Senior Cyber Tools Architect/Engineer

Posted Yesterday
Be an Early Applicant
Quantico, VA, USA
In-Office
190K-220K Annually
Senior level
Information Technology • Professional Services • Cybersecurity • Defense
The Role
Serves as the technical authority for enterprise cybersecurity architecture, tools, and platforms across hybrid and multi-cloud environments. Leads security tool selection, integration, optimization, governance, architecture design, risk management, compliance, ATO support, lifecycle modernization, and incident-response architecture. Establishes security standards and metrics, evaluates emerging technologies, mentors technical staff, and communicates recommendations to leadership. Requires extensive cybersecurity architecture and engineering experience, federal compliance expertise, advanced security tooling knowledge, scripting and automation skills, and an active Top Secret clearance.
Summary Generated by Built In

Location: Quantico, VA. Hybrid 2 days onsite.
Security Clearance: Active TS or higher [Required]
Job Type: Full-Time
Target Salary Range*: $190,000 - $220,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview

Amatriot is hiring a Senior Cyber Tools Architect/Engineer to support the Defense Counterintelligence Security Agency (DCSA) program in Quantico, VA 22134, USA.

This role serves as the technical authority for cybersecurity tools, platforms, and frameworks, leading enterprise security architecture and tooling initiatives that protect critical assets, data, and systems across hybrid and multi-cloud environments.

The architect/engineer selects, integrates, and optimizes security technologies; designs incident response and threat analysis architectures; ensures regulatory compliance; and oversees security systems from acquisition through modernization. The role partners with Application, Data, Infrastructure, and Security Operations teams to develop scalable, resilient security solutions aligned with business objectives.

Key ResponsibilitiesTool Integration and Platform Management
  • Lead the selection, evaluation, testing, and integration of enterprise security software, SIEM/SOAR platforms, firewalls, endpoint defenses, and other cybersecurity tools.

  • Design integration strategies that support interoperability between security tools and enterprise systems.

  • Architect data flows and correlation rules to support threat detection and response.

  • Develop and maintain security tool roadmaps aligned with organizational strategy and emerging threats.

  • Optimize tool configurations for effectiveness, performance, and cost efficiency.

  • Establish and enforce tool governance, change management, and configuration standards.

Security Frameworks and Architecture
  • Develop security strategies for hybrid environments that maintain a consistent security posture across platforms.

  • Create reference architectures and design patterns for secure application deployment, data protection, and infrastructure hardening.

  • Develop security architecture blueprints for cloud-native applications, IoT, and edge computing.

  • Design resilient architectures that support business continuity, disaster recovery, and high availability.

  • Establish architecture principles, standards, and guidelines aligned with industry best practices and organizational objectives.

Risk Management and Compliance
  • Align security architectures with NIST RMF, FISMA, FedRAMP, CMMC, ISO 27001, and DoD STIGs.

  • Develop and maintain a Security Risk Management Plan supporting program and mission objectives.

  • Conduct security assessments, architecture reviews, and audits to identify vulnerabilities, gaps, and compliance deficiencies.

  • Lead threat modeling, vulnerability analysis, and impact assessments.

  • Implement remediation plans and compensating controls.

  • Prepare security authorization packages and support Authority to Operate (ATO) processes.

  • Report security posture, risk metrics, and compliance status to senior leadership.

Security System Lifecycle Management
  • Oversee security architecture throughout acquisition, design, development, deployment, operations, and modernization.

  • Develop security requirements and evaluation criteria for technology acquisitions and vendor selection.

  • Plan and execute tool upgrades, migrations, and modernization with minimal operational impact.

  • Establish procedures for secure data disposal and system retirement.

  • Manage technical debt and develop strategies to enhance or replace legacy systems.

Policy, Standards, and Governance
  • Establish, document, and oversee security policies, standards, procedures, and guidelines.

  • Develop architecture standards for cloud adoption, application development, data protection, and infrastructure deployment.

  • Maintain security baselines and hardening guides for operating systems, databases, applications, and network devices.

  • Define security metrics, key performance indicators (KPIs), and key risk indicators (KRIs).

  • Establish governance processes for design reviews, exception management, and variance tracking.

  • Align security policies with federal regulations, industry frameworks, and organizational risk tolerance.

Technical Leadership and Innovation
  • Serve as the subject matter expert and technical authority for cybersecurity architecture and security tools.

  • Resolve complex security tool integration and operational issues.

