Security Architect - Aviation

SteerBridge
  • Vienna, Virginia
    30+ days ago

    Job Description

    SteerBridge is a modern technology company delivering innovative, mission‑focused solutions to the U.S. Government and private sector. Leveraging deep expertise in federal acquisition, digital transformation, and emerging technologies, we deliver agile, commercial‑grade capabilities that accelerate operational effectiveness and drive measurable mission success.
    At the core of SteerBridge is our people—especially the veterans whose leadership, problem‑solving mindset, and commitment to excellence elevate every project we support. We don’t simply hire exceptional talent; we cultivate it, creating meaningful career pathways for veterans, military spouses, and professionals who share our passion for advancing technology and strengthening the missions we serve.

    POSITION OVERVIEW

    SteerBridge is seeking a Security Architect to define the security architecture and compliance strategy for a mission-critical Defense Aviation platform running in AWS GovCloud for federal customers. This role owns the security blueprint—controls, identity, zero-trust access, monitoring, and authorization strategy—for environments supporting federal aviation operations.

    The architect will work directly with solutions architects, security and cloud engineers, data teams, and stakeholders to translate DoD security requirements into enforceable, well-architected designs and to guide the platform toward and through authorization (ATO).

    This role stays close to implementation. The ideal candidate sets security standards, designs control frameworks, reviews architectures, and guides engineers in implementing defense-in-depth and zero-trust access.

    This is a hybrid position based in Vienna, VA.

    Key Responsibilities

    Security Architecture and Strategy

    • Define the security architecture for AWS GovCloud workloads spanning identity, zero-trust access, network segmentation, encryption, monitoring, and data protection
    • Design and own the zero-trust access architecture, leveraging Zscaler (ZTNA/SASE) to broker secure access to applications and infrastructure
    • Design defense-in-depth control frameworks aligned to DoD and DISA requirements
    • Produce security architecture documentation, control mappings, and decision records
    • Establish security standards and reference patterns for engineering teams

    Compliance and Authorization

    • Lead security alignment with DoDI 8510, CNSSI 1253, STIGs, DoD CC SRG, and ATO and authorization processes.
    • Define control implementation and evidence strategies for audits and assessments
    • Assess and communicate security risk to technical and non-technical stakeholders
    • Guide POA&M development and remediation prioritization

    Design Governance and Guidance

    • Review architectures and designs to ensure security is embedded from the outset
    • Set standards for least-privilege IAM, zero-trust secure access (Zscaler/ZTNA), and hardened baselines
    • Guide engineers implementing security controls, detection, and response capabilities
    • Lead security and threat-model reviews

    Collaboration and Leadership

    • Partner with cloud and solutions architects to ensure secure-by-design platforms
    • Advise leadership on security strategy, posture, and risk trade-offs
    • Mentor engineers and promote a strong security culture

    Required Qualifications

    • U.S. Citizenship required (for clearance purposes)
    • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering.
    • 10+ years of security experience, including 3+ years in a security architecture or lead role
    • Experience designing zero-trust architectures, ideally with Zscaler or a comparable ZTNA or SASE platform
    • Deep expertise in cloud security architecture (AWS), identity, and network segmentation
    • Strong command of security frameworks including DoDI 8510, CNSSI 1253, STIGs, DoD CC SRG, DISA STIGs
    • Experience guiding systems through ATO and authorization in DoD environments
    • Strong understanding of defense-in-depth, zero-trust principles, and least-privilege design
    • Ability to produce clear security architecture documentation and risk assessments
    • Experience leading security across multidisciplinary teams
    • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
    • Skill in translating operational requirements into protection needs (i.e., security controls).
    • Skill in applying cybersecurity methods, such as firewalls, demilitarized zones, and encryption.
    • Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Ability to apply an organization’s goals and objectives to develop and maintain architecture.
    • One or more of the following:
      • Certified Information Security Manager (CISM)
      • Certified Information Systems Security Professional (CISSP)
      • Cisco Certified Network Professional (CCNP) Enterprise
      • GIAC Certified Intrusion Analyst (GCIA)
      • GIAC Defensible Security Architecture (GDSA)
      • GIAC Global Industrial Cyber Security Professional (GICSP)
      • Information Systems Security Architecture Professional (ISSAP)
      • Information Systems Security Engineering Professional (ISSEP)

    Preferred Qualifications

    • Extensive experience in AWS GovCloud or other federal or regulated environments
    • Masters or PHD in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering.
    • Deep experience architecting Zscaler or comparable ZTNA/SASE solutions and integrating them with identity and conditional access
    • Experience with continuous monitoring, SIEM strategy, and incident response programs
    • Experience with data security and protection of analytics and Medallion platforms
    • Senior certifications such as CCSP; or AWS Security Specialty
    • Experience supporting aviation, defense, logistics, or fleet management systems
    $170,000 - $180,000 a year

    Annually, commensurate with experience and location.

    SteerBridge is proud to be an Equal Opportunity Employer. We are committed to creating a diverse and inclusive workplace where all qualified applicants and employees are treated with respect and dignity—regardless of race, color, gender, age, religion, national origin, ancestry, disability, veteran status, genetic information, sexual orientation, or any other characteristic protected by law.
     
    We also provide reasonable accommodations for individuals with disabilities in accordance with applicable laws. If you require assistance during the application process, we encourage you to reach out so we can support your needs.
    If you would like information about how your application is processed, please contact us.
    If you would like information about how your application is processed, please contact us.

    Numbers & Facts

    LocationVienna, Virginia
    Websitehttps://www.steerbridge.com

    Skills

    • Amazon Web Services (AWS)unmatched
    • Aviation Industryunmatched
    • Blueprintsunmatched
    • CCNP - Cisco Certified Network Professionalunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Data Scienceunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Defense in Depthunmatched
    • Documentationunmatched
    • Embedded Systemsunmatched
    • Emerging Technologyunmatched
    • Establish Prioritiesunmatched
    • Firewallsunmatched
    • Fleet Managementunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Governmentunmatched
    • ISSAP - Information Systems Security Architecture Professionalunmatched
    • ISSEP - Information Systems Security Engineering Professionalunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Logisticsunmatched
    • Militaryunmatched
    • Model Reviewunmatched
    • Operational Supportunmatched
    • Operations Processesunmatched
    • Problem Solving Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Software Engineeringunmatched
    • Technical Deliveryunmatched
    • Threat Modelingunmatched
    • United States Citizenunmatched
    • United States Department of Defense (DoD)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder