Job Closed

This listing is no longer active.

ShorePoint logo
ShorePoint

ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.

Lead Security Architect

Security EngineerSecurity EngineerOtherRemoteTeam 201-500

Location

United States

Posted

109 days ago

Salary

0

No structured requirement data.

Job Description

Lead Security Architect

ShorePoint

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are seeking a Lead Security Architect who possesses deep technical mastery in designing resilient, enterprise-grade security frameworks. You will serve as the strategic visionary and technical anchor, ensuring our mission-critical systems are inherently secure by design and aligned with evolving federal defense standards. This role will bridge the gap between complex engineering requirements and executive risk management, orchestrating the transition to a robust Zero Trust environment. - Lead the design and evaluation of enterprise security architectures, ensuring all systems align with Zero Trust Architecture (ZTA) principles and organizational cybersecurity guidelines. - Serve as the primary technical liaison between enterprise architects and systems security engineers to ensure security controls are correctly allocated and implemented. - Convert complex operational needs and stakeholder security interests into detailed technical requirements and functional specifications. - Provide critical input to the Risk Management Framework (RMF) process, including the development of system life-cycle support plans and operational procedures. - Manage security requirements throughout the acquisition life cycle, from drafting statements of work to evaluating vendor-proposed security designs for adequacy. - Perform regular security reviews and design modeling to identify architecture gaps, developing comprehensive risk management plans to address vulnerabilities. - Categorize systems and define clear security boundaries, documenting the protection needs for information systems and networks. - Advise senior leadership and authorized officials on design concepts, project costs and the potential adverse effects of identified vulnerabilities. Qualifications - 10+ years of professional experience in cybersecurity, including 5+ years in security architecture or a senior technical role. - One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC Security Enterprise Architect (GSEA) or GIAC Defensible Security Architecture (GDSA). - Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking. - Demonstrated experience architecting secure enterprise systems using Zero Trust Architecture (ZTA) principles. - Applicants must be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements. Requirements - Deep proficiency in describing and documenting IT architectures using frameworks such as TOGAF, DoDAF or FEAF, with a focus on integrating security into the full system development life cycle. - Mastery of Zero Trust Architecture (ZTA) principles, including identity management (PKI, Oauth, SAML), micro-segmentation and secure cloud/hybrid IT delivery models like DevOps and Agile. - Comprehensive knowledge of NIST 800-series, FedRAMP and the Risk Management Framework (RMF) to ensure systems meet stringent federal and defense cybersecurity standards. - Technical expertise in network security (TCP/IP, VPNs, firewalls), encryption algorithms and the ability to design countermeasures against complex cyber threats and vulnerabilities. - Ability to translate operational requirements into technical protection needs and effectively communicate risk and design concepts to both technical experts and executive stakeholders. Benefits - 144 hours of PTO - 11 holidays - 85% of insurance premium covered - 401k - Continued education, certifications maintenance and reimbursement - More benefits available Company Description ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.

Job Requirements

  • 10+ years of professional experience in cybersecurity, including 5+ years in security architecture or a senior technical role.
  • One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC Security Enterprise Architect (GSEA) or GIAC Defensible Security Architecture (GDSA).
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Demonstrated experience architecting secure enterprise systems using Zero Trust Architecture (ZTA) principles.
  • Applicants must be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
  • Deep proficiency in describing and documenting IT architectures using frameworks such as TOGAF, DoDAF or FEAF, with a focus on integrating security into the full system development life cycle.
  • Mastery of Zero Trust Architecture (ZTA) principles, including identity management (PKI, Oauth, SAML), micro-segmentation and secure cloud/hybrid IT delivery models like DevOps and Agile.
  • Comprehensive knowledge of NIST 800-series, FedRAMP and the Risk Management Framework (RMF) to ensure systems meet stringent federal and defense cybersecurity standards.
  • Technical expertise in network security (TCP/IP, VPNs, firewalls), encryption algorithms and the ability to design countermeasures against complex cyber threats and vulnerabilities.
  • Ability to translate operational requirements into technical protection needs and effectively communicate risk and design concepts to both technical experts and executive stakeholders.

Benefits

  • 144 hours of PTO
  • 11 holidays
  • 85% of insurance premium covered
  • 401k
  • Continued education, certifications maintenance and reimbursement
  • More benefits available

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 11-50Since 2023

• Plan and engineer the integration of a wide variety of cybersecurity and IT tools into Wraithwatch’s core artificial intelligence engine. • Ensure AI engine has access to common data models and function execution models across disparate sets of IT and security tools. • Provide cybersecurity subject matter expertise, oversight, and optimization into autonomous reasoning and analysis performed by Wraithwatch system. • Own Wraithwatch’s internal corporate cybersecurity posture across our company endpoints, cloud systems, build pipelines, and AI subsystems.

