Security architect jobs in Portsmouth, VA - 91 jobs
All
Security Architect
Information Systems Security Officer
Security Engineer
Defense Analyst
Information Security Officer
Senior Security Engineer
Senior Information Security Consultant
Security System Engineer
Data Security Analyst
Senior Manager, Information Security Office Consultant
Capital One 4.7
Security architect job in Newport News, VA
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
As a Senior Manager, You will play a leading role in delivering product security advisory services for a fast moving project within a line of business portfolio, working closely with other professionals as required. You have the ability to lead complex problem solving in partnership with multiple stakeholders in a fast-paced environment, driving results with critical impact. You will work with the other Information security consultants, business, technology and risk partners to achieve time sensitive goals and objectives in a secure manner with a heavy forward lean on modern software and technology architectures.
Responsibilities:
Act as an Information Security point of contact for a business function within the Card line of business
Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Leverage strong technical acumen and be security SME reviewing architecture, providing risk mitigation solutions and driving overall risk management.
Partner closely with engineers, product managers, and other cross-functional partners to help break down complexity and organizational silos to problem solve.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special Information Security hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have experience in securing large-scale e-commerce platforms, with deep understanding of payments systems, customer data protection across high transaction environments ensuring protection of user data across internal and partner ecosystems.
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of Security concepts
At least 5 years of experience performing security risk assessments and securityarchitecture reviews
At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
At least 4 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
6+ years of experience Application Security, Threat Modeling, Penetration Testing, Vulnerability Management
4+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
2+ years experience in e-commerce industry
2+ years of experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
1+ years of experience in security integration for Mergers and Acquisitions
1+ years of experience with Cloud patch management practices such as system rehydration and image management
1+ years of experience utilizing Agile methodologies
1+ years of experience with Software SecurityArchitecture
1+ years of experience with Application Security
1+ years of experience with Threat Modeling
1+ years of experience with Penetration Testing and/or Vulnerability Management
1+ years of experience with integrating SaaS products into an Enterprise Environment
1+ years of experience with securing Container services
1+ years of experience with Splunk-Fu and Enterprise Monitoring experience
1+ years of experience in a Financial services industry experience
1+ years of experience with Offensive or Defensive Security techniques
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber Technical
New York, NY: $250,800 - $286,200 for Sr Manager, Cyber Technical
Plano, TX: $209,000 - $238,500 for Sr Manager, Cyber Technical
Richmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$84k-108k yearly est. 1d ago
Looking for a job?
Let Zippia find it for you.
Information Systems Security Officer (ISSO) - Intermediate (Info. Systems &Cyber Security, Associate)
The Mil Corporation 4.5
Security architect job in Norfolk, VA
Clearance Required: Secret Education Required: BA/BS or HS/GED and Equivalent Work Experience US Citizenship: Required
The MIL Corporation seeks an Information Systems Security Officer (ISSO) - Intermediate (Info. Systems & Cyber Security, Associate) to support cybersecurity operations for a Federal Government client in Norfolk, VA. The ISSO ensures cybersecurity for assigned systems, reporting to the Program Manager/System Owner (PM/SO). Responsibilities include feature deployment, security policy implementation, and RMF compliance. The ISSO may delegate tasks during Assessment and Authorization (A&A) but remains accountable.
This position currently requires a hybrid schedule. This hybrid position may require schedule changes based on contract needs. Schedule is subject to change based on company/contract requirements.
Responsibilities
Collaborate with SOC stakeholders (systems administration, network, security, infrastructure teams, Enterprise Help Desk, program managers, and business unit sponsors).
Ensure DoN Authorization to Operate (ATO) compliance Commander, Navy Installations Command (CNIC) operational IT boundaries per applicable directives.
Provide expertise in RMF processes, guiding system owners through steps 1-5, including categorization, control selection, and eMASS documentation.
Conduct continuous monitoring, vulnerability scanning, STIG/patch application, and manage findings in eMASS and VRAM.
Maintain and update POAMs and configuration management plans, ensuring timely milestone completion.
Evaluate threats, vulnerabilities, and security findings, providing recommendations to enhance IT resource protection.
Ensure compliance with Department of Navy (DoN) and DoD cybersecurity policies, verifying user clearances and training.
