ICAM, IAM, PIV, PKI, PAM, SSO, OAuth, OIDC, or access-control systems.
- Experience with AWS, Azure, hybrid-cloud, or on-premises federal environments.
- Experience with secure CI/CD pipelines and automated security gates.
- Experience with SonarQube, Jenkins, GitHub Enterprise, Splunk, container security, STIGs, or hardened images.
- CISSP, CSSLP, CCSP, AWS/Azure security certification, or comparable security credential.
What We Do
Makpar provides high level strategic and project management services based on over 10 years of experience in customer focused, cutting edge technology in product development, big data and analytics. With a principal office in Loudon County, Virginia, we have access to the best and the brightest people in the industry who have a passion for helping our clients. Our highly experienced consultants will work on your most pressing challenges day in and day out and will deliver results that will delight you. We value integrity, honesty, and open communications in all our dealings. We continually strive to improve ourselves through soliciting feedback and evaluating our results against the best in the industry.