  • Lead proof-of-concept initiatives to evaluate emerging technologies and solutions.

  • Analyze emerging threats, attack vectors, and security trends to inform architecture decisions.

  • Drive improvements in security posture, operational efficiency, and cost optimization.

  • Present security architectures and recommendations to senior leadership, technical teams, and business stakeholders.

Training and Enablement
  • Develop and deliver training on security architecture, tools, and best practices.

  • Mentor junior architects, engineers, and analysts, providing technical and career development guidance.

  • Lead knowledge transfer during tool implementations and architecture transitions.

  • Maintain current knowledge of security technologies, threats, compliance requirements, and industry best practices.

QualificationsEducation
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems Management, or a related field. An equivalent combination of military service and/or at least ten (10) years of significant, relevant work experience may be considered in lieu of the degree requirement. [Required]

Experience
  • Minimum of 10 years of progressive cybersecurity architecture and engineering experience, including at least 5 years of hands-on experience designing and implementing enterprise security tools and platforms in large-scale, complex environments. [Required]

Skills
  • Deep expertise in enterprise security architecture frameworks, including SABSA, TOGAF, and Zachman. [Required]

  • Proven experience designing and implementing cybersecurity architectures and principles. [Required]

  • Advanced knowledge of defense-in-depth strategies and layered security controls. [Required]

  • Experience with on-premises and cloud security architectures. [Required]

  • Expertise in secure network architecture, segmentation, and micro-segmentation. [Required]

  • Extensive experience with enterprise SIEM solutions, such as Splunk, IBM QRadar, Microsoft Sentinel, and LogRhythm, and SOAR platforms, including Palo Alto Cortex XSOAR, Splunk Phantom, and IBM Resilient. [Required]

  • Deep knowledge of EDR/XDR solutions, including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, and Carbon Black. [Required]

  • Advanced experience with next-generation firewalls, including Palo Alto, Fortinet, and Cisco Firepower; IDS/IPS; web application firewalls (WAF); and network access control (NAC). [Required]

  • Expertise with vulnerability scanning and management platforms, including Tenable, Qualys, and Rapid7. [Required]

  • Experience with cloud-native security tools, including AWS Security Hub, Azure Security Center, and GCP Security Command Center, and CASB solutions. [Required]

  • Strong understanding of IAM platforms, PAM solutions, and identity governance. [Required]

  • Comprehensive understanding of NIST CSF, NIST RMF, NIST 800-53, FISMA, FedRAMP, CMMC, DFARS, ISO 27001/27002, and DoD STIGs. [Required]

  • Experience with security assessment and authorization (SA&A) processes and ATO procedures. [Required]

  • Strong knowledge of risk assessment methodologies and tools. [Required]

  • Proficiency in scripting and automation using Python, PowerShell, and Bash. [Required]

  • Experience with Infrastructure as Code (IaC) and security automation using Terraform, Ansible, and CloudFormation. [Required]

  • Strong understanding of DevSecOps principles and CI/CD security integration. [Required]

  • Knowledge of Docker and Kubernetes security. [Required]

  • Experience with API security and microservices architectures. [Required]

  • Ability to communicate complex technical architectures, security concepts, and risk assessments to diverse audiences, including senior leadership, verbally and in writing. [Required]

Certifications
  • Meet 8570 IASAE III certification requirements at the time of hire, such as CISSP-ISSAP or CISSP-ISSEP. [Required]

Clearance
  • Active Top-Secret clearance, with eligibility to be upgraded to TS/SCI. [Required]

Working Conditions
  • Primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base, VA. [Required]

  • The source also specifies that this is primarily a Telework position with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base, VA. [Required]

  • If the alternate worksite is outside DCSA facilities or corporate office space, reliable voice communication capability and a stable, capable internet connection are required. [Required]

  • May require occasional travel to other DCSA locations, vendor sites, or training, estimated at <10%.

  • Ability to work flexible hours as needed for critical security incidents, maintenance windows, and emergency response activities. [Required]

  • Ability to participate in an on-call rotation for critical security architecture support. [Required]

Preferred Qualifications
  • Master’s degree.

  • Experience in DoD or Federal Government environments.

  • Previous support of DCSA, DoD, or Intelligence Community programs.

  • Advanced knowledge of DoD cybersecurity requirements, RMF processes, and authorization procedures.

  • Experience with the Continuous Diagnostics and Mitigation (CDM) program and tools.

