Cloud Security Architect, Lead

The Challenge:

Everyone knows security needs to be “baked in” to a system architecture, but you actually know how to bake it in. You can identify and implement Cybersecurity solutions to protect the confidentiality, integrity, and availability of systems in leading commercial Clouds like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). What if you could use your Cyber engineering skills to design and build Cybersecurity solutions in the Cloud to protect personal, financial, health, and other sensitive information for government agencies and global enterprises? We’re looking for an experienced architect who can create advanced Cybersecurity solutions in the Cloud that will stand up to even the most advanced Cyber threats.

As a lead Cloud security architect at Booz Allen, you’ll research, design, and implement Cybersecurity solutions to protect our client's most sensitive information in AWS, Azure, and GCP. You’ll coordinate with investment teams, executives, clients, and industry leading vendors to identify the right mix of tools and techniques to translate your customer’s goals into a plan that will enable secure and effective Cloud hosted solutions. We need to come up with the best solution, so you’ll investigate new techniques, break free from the legacy model, and go where the industry is going. You’ll lead the team through a critical approach to design, including providing alternatives and customizing solutions while maintaining a balance of security and mission needs. This is a chance to make a difference in the security of our country's financial markets, warfighters, citizen services, and healthcare. Your technical expertise will be vital as you help customers overcome their most difficult challenges by integrating security best practices like SecDevOps, Identity and Access Management, Cencryption, and security analytics. You’ll be able to broaden your skillset into advanced and emerging areas of ybersecurity like zero trust networks, automated incident response, and container security to support dynamic and immutable Cloud infrastructure. Join our team as we deliver innovative Cybersecurity solutions to protect our client's information in the Cloud.

Empower change with us.

Build Your Career:

Rewarding work, fun challenges, and a ton of investment in our people—that’s Booz Allen Cyber. When you join Booz Allen, we’ll help you develop the career you want.

Competitions — From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we’ve got plenty of chances for you to show off your skills.

Paid Research — Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.

Cyber University — CyberU has more than 5000 instructor-led and self-paced Cyber courses, a free online library that you can access from just about anywhere—including your phone—and certification exam prep guides that include practical assessments to prepare you for your exam.

Academic Partnerships — In addition to our tuition reimbursement benefit, we’ve partnered with University of Maryland University College to offer two graduate certificate programs in Cybersecurity—fully funded without a tuition cap.

Maker/Hackerspaces — Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.

You Have:

-8+ years of experience with engineering and administering production IT systems or networks for large commercial enterprises or government agencies

-4+ years of experience with supporting production systems in AWS, Azure, or GCP

-2+ years of experience with leading teams of technical staff in the design, build, and integration of IT solutions

-Experience with network and system security tools in the Cloud, including network firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS), anti-malware, vulnerability scanning, encryption, monitoring, and Identity, Credential, and Access Management (ICAM) and developing technical engineering artifacts, including requirements traceability matrices, network diagrams, bills of materials, data flow diagrams, installation procedures, and operations manuals

-Knowledge of how to apply native Cloud security and monitoring services in the Cloud, including network firewalls, access control lists, encryption, auditing and monitoring, alerting, secrets management, and compliance scanning

-Knowledge of IT Service Management and Cybersecurity processes and concepts, including change management, incident management, problem management, configuration management, threats, vulnerabilities, security operations, encryption, boundary defense, auditing, authentication, and risk management

-Ability to automate the provisioning and configuration of IT environments, including tools such as CloudFormation, Azure Resource Manager (ARM) templates, Puppet, Chef, Ansible, or PowerShell tools

-Ability to obtain a security clearance

-BA or BS degree

-AWS, Microsoft Azure, or Google Cloud Platform Advanced Level Certification, Security+ Certification, and CCSK or CCSP Certification

Nice If You Have:

-Experience with the full software or systems development life cycle, including requirements analysis, design, integration, testing, and implementation

-Experience with working in a network Security Operations Center (SOC) as an engineer or analyst

-Experience with implementing Docker Datacenter

-Experience with software development in one or more of the following languages: .NET, Java, PHP, Perl, Python, or Ruby

-Knowledge of federal IT and Cloud security policies, including FISMA, FedRAMP, NIST 800–53, and DoD Cloud SRG, and applying them to the design and implementation of Cloud solutions to achieve an Authorization to Operate (ATO)

-Possession of excellent oral and written communication skills, including public speaking, prior publications, and speaking engagements in relevant industry or vendor forums

-Secret clearance

-BA or BS degree in a Math, Science, or Engineering field

-CISSP Certification

-ITIL Certification

-AWS Certified Solutions Architect - Professional

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.

Not ready to apply? Join our talent community and sign up for job alerts.