Assemble and submit Security Authorization Packages, registering and maintaining systems in eMASS.
Execute annual security reviews, control testing, and contingency plan testing per FISMA requirements.
Correlate non-RMF vulnerability assessment findings (e.g., penetration testing, CCORI) to RMF controls for holistic risk assessment.
Travel
Up to 10% annually, as required.
Required Qualifications
7 years of relevant experience in cybersecurity or related fields
Active Security+ Certification (IAT Level II)
Expertise in RMF processes and tools (e.g., eMASS, VRAM, NESSUS) and compliance frameworks (e.g., CNSS 1253, FIPS 199, STIGs)
Strong understanding of DoD, DoN, and CNIC cybersecurity directives, processes, and business rules
Proven experience creating and maintaining RMF artifacts, managing vulnerabilities, and maintaining configuration management plans
Strong communication skills for effective collaboration with team members
Desired Qualifications
CISSP Certification
Hands-on experience with the U.S. Navy Risk Management Framework Process Guide (RPG) NAO process and procedures
Education
Bachelor's Degree in a relevant field from an accredited institution. Alternatively, an Associate's Degree with an additional 4 years of relevant work experience, or an additional 6 years of relevant work experience in lieu of a degree.
Clearance
All applicants for this position must possess a current Secret clearance; please note that the clearance process considers financial background aspects.
Compensation
The MIL Corporation values your contributions and offers a range of benefits to support your overall well-being. We are pleased to offer a comprehensive range of benefits to our full-time employees which include health, life, disability, and retirement plans, as well as paid time off, opportunities for professional growth and tuition assistance. Additional benefits and incentives may also apply, which will be communicated during the hiring process.
For this position, the projected compensation range is $115,000 - $145,000 per year. This estimate represents the typical salary range and is just one part of MIL's complete compensation package. Final salary for this position is determined based on factors such as individual qualifications, education, experience, and contractual limitations. Learn more on the MIL Careers page.
Why MIL?
The MIL Corporation (MIL) is a dynamic workforce of industry professionals who deliver world-class solutions in cyber, engineering, financial management, and information technology - and we are looking for candidates like you! MIL offers opportunities for professionals at all stages of their careers, from early-career candidates to experienced industry professionals. We are known for a collaborative, people-first culture where employees are supported, valued, and encouraged to grow. This commitment to our people and our work is reflected in the industry and workplace awards MIL has received over the years.
2021 - 2024, Top Workplaces USA award (Energage)
2017 - 2025 Top Workplaces Award, Greater Washington Area (The Washington Post)
2018 - 2025 Certified Great Workplace, Great Place to Work
2021 - 2025, Best Workplaces in Consulting & Professional Services
2021 Fortune Best Workplaces for Millennials
2018 Fortune, Great Place to Work: Best Place to Work for Diversity
2017, 2020 - 2025 Top Workplace Award, South Carolina (Greenville Business Magazine, Columbia Business Monthly, and Charleston Business Magazine)
2025 Corporate Partnership Award, Association of Fundraising Professionals, Maryland Chapter
2025 Moxie Award, GovCon Category
2024 Patriot Award, Employer Support of the Guard and Reserve (ESGR), Department of Defense
2022 Freedom Award, Employer Support of the Guard and Reserve (ESGR), Department of Defense
2018, Above & Beyond Award, Employer Support of the Guard and Reserve (ESGR), Department of Defense
If your goal is to help the federal government deploy leading technologies, improve financial management, or defend the nation in cyberspace, MIL welcomes you. Become a part of something greater, where you, the people, make the difference.
Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by state or federal law.
$115k-145k yearly 2d ago
Systems Security Engineer (ISSE)
Solvere Technical Group
Security architect job in Suffolk, VA
Solvere Technical has an immediate need for an ONSITE Information Systems Security Engineer (ISSE) at Navy Information Warfighting Development Center (NIWDC) based in Norfolk, Virginia.
MUST be a US CITIZEN, live close to NORFOLK, VA, have an ACTIVE TOP SECRET CLEARANCE, with active IAT II CERTIFICATION.
Job Description
Supports our customer providing system Risk Management Framework (RMF) ATO security engineering services and documentation.
