• Multi-Enclave Design & Architecture: Designs secure enterprise architectures across multiple security classification enclaves (UNCLASSIFIED and SECRET). Implements Zero Trust Architecture (ZTA), Software Defined Networking (SDN), and Comply-to-Connect (C2C) frameworks.
• Acquisition & Lifecycle Support: Document and integrate cybersecurity architecture and systems security engineering requirements throughout the DoD acquisition lifecycle. Evaluate security architectures proposed in response to acquisition documents.
• Risk Management & Continuous Monitoring: Perform security planning, assessment, risk analysis, and risk management. Perform Risk Assessments on findings identified through Continuous Monitoring Activities, recommending courses of action for all vulnerabilities or non-compliant areas.
• System Integration: Participate as the primary security engineering representative on engineering teams for the design, development, implementation, evaluation, and integration of IA architectures, systems, or system components.
• DCO Team Integration: Works directly alongside Defensive Cyber Operations (DCO) to feed system telemetry into incident response workflows and translate active threat hunt findings into system architecture hardening.
• Configuration & Maintenance: Evaluate and test software security patches and configuration changes for compatibility with the current baseline, employing secure configuration management processes. Evaluate new or trial equipment/software being brought into authorization boundaries.
• Security Engineering & Cloud Oversight: Drive “security by design” by reviewing technical change requests, evaluating new technologies, and providing security oversight for cloud-based platforms (primarily Azure).
• Emerging Technology: Apply knowledge of AI policy, procedures, and workforce structure to design, develop, and implement secure networking, computing, and enclave environments.
• Advanced Analytics & Dashboards: Implements and manages advanced cybersecurity dashboards that aggregate vulnerability management metrics and provide leadership with real-time risk-posture and project-tracking visualization.
• Stakeholder Engagement: Interact with the customer and project team members to translate operational requirements into protection needs (security controls) and identify overall security requirements for the proper handling of Government data. Ensure trusted relationships among external systems are enforced.