cFocus Software seeks a Security Architect to join our program supporting the Federal Communications Commission (FCC). This position is remote
Qualifications
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related fields
- Active Top Secret Clearance
- ISSEP (Information Systems Security Engineering Professional) or CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional)
- GIAC Security Expert (GSE) or Microsoft Certified Cybersecurity Architect Expert
- Minimum 10+ years of experience in cybersecurity with at least 5 years focused on enterprise security architecture and engineering
- Core competencies in enterprise security design, systems engineering, and compliance
- Possess the knowledge, skills, tasks, and capabilities described in the NICE Work Role Framework for Security Architect (SP-ARC-002)
Duties
- Design, implement, and maintain the enterprise cybersecurity architecture supporting FCC SOC operations
- Ensure compliance with FISMA, NIST 800-53, FedRAMP, and Zero Trust Architecture requirements
- Develop and update enterprise security roadmaps, standards, and architecture diagrams
- Conduct security risk assessments, gap analyses, and compliance reviews of FCC systems and applications
- Provide architectural oversight of cloud, hybrid, and on-premise environments (Azure, Microsoft 365, and enterprise IT systems)
- Author and maintain security documentation, policies, and technical standards to support FCC mission objectives
- Collaborate with system owners, SOC leadership, and engineering teams to design secure solutions and validate control implementations
- Support Authorization to Operate (ATO) processes by aligning system architecture with risk management framework (RMF) requirements
- Integrate security requirements into system development lifecycles (SDLC) and modernization initiatives
- Provide senior-level guidance and mentorship to SOC engineers, analysts, and development teams on secure design practices
- Align security architecture with Zero Trust principles, Defense-in-Depth strategies, and federal modernization initiatives
- Review and validate system changes, new technologies, and integration projects to ensure security-by-design
- Provide technical input during incident response and remediation planning, ensuring architecture resilience against evolving threats