Support the Government to ensure core security engineering principles are implemented into assigned programs information systems architecture.
Determine client security control requirements and support security categorization of the system.
Implement security controls utilizing eMASS and Xacta 360 support tools.
Conduct certification and testing in accordance with the Risk Management Framework (RMF) and National Institute of Standards and Technology (NIST) policy; identify deficiencies and providing recommendations of risk mitigation to customer.
Perform Risk Assessments and develop Concepts of Operations (CONOPS), Security Policies, Cybersecurity Strategy, Test Plans, System Security Plans and CYBERSAFE related documentation.
Maintain the Plan of Action and Milestones (POA&M) to ensure documentation and traceability which outlines a plan to address identified security weaknesses or vulnerabilities within an organization's systems.
Perform cybersecurity hardening and security monitoring on network infrastructures (STIGs, patching, ACAS scanning, etc.).
Ability to develop and interpret securityarchitectures, data flow diagrams, and publications that depict the system(s) architecture.
Ability to be able to identify risk areas of non-compliance and propose solutions to design to full-fill operational requirements and meet cybersecurity requirements simultaneously.
Incorporate cybersecurity vulnerability solutions into system designs (e.g., Cybersecurity Vulnerability Alerts).
Provide support to security/certification test and evaluation activities.
Job Qualifications:
MUST be a US Citizen
MUST have an active Security Clearance - Top Secret
MUST reside in Norfolk, Virginia or surrounding areas and able to commute onsite daily.
MUST have at least five (5) years of experience as an ISSE on programs and contracts of similar scope, type, and complexity within the Federal Government.
MUST have an active CompTIA Security+ CEU or equivalent certification (CISSP, SSCP, CSA+, or equivalent).
MUST have an Active DoD 8570 IAT II certification.
MUST have a Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or equivalent 5+ years experience.
Must be Proficient in Microsoft Office tools. (Power Point, Word, Visio, etc.).
Must have excellent technical writing, reporting and communication skills.
Desired Qualifications:
Experience conducting security assessments and working with Security Control Assessors (SCAs) and applying standard auditing techniques during systems security control assessments, including the proper interpretation of the control requirements, determining if the artifacts provided are sufficient and recommending remedial action to Government customer to ensure compliance.
Knowledge of Department of Defense Architecture Framework (DoDAF) views facilitating integration and promoting interoperability across capabilities and among integrated architectures.
Experience with modern networks, operating systems, databases, and virtual computing.
Expert knowledge of security engineering, design concepts and principles.
Exceptional verbal and written communication skills, with the ability to collaborate across teams and organizations, including senior level management.
Proven ability to multi-task and deliver on-time with the highest quality.
Experience with the NAVY RMF ATO process.
Experience working with Navy EMASS and Xacta 360.
Experience with Cloud Systems
Masters degree in Cybersecurity, Information Assurance, Computer Science, or equivalent 9+ years experience.
Security Requirements:
Must already have an Active DoD Top Secret security clearance.
Travel Requirements:
Occasional travel might be required
Physical Requirements:
Repeating motions that may include the wrists, hands and/or fingers.
Light work that includes moving objects up to 20 pounds
BENEFITS
Solvere offers a comprehensive and generous benefits package. The Solvere benefits package includes medical, dental, and vision insurance for the employee and/or families. Solvere also includes basic life insurance plus short- and long-term disability for the employee. Employees may elect to enroll in our company's 401k plan. Employees will also accrue paid time off and holidays. Additional voluntary options include supplemental insurance plans.
About the Company Visit: ************************
Solvere Technical Group is committed to non-discrimination and equal employment opportunity. All qualified applicants will receive consideration for employment without discrimination based on disability, protected veteran status or any other characteristics protected by law.
$79k-110k yearly est. 2d ago
Cyber Security Architect I
Athena Technology Group 3.1
Security architect job in Norfolk, VA
Employment Type: Full-Time Shift: N/A About the Company Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) and Historically Underutilized Business Zone (HUBZone) established in 2010. ATG has immense experience and a strong, solid reputation throughout various government agencies providing consistently superior, innovative and cost-effective solutions. ATG is a premier provider of cybersecurity, risk management framework (RMF) and communications cybersecurity solutions as well as information technology (IT) and communications consulting, system engineering, integration, deployment and operation of state-of-the-art command and control and information systems that deliver critical network centric solution to the warfighter. We are looking for innovative industry professionals to join our team and continue our proven track record.