United States
SentinelOne logo

Director, Privacy & Security, Legal

SentinelOne

Secure your enterprise with the autonomous cybersecurity platform. Endpoint. Cloud. Identity. XDR. Now.

Security Engineer109 days ago
OtherRemoteTeam 1,001-5,000Since 2013H1B Sponsor

• Develop and execute a global legal strategy for privacy and data security that aligns with SentinelOne’s rapid growth and product innovation. • Work cross-functionally across the organization, supporting the Commercial team on the privacy aspects of both inbound and outbound work while collaborating closely with the Legal Product team. • Provide expert guidance on a wide range of privacy, security, and compliance matters, ensuring that legal requirements are integrated seamlessly into our technical operations. • Lead the legal side of incident management and response, providing strategic advice and legal guidance on all types of incidents to ensure the company navigates complex security events with precision and speed.

United States
$206.3K - $270K / year
Job Closed
ASCERA logo

Senior Security Compliance Consultant

ASCERA

The Better Way to Do Security Compliance.

Security Engineer109 days ago
OtherRemoteTeam 11-50Since 2023H1B No Sponsor

__Own The Role:__112Cyber (formerly SP6 Cyber Risk & Compliance) is looking for a Compliance SME wanting to take the next step in their career! In this role, you will assist organizations in solidifying and strengthening their security posture while also conducting assessments for those pursuing certification. Joining our Compliance team, you will see your impact across the company as you take ownership over customer projects and advising our platform team on the different compliance rules.    From there, you will be supporting Defense Industrial Base (DiB) companies to ensure they are CMMC and/or NIST 800-171 compliant. You will accomplish this through providing pre-audit readiness and GAP assessments, plans of action and milestones (POA&M) support, Compliance as a Service (CaaS), and official C3PAO assessments.   __**How You’ll Drive Success:**____Advisory Services__ - Leading cybersecurity gap assessments aligned with NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC). - Supporting the day-to-day activities of engagements for external clients, as a contributing member of 112Cyber’s customer-facing Cyber Risk & Compliance practice. - Assist external customers in their FedRAMP, DFARS 7012, CMMC, and NIST 800-171 compliance initiatives.  - Applying cyber compliance / risk management knowledge, control principles and technical knowledge across cyber risk and compliance engagements.   - Consulting with end clients to gather requirements and understand our clients' key business and security challenges. Working with team members to advise on practical and cost-effective solutions to help mitigate our clients’ cybersecurity risks and challenges. - In depth knowledge of relevant security regulatory compliance requirements and translating those into business processes and security controls to enhance and support client’s compliance and audit capabilities.   - Articulating and defending IT controls testing approach and performing test of design and operating effectiveness. - Develop and deliver training to internal teams and customers.   - Establishing and maintaining effective working relationships with colleagues, existing clients, and prospective client organizations.  - Supporting the ASCERA product team and advising them on NIST continuous monitoring software. __C3PAO Assessments__ - Conducting formal assessments of organizations’ cybersecurity practices using the CMMC assessment process (CAP). - Collaborate with client organizations to plan assessments, develop assessment schedules, and ensure readiness - Assess the effectiveness of security practices and ensure they align with the CMMC practices and processes. - Interview key personnel within the organization to understand how cybersecurity practices are implemented and maintained. - Evaluate sufficiency and adequacy of evidence to verify implementation. - Maintain an objective and unbiased stance during the assessment process, ensuring that conclusions are based on facts and evidence. - Ensure that all documentation is properly prepared for submission to eMASS if the organization is seeking certification.

Florida
Red Hat logo

Senior Software Engineer – OpenShift Infrastructure, Security Compliance

Red Hat

The leading provider of enterprise open source solutions.

Security Engineer109 days ago
Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

• Develop tooling to generate and automate regulatory benchmark guidance • AI driven tooling (MCP servers/toolsets) that integrates with IDEs (Claude Code/Cursor) • Understanding Compliance Operator resources, like CustomRules and Profiles • Implementing checks using multiple scanning technologies, like OpenSCAP and CEL expressions • Developing and maintaining operators that improve OpenShift security posture • Contribute to industry benchmark regulatory bodies where applicable (CIS)

Czechia
Job Closed