General Dynamics is a global aerospace and defense company offering products designed to provide safety and security to people around the world. In the past, General Dynamics has p
Cloud Network Security Architecture Manager
Location
West Virginia + 1 moreAll locations: West Virginia | Texas
Posted
72 days ago
Salary
$114.8K - $155.3K / year
Seniority
Lead
Job Description
Cloud Network Security Architecture Manager
General Dynamics
Title: Cloud Network Security Architecture Manager (TIC 3.0) Location: USA WV Martinsburg - 510 Butler Ave (WVC009) Job Description: Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: MBI (T2) Job Family: IT Infrastructure and Operations Job Qualifications: Skills: Cloud Platform, IT Service Management (ITSM), Network Architecture Certifications: None Experience: 10 + years of related experience US Citizenship Required: No Job Description: GDIT has an opportunity for a Cloud Network Security Architecture Manager supporting the Department of Veterans Affairs (VA). This role leads secure network and cloud architecture design, TIC 3.0 modernization, and enterprise gateway operations. The manager partners with stakeholders, guides technology decisions, and ensures security, compliance, and performance across hybrid and multi‑cloud environments. HOW YOU WILL MAKE AN IMPACT • Partner with internal teams and customer groups to define strategy, design solutions, and support implementation. • Collaborate with stakeholders and vendors to ensure solutions meet technical and business requirements. • Communicate technical status, risks, and impacts to leadership and customers. • Evaluate new technologies, perform pilots, assess vendors, and recommend solutions. • Resolve escalations by analyzing issues, providing guidance, and implementing fixes. • Mentor engineering staff on key technologies and processes. • Develop and execute test plans to validate solutions. • Establish timelines, coordinate delivery, and support budgeting decisions. • Write functional and technical requirements and solution documentation. • Stay current on cloud, security, and network technology trends. • Support selection, implementation, and operationalization of new technologies. WHAT YOU’LL NEED TO SUCCEED • Bachelor’s Degree or 4+ additional years of experience in lieu of a degree. • 10+ years in cloud, network, or platform engineering/architecture supporting enterprise‑scale environments. • 3+ years leading AWS/Azure hybrid or multi‑cloud environments in regulated or federal settings. • Experience supporting large federal agencies or customers. • Support 24×7×365 TIC operations, including critical incident bridge participation. • Lead TIC 3.0 policy enforcement, DNS filtering, SSL decryption, IPS/IDS signature deployment. • Manage DHS Cyber Hygiene, ED 19‑01, BOD 18‑01/19‑02 compliance and remediation actions. • Oversee external connections (BPE/S2S VPN) approval, audits, and configuration lifecycle. • Deliver required weekly TIC reports, vulnerability rollups, and compliance status updates. • Lead TIC technical refresh, architecture redesign, and next‑generation gateway modernization. Additional Experience: • Experience designing landing zones, secure network/identity patterns, and CI/CD/IaC pipelines. • Knowledge of NIST 800‑53/RMF, Zero Trust, TIC 3.0, FedRAMP services, and continuous monitoring. • Experience delivering Kubernetes/OpenShift platforms with DR, RTO, and RPO requirements. • Leadership in multi‑vendor/SIAM environments with cross‑domain change coordination and incident response. Technical Skills: • Cloud Platforms: AWS, Azure, IAM/Entra ID, landing zones, cloud networking, security, monitoring. • Networking & Identity: VPC/VNet design, hub‑and‑spoke, SD‑WAN, DNS, NAT, firewalls, service mesh, SSO, PIV/FIDO2. • Automation & Delivery: Terraform, CloudFormation/Bicep, Ansible, Packer, Helm, GitOps, policy as code. • Containers & Platforms: Kubernetes/OpenShift operations, lifecycle management, security. • Observability & SRE: OpenTelemetry, Prometheus/Grafana, SIEM/log analytics, SLOs/error budgets. • Data & Storage: Managed databases, backup/restore, immutability, replication. • Security & Compliance: CIS/STIGs, vulnerability orchestration, encryption, secrets management. • Cost & Performance: FinOps fundamentals, autoscaling, rightsizing, performance tuning. Preferred Certifications: • AWS Solutions Architect – Professional • Microsoft Azure Solutions Architect Expert • VMware Certified Professional / Advanced Professional • CKA/CKAD or OpenShift Administrator • HashiCorp Terraform Associate / Authoring and Operations Professional LOCATION: Hybrid, based out of Martinsburg, WV or Austin, TX. CLEARANCE: Must be able to obtain and maintain a Public Trust clearance. Visa sponsorship will not be provided for this position. GDIT IS YOUR PLACE At GDIT, the mission is our purpose, and our people are at the center of everything we do. ● Growth: AI-powered career tool that identifies career steps and learning opportunities ● Support: An internal mobility team focused on helping you achieve your career goals ● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off ● Community: Award-winning culture of innovation and a military-friendly workplace OWN YOUR OPPORTUNITY Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward. The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Hybrid Work Location: USA DC Washington Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Cybersecurity Engineer – CIAM
Home DepotHome Depot is a Fortune 500 company and the world's largest specialty retailer of home-improvement products. Founded in 1978 with its first two stores in Atlant
• Design automation workflows and capabilities in support of data collection, investigation and incident response. • Develop threat hunting and data analysis strategy and capabilities. • Identify and propose new technologies, methodologies and/or approaches to detecting malicious activity. • Utilize indicators to scope and respond proactively to emerging threats. • Design, build, configure, maintain and monitor cybersecurity threat defense capabilities and user access management.