ATG is an Equal Opportunity/Affirmative Action Employer Minorities/Females/Vets/Disability
Job Summary
Support the Naval Sea Systems Command Code 03S (NAVSEA 03S) Digital Industrial Operations (DIO) efforts concerning information technology services in support of the Navy Maritime Maintenance Enterprise Solution (NMMES) Program.
Key Responsibilities
Relies on extensive experience and judgment to plan and accomplish goals and independently performs a wide variety of complicated tasks.
May provide consultation on complex projects and is considered to be the top level contributor/specialist. Performs a variety of routine project tasks applied to specialized technology problems.
Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to Information Assurance requirements.
Conducts security assessments and security consulting services.
Analyzes information security requirements.
Knowledgeable about DoD and DoN Information Assurance rules and regulations.
Under general supervision, designs, develops, engineers and implements solutions to MLS requirements. Gathers and organizes technical information about an organization's mission goals and needs, existing security products and ongoing programs in the MLS arena.
Performs risk analyses, which also includes risk assessment.
Provides technical support for secure software development and integration tasks, including reviewing work products for correctness and adhering to the design concept and to user standards.
Knowledgeable of Security/IA products such as PKI, VPN, firewalls, and intrusion detection systems.
Analyzes and recommends resolution of security/IA problems on the basis of knowledge of the major IA products and services, an understanding of their limitations, and knowledge of the IA disciplines.
Qualifications:
Required:
Requires US Citizenship
Required Security Clearance: Secret
Years Experience: Experience with IT and Cybersecurity
Education: Minimum of 0-5 years of applicable experience
Familiar with a variety of the field's concepts, practices, and procedures.
Desired:
Experience with network infrastructure, database, cloud and data center operations, and security protocols
Physical and Environmental Conditions
Work to be performed out of Norfolk, VA supporting various missions across the area of responsibility.
Must be able to sit for long periods of time in office-setting
Additional Benefits
Performance Bonuses and annual salary reviews
Health, dental, and vision insurance
Short Term Disability, Long Term Disability, and Life Insurance
401(k) plan with company match
Opportunities for professional growth and development
A collaborative and inclusive work environment
ATG is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Learn more about your rights under Federal EEO laws and supplemental language.
$109k-154k yearly est. 60d+ ago
Director, Client Security Engineering Architect
KPMG 4.8
Security architect job in Virginia Beach, VA
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Director, Tech Engineering to join our Tax Ignition Group.
Responsibilities:
* Lead the function of responding to clients' security inquires
* Meet with clients to answer their security questions and negotiate compensating controls when there are gaps between client requirements and our product offerings
* Drive innovation and improvement in the client security inquiry process such incorporating Artificial Intelligence into the process, creating additional collateral such as whitepapers, managing metrics, and improving the tooling and interactions with requestors
* Partner with various groups within Tax's technology function and business teams to incorporate trends into product roadmaps; collaborate with other compliance teams, and raise awareness around client security requirements
* Review and respond to client security questionnaires and assessments
* Build and maintain a knowledge base of common client questions
Qualifications:
* Minimum ten years of recent experience in Information Technology (IT) security compliance, risk management or related IT security within a large IT organization, preferably within a professional services firm, software product, or other highly regulated environment
* Bachelor's degree from an accredited college or university is preferred
* Deep understanding of cloud architecture, modern software development, and technical security controls is required; Azure experience is preferred
* Strong executive presence, negotiation, presentation, and communication skills are required; excellent analytical and problem-solving skills to assess complex security issues and develop effective solutions; capability to work effectively in a global environment, understanding diverse cultural perspectives and international client needs
* Proven experience in client-facing roles, particularly in handling security inquiries, negotiations, and managing client relationships; demonstrated ability to drive innovation and continuous process improvement, particularly in integrating new technologies and methodologies into existing processes
* Demonstrated knowledge of industry authoritative sources such as COBIT, NIST, ISO standards; CISM, CISA, ISO 27001 Auditor, LSS Green Belt, CRISC, CIPP, CGEIT or ITIL preferred
* Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.