  • Background in penetration testing, red team operations, or offensive security.

  • Experience with SOAR development.

  • Familiarity with threat intelligence platforms and frameworks, including MITRE ATT&CK and STIX/TAXII.

  • Experience with data loss prevention (DLP) and insider threat detection solutions.

  • Knowledge of software-defined networking (SDN) and network function virtualization (NFV) security.

  • Previous experience in a leadership, principal architect, or chief architect role.

  • Published research, white papers, or presentations on cybersecurity architecture.

  • Active participation in cybersecurity professional organizations and communities.

  • Cell phone preferred for voice communication at an alternate worksite.

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems Management, or a related field, or equivalent military service and at least 10 years of relevant experience.
  • At least 10 years of progressive cybersecurity architecture and engineering experience.
  • At least 5 years of hands-on experience designing and implementing enterprise security tools and platforms in complex environments.
  • Expertise in SABSA, TOGAF, and Zachman security architecture frameworks.
  • Experience designing and implementing cybersecurity architectures, defense-in-depth strategies, and layered security controls.
  • Experience with on-premises and cloud security architectures.
  • Expertise in network architecture, segmentation, and micro-segmentation.
  • Experience with enterprise SIEM and SOAR platforms, including Splunk, IBM QRadar, Microsoft Sentinel, LogRhythm, Palo Alto Cortex XSOAR, Splunk Phantom, and IBM Resilient.
  • Knowledge of EDR/XDR solutions, including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, and Carbon Black.
  • Experience with next-generation firewalls, IDS/IPS, WAF, and NAC, including Palo Alto, Fortinet, and Cisco Firepower.
  • Experience with Tenable, Qualys, and Rapid7 vulnerability management platforms.
  • Experience with AWS Security Hub, Azure Security Center, GCP Security Command Center, and CASB solutions.
  • Strong understanding of IAM, PAM, and identity governance platforms.
  • Knowledge of NIST CSF, NIST RMF, NIST 800-53, FISMA, FedRAMP, CMMC, DFARS, ISO 27001/27002, and DoD STIGs.
  • Experience with security assessment and authorization processes and ATO procedures.
  • Knowledge of risk assessment methodologies and tools.
  • Proficiency with Python, PowerShell, and Bash scripting and automation.
  • Experience with Terraform, Ansible, and CloudFormation for Infrastructure as Code and security automation.
  • Strong understanding of DevSecOps and CI/CD security integration.
  • Knowledge of Docker and Kubernetes security.
  • Experience with API security and microservices architectures.
  • Ability to communicate complex security architectures and risk assessments to technical and executive audiences.
  • Meet DoD 8570 IASAE III certification requirements, such as CISSP-ISSAP or CISSP-ISSEP.
  • Active Top Secret clearance with eligibility for upgrade to TS/SCI.
  • Bachelor's or master's degree, with a master's preferred.
  • Experience in DoD or federal government environments.
  • Experience supporting DCSA, DoD, or Intelligence Community programs.
  • Advanced knowledge of DoD cybersecurity requirements, RMF processes, and authorization procedures.
  • Experience with the Continuous Diagnostics and Mitigation program and tools.
  • Background in penetration testing, red team operations, or offensive security.
  • Experience with SOAR development.
  • Familiarity with MITRE ATT&CK and STIX/TAXII.
  • Experience with DLP and insider threat detection solutions.
  • Knowledge of SDN and NFV security.
  • Previous leadership, principal architect, or chief architect experience.
  • Willingness to work onsite at Quantico at least two days weekly, work flexible hours, and participate in an on-call rotation.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Vienna, VA
200 Employees
Year Founded: 2011

What We Do

The Amatriot Group is a talent solutions firm providing technology expertise to the federal and commercial sectors. With over a decade of experience delivering mission-critical support to the intelligence, defense, and national security sectors, the company specializes in delivering cutting-edge technology solutions by securing top-tier talent to bridge workforce gaps in the most complex and secure environments.

Similar Jobs

Wipfli Logo Wipfli

Manager, Financial Reporting - Nonprofit Clients

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-145K Annually

Wipfli Logo Wipfli

Manager, Accounting Advisory Services - Nonprofit Industry Clients

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-160K Annually

Wipfli Logo Wipfli

Senior Manager, Accounting Advisory - Nonprofit Industry Clients

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-195K Annually

Wipfli Logo Wipfli

Product Owner

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
117K-158K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
Los Angeles, California
38 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account