Staff Security Engineer
DDNWorld’s leading Data Intelligence Platform supercharging over 500,000 GPUs across all data workloads
• Lead the design and implementation of end-to-end security architecture for distributed storage platforms • Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers • Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform. • Define identity and access management (IAM) integrating enterprise identity providers • Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.
Senior Product Security Engineer – Sovereign Cloud
Red HatThe leading provider of enterprise open source solutions.
• Own the security and compliance functions related to our digital sovereign commercial product offerings and environments. • Lead technical discussions across multi-functional engineering teams, product and sales teams, as well as with third party auditors. • Support the continuous improvement of Red Hat Product Security through designing, developing, and implementing automation at scale to enable the maturation of processes. • Mentor and aid the growth of junior team members. • Support the downstream integration of open-sourced projects; collaborate to develop and implement Red Hat specific capabilities from the upstream. • Serve as an evangelist of security and compliance both inside Red Hat and externally, with partners, customers, or within the open-source community.
Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. At Coinbase, identity and access controls are foundational to protecting customer funds, sensitive data, and the trust that underpins our position as the world's most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged access controls, and automated governance across a complex and rapidly evolving technology ecosystem and regulatory landscape. This role serves as a senior technical leader within the IAM program, partnering with Engineering, IT, Platform, and business teams to architect and deliver identity solutions that balance zero-trust security with workforce enablement, reduce insider risk, and satisfy global regulatory requirements. What you’ll be doing (ie. job duties): - Lead the architectural vision and security engineering execution for Coinbase’s Identity and Access Management (IAM) and workforce security platforms across our multi-cloud infrastructure, extensive third-party SaaS ecosystem, and internally developed applications. - Evaluate, design, and implement "build, buy, or hybrid" strategies for workforce Identity Governance and Administration (IGA), integrating commercial tools with custom middleware and machine learning or AI models to automate complex access lifecycles and maximize ROI. - Write high-quality code to build scalable automation, custom integrations, and self-service guardrails that embed intelligent identity controls directly into CI/CD pipelines, SaaS provisioning workflows, and internal enterprise tooling. - Conduct comprehensive threat modeling and security architecture reviews for foundational identity systems and critical SaaS integrations, utilizing automated threat intelligence and AI-assisted analysis to proactively identify attack vectors and design resilient mitigations. - Partner with Engineering, IT, HR, AI/ML, and Product teams to align security initiatives with business goals, balancing robust zero-trust security with developer velocity and seamless workforce enablement. - Act as the directly responsible individual (DRI) for complex, cross-team security initiatives, mentoring junior and mid-level engineers, and influencing senior leadership on risk tradeoffs and next-generation workforce security strategies. What we look for in you (ie. job requirements): - 7+ years of proven experience in software engineering, security engineering, or systems architecture, with a deep, Staff-level focus on Identity and Access Management and enterprise workforce security. - Must be proficient in at least one programming language (e.g., Python, Go) and be able to effectively leverage AI-assisted development tools to build security tooling, automate workflows, and accelerate code review. - Demonstrated track record of successfully implementing complex hybrid IAM infrastructures, integrating a massive footprint of third-party SaaS applications alongside internally developed microservices. - Deep operational and architectural understanding of Identity Governance and Administration (IGA) processes, including automated provisioning/deprovisioning (JML workflows), continuous access reviews, and privileged access management (PAM) across a diverse enterprise fleet. - Extensive expertise in modern identity protocols (SAML, OAuth2, OIDC, SCIM), cloud IAM (AWS and GCP), and dynamic access control frameworks (RBAC, ABAC, ReBAC) that adapt based on behavioral context and AI-driven risk scoring. - Strong background in applied risk management, automated threat modeling, and zero-trust architecture principles applied to high-growth distributed systems and globally distributed workforces. - An execution-focused mindset with the ability to navigate ambiguity, drive alignment without direct authority, and communicate highly technical risk concepts to business stakeholders. - Experience driving security and engineering outcomes across decentralized or federated organizational structures, where the ability to build consensus, influence without direct authority, and coordinate delivery across multiple contributing teams is essential to success. Nice to haves: - Experience operating in a hyper-growth tech, FinTech, or crypto environment, navigating strict regulatory landscapes (e.g., SOX) specifically regarding workforce access, logging, and auditing. - Experience governing non-FTE workforce populations (such as BPO, contractors, and M&A) at scale, including birthright access design, role-based access control for high-risk personas, and timely deprovisioning across complex identity lifecycles. - Hands-on experience with Policy-as-Code paradigms (like Open Policy Agent) and integrating machine learning to automate policy generation, detect permission anomalies, or streamline IGA certification campaigns. - Experience managing identity boundaries for AI/ML workloads, including securing workforce access to large language models, training data pipelines, and inference infrastructure. Job #: P76467 Pay Transparency Notice: Depending on your work location, the target annual salary for this position can range from $218,025 to $256,500 + target bonus + target equity + benefits (including medical, dental, vision and 401(k)). #LI-Remote Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $218,025—$256,500 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal OpportunityCoinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and ApplicantsDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI DisclosureFor select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com