Follow this link to obtain salary ranges by city outside of CA:
**********************************************************************
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
$86k-120k yearly est. 60d+ ago
Cyber Security Architect
Caci International Inc. 4.4
Security architect job in Norfolk, VA
Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Continental US * * * The Opportunity: Join CACI as the prime contractor on a growing program supporting NAVSEA 03D3 Digital Program Office as a Cyber SecurityArchitect supporting the Navy Maintenance and Modernization Enterprise Solution (NMMES), a mission-critical program that supports over 45,000 users executing naval ship and submarine maintenance operations worldwide.
Key Responsibilities:
* Perform specialized technology tasks related to Information Assurance requirements
* Conduct security assessments and provide security consulting services
* Analyze information security requirements for complex systems
* Apply DoD and DoN Information Assurance rules and regulations
* Design, develop, and implement solutions to Multilevel Security (MLS) requirements
* Gather and organize technical information about organizational mission goals, needs, and security products
* Perform risk analyses and assessments
* Provide technical support for secure software development and integration tasks
* Review work products for correctness and adherence to security standards
* Work with Security/IA products such as PKI, VPN, firewalls, and intrusion detection systems
* Analyze and recommend security/IA solutions based on product knowledge and limitations
* Support both legacy and modern application security requirements
Qualifications:
Required:
* Bachelor's Degree in Computer Science, Information Security, or related field
* Up to 3 years of experience in cybersecurity or related area
* Knowledge of DoD and DoN Information Assurance rules and regulations
* Understanding of security technologies and frameworks
* Experience with security assessment and risk analysis
Desired:
* Security certifications (e.g., Security+, CISSP, CEH)
* Experience with DoD/Navy programs or similar government IT systems
* Knowledge of FedRAMP and DISA security requirements
* Familiarity with Risk Management Framework (RMF)
* Experience with security tools and technologies
* Understanding of cloud security principles
* Knowledge of secure development practices
* SAFe certification
Specific labor category determined by years of experience + educational degrees as stated below:
* Cyber SecurityArchitect I - Bachelors degree and 3+ years of experience in Cyber Security or related area.
* Cyber SecurityArchitect II - Bachelors degree and 5+ years of experience in Cyber Securityarchitecture.
Additional Information:
This position offers an opportunity to protect critical Navy maintenance systems and data. The ideal candidate will combine strong technical security skills with an understanding of DoD security requirements and regulations.
Success in this role requires:
* Strong understanding of cybersecurity principles
* Knowledge of DoD security requirements
* Analytical and problem-solving skills
* Attention to detail
* Good documentation abilities
* Effective communication skills
Note: Position supports NMMES software suite which includes both legacy software applications and current web application technologies running on multiple operating systems. Must be comfortable working with diverse technology stacks and security requirements.
Key Success Factors:
* Understanding of securityarchitecture principles
* Knowledge of security assessment methodologies
* Familiarity with security tools and technologies
* Understanding of compliance requirements
* Ability to perform risk assessments
* Knowledge of secure development practices
The role requires someone who can:
* Assess security requirements
* Implement security solutions
* Conduct risk analyses
* Support secure development
* Document securityarchitectures
* Stay current with security threats and solutions
* Work effectively with development and operations teams
Special Requirements:
* Must be able to obtain and maintain required security clearances
* Must understand and comply with DoD security policies and procedures
* Must maintain knowledge of current security threats and mitigation strategies
* Must be able to work in a classified environment when required
This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI.
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
________________________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here.
The proposed salary range for this position is:
$53,100-$106,300
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
$53.1k-106.3k yearly 60d+ ago
Cyber Security Architect II
CDIT
Security architect job in Norfolk, VA
Program Background
The Navy Maritime Maintenance Enterprise Solution (NMMES) is a comprehensive Information Technology (IT) toolset supporting NAVSEA's ship maintenance, overhaul, repair, and modernization operations across the U.S. Navy fleet. NMMES encompasses approximately 79 IT systems, applications, networks, and data centers serving over 51,000 users worldwide at Navy Shipyards (NSY), Intermediate Maintenance Facilities (IMF), Regional Maintenance Centers (RMC), Ship Repair Facilities, and Forward Deployed Regional Maintenance Centers. The NMMES Technical Refresh (NMMES -TR) program requires robust cybersecurity architecture to protect these critical enterprise systems, ensure compliance with DoD and DoN Information Assurance requirements, and maintain secure operations across multiple classification levels.
Position Summary
The Cyber SecurityArchitect is a senior -level specialist responsible for designing, developing, engineering, and implementing solutions to Multi -Level Security (MLS) and Information Assurance (IA) requirements. This position conducts security assessments and consulting services, performs risk analyses, and provides technical support for secure software development and integration. The Cyber SecurityArchitect gathers and organizes technical information about mission goals, existing security products, and ongoing programs to develop comprehensive securityarchitectures. This role is considered a top -level contributor/specialist who independently performs complex tasks, provides consultation on complex projects, and may lead and direct the work of others.
Key Responsibilities
SecurityArchitecture and Design
Design, develop, engineer, and implement solutions to Multi -Level Security (MLS) requirements
Develop and maintain cybersecurity architecture for enterprise systems and applications
Gather and organize technical information about organizational mission goals, needs, and existing security products
Evaluate ongoing programs in the MLS arena and recommend architectural improvements
Integrate electronic processes and methodologies to resolve total system problems as they relate to Information Assurance requirements
Design defense -in -depth security solutions that protect the confidentiality, integrity, and availability of systems
Architectsecurity solutions for cross -domain requirements and system interconnections
Security Assessment and Risk Analysis
Conduct security assessments and security consulting services for enterprise systems
Perform risk analyses including comprehensive risk assessments of systems and networks
Analyze information security requirements and identify gaps in current security posture
Evaluate security controls for effectiveness in meeting DoD and DoN IA requirements
Assess vulnerabilities and threats to systems and recommend mitigation strategies
Review and validate security implementations against established security policies and standards
Support Risk Management Framework (RMF) activities including security control selection and assessment
Security Products and Solutions
Apply expert knowledge of security/IA products including PKI, VPN, firewalls, and intrusion detection systems
Analyze and recommend resolution of security/IA problems based on knowledge of major IA products and services
Evaluate security product capabilities and limitations for suitability in meeting requirements
Design and implement PKI solutions for certificate management and secure communications
Configure and integrate firewalls, IDS/IPS, and network security appliances
Implement VPN solutions for secure remote access and site -to -site connectivity
Evaluate emerging security technologies and recommend adoption where appropriate
Secure Software Development Support
Provide technical support for secure software development and integration tasks
Review work products for correctness and adherence to design concepts and user standards
Ensure security requirements are integrated throughout the software development lifecycle
Validate that security controls are properly implemented in applications and systems
Support security testing and evaluation of software products
Advise development teams on secure coding practices and securityarchitecture patterns
Compliance and Regulatory
Apply expert knowledge of DoD and DoN Information Assurance rules and regulations
Ensure systems comply with NIST SP 800 -53 security controls and DISA STIGs
Support Authorization to Operate (ATO) processes and documentation
Maintain compliance with DoD 8570/8140 cybersecurity workforce requirements
Interpret and apply DoD cybersecurity policies including DoDI 8510.01 (RMF)
Support continuous monitoring requirements and security posture reporting
Technical Leadership and Consultation
Provide consultation on complex cybersecurity projects as a top -level contributor/specialist
May lead and direct the work of other cybersecurity and IA personnel
Independently perform a wide variety of complicated security engineering tasks
Rely on extensive experience and judgment to plan and accomplish goals
Mentor junior team members on securityarchitecture principles and best practices
Collaborate with program management, systems engineers, and developers on security requirements
Brief leadership on security posture, risks, and recommended mitigations
RequirementsRequired Qualifications
Education
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (Master's degree preferred)
Experience
Minimum 5 years of experience in cybersecurity, information assurance, or related field
Familiarity with a variety of cybersecurity concepts, practices, and procedures
Demonstrated experience designing and implementing securityarchitectures
Experience with Multi -Level Security (MLS) environments and solutions
Experience conducting security assessments and risk analyses
Knowledge of DoD and DoN Information Assurance rules and regulations
Hands -on experience with security/IA products including PKI, VPN, firewalls, and intrusion detection systems
Ability to independently perform complex tasks and provide consultation on complex projects
Clearance
• Active Secret security clearance (minimum); Top Secret clearance preferred
Desired Qualifications
Master's degree in Cybersecurity, Information Assurance, or related field
Experience supporting Navy or NAVSEA IT programs
Experience with cross -domain solutions and guard technologies
Experience with cloud securityarchitecture (AWS, Azure, DoD Cloud)
Knowledge of NIST Cybersecurity Framework (CSF) and RMF implementation
Experience with eMASS and Navy RMF processes
Experience leading cybersecurity teams or projects
Knowledge of Zero Trust Architecture principles
Experience with security automation and orchestration tools
ISSEP, ISSAP, or ISSE certification
Technical Skills
SecurityArchitecture
Defense -in -Depth, Zero Trust, MLS Architecture, Cross -Domain Solutions, Security Design Patterns
Security Products
PKI/Certificate Management, VPN (IPSec, SSL), Firewalls (Palo Alto, Cisco ASA, Juniper), IDS/IPS (Snort, Suricata)
Risk Management
RMF, Risk Assessment, Vulnerability Assessment, Threat Modeling, Security Control Assessment
Compliance Frameworks
NIST SP 800 -53, NIST CSF, DISA STIGs, CNSSI 1253, DoDI 8510.01, DoDI 8500.01
Security Tools
ACAS/Nessus, SCAP, SIEM (Splunk, ArcSight), HBSS/ESS, Wireshark, eMASS
Network Security
Network Segmentation, DMZ Architecture, NAC, 802.1X, Network Access Control
Identity & Access
PKI, CAC/PIV, SAML, LDAP/Active Directory, Multi -Factor Authentication, Privileged Access Management
Encryption
Data -at -Rest Encryption, Data -in -Transit Encryption, Key Management, TLS/SSL, NSA Suite B
Cloud Security
AWS GovCloud, Azure Government, FedRAMP, Cloud Access Security Broker (CASB)
Core Competencies
Expert -level analytical and problem -solving skills for complex security challenges
Strong strategic thinking with ability to develop comprehensive securityarchitectures
Excellent written and verbal communication skills for technical documentation and executive briefings
Ability to independently perform complex tasks with minimal supervision
Leadership capabilities with experience directing and mentoring technical staff
Deep understanding of IA disciplines and their application to real -world security problems
Ability to translate complex security requirements into implementable solutions
Strong collaboration skills for working across technical and program management teams
Commitment to continuous learning in the rapidly evolving cybersecurity landscape
Sound judgment in making risk -based decisions and recommendations
$103k-152k yearly est. 60d+ ago
SOC Cyber Defense Analyst - SME (Journeyman)
Akira Technologies Inc. 4.1
Security architect job in Norfolk, VA
Akira Technologies is seeking a SOC Cyber Defense Analyst (SME / Journeyman) to support a government client in Norfolk, VA. This role provides hands-on cybersecurity monitoring, incident response, and forensic analysis across Operational Technology (OT), Industrial Control Systems (ICS), and enterprise network environments, including on-premises and cloud systems.
The ideal candidate has 5-7 years of cybersecurity operations experience, operates independently on complex incidents, and serves as a technical subject matter expert within the SOC while supporting and mentoring junior analysts.
This is an onsite position supporting NAVFAC in Norfolk, VA. This role requires Top Secret or higher clearance.
Key Responsibilities
Perform cyber defense monitoring and forensic analysis across host and network systems, including malware triage, log correlation, and timeline reconstruction.
Investigate security incidents using MITRE ATT&CK and Cyber Kill Chain methodologies.
Support containment, eradication, and recovery actions in accordance with established incident response procedures.
Serve as a journeyman-level SME, providing technical guidance and mentoring to junior SOC analysts.
Monitor, tune, and enhance SIEM platforms (e.g., Splunk Enterprise Security, Elastic SIEM, Cribl) to improve detection and threat visibility.
Develop and maintain SIEM correlation rules, dashboards, and continuous monitoring content using data models and tstats.
Evaluate system and network configurations for vulnerabilities and recommend remediation aligned with DoD cybersecurity standards.
Support STIG compliance activities and assist with Information Assurance Vulnerability Management (IVAM) actions.
Utilize asset mapping and inventory tools to validate authorized devices and identify unauthorized or anomalous systems.
Handle digital evidence in accordance with government forensic and chain-of-custody best practices.
Produce concise technical and executive-level reports detailing findings, impacts, and mitigation recommendations.
Collaborate with SOC leadership and government stakeholders to improve SOC workflows, threat hunting, and operational effectiveness.
Required Qualifications
Active Top Secret clearance (or higher).
5-7 years of experience in cybersecurity operations, SOC analysis, or incident response.
Strong knowledge of Windows and Linux operating systems, network traffic analysis, and security monitoring.
Experience working within DoD cybersecurity frameworks and compliance-driven environments.
Hands-on experience with tools such as Splunk (Enterprise Security preferred), Palo Alto, Elastic SIEM, Cribl, Nessus, CrowdStrike, VMware, or similar technologies.
Demonstrated ability to independently lead investigations and communicate findings to technical and non-technical audiences.
Preferred Qualifications
Experience supporting OT / ICS / SCADA environments.
Advanced Splunk Enterprise Security content development experience.
Familiarity with GrayNoise, Shodan, MODBus, PCAP analysis, or industrial protocols.
Relevant certifications such as GCIH, CEH, GCED, OSCP, CISSP, or equivalent.
Leveling Summary
Performs independently on complex incidents.
Acts as a technical SME within the SOC.
Mentors junior analysts without formal program or SOC ownership.
Escalates advanced or strategic issues to senior or lead analysts.
Salary Range: $125,000 - $140,000
Akira's pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
General Description of Benefits
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental plans, and vision coverage, and a 401(k) plan with employer match. To promote work/life balance, Akira offers paid time off, including vacation and sick time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave. We also offer short and long-term disability benefits to protect employee income in the event of sickness or injury, life insurance, accidental death and dismemberment insurance, and critical illness insurance. Akira also offers tuition, training, and certification reimbursement for professional development and career advancement.
Akira regularly reviews our total rewards package to ensure our offerings remain competitive and reflect the values and needs expressed by our employees.
About Akira Technologies
Akira strives to meet and exceed the mission and objectives of US federal agencies. As a leading small business cloud modernization and data analytics services provider, we deliver trusted and highly differentiated solutions and technologies that serve the needs of our customers and citizens. Akira serves as a valued partner to essential government agencies across the intelligence, cyber, defense, civilian, and health markets. Every day, our employees deliver transformational outcomes, solving the most daunting challenges facing our customers.
Akira is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
$125k-140k yearly Auto-Apply 35d ago
Executive Advisor -Business Information Security Officer
Elevance Health
Security architect job in Norfolk, VA
Executive Advisor - Business Information Security Officer Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Executive Advisor - Business Information Security Officer serves as a dedicated security and risk management leadership function aligned to the major business and technology-enabling divisions of Elevance Health. BISOs are embedded security leaders - connecting executive business and innovation leaders, technology professionals, compliance management teams, and the Global Information Security organization.
How You Will Make an Impact:
* Leads Information Security and Risk Management for an assigned Business Unit
* Leads Information Security and Technology Risk Management for an assigned Business Unit, ensuring alignment with enterprise security strategy, business objectives, and regulatory obligations.
* Serves as the primary business-facing point of contact for information security and technology risk matters, coordinating enterprise security capabilities and services as needed.
* Acts as a key leadership contact during incident response activities, ensuring effective business engagement, executive communication, and post-incident remediation.
* Owns the development and execution of the Business Unit security roadmap, aligned with enterprise priorities, business strategy, and defined risk tolerance.
* Identifies, prioritizes, and recommends opportunities to reduce risk and improve security outcomes through targeted assessments, continuous monitoring, and metrics-driven analysis.
* Participates in enterprise planning activities, including vendor and third-party risk assessment, technology platform selection and retirement, securityarchitecture alignment, prioritization, and integration planning.
* Serves as the Information Security and Technology Risk lead for mergers, acquisitions, and divestitures, including due diligence, integration planning, and risk remediation.
* Establishes and participates in governance forums to assess, accept, mitigate, or escalate technology risk in alignment with enterprise risk management practices.
* Provides security leadership for healthcare regulatory and compliance requirements (e.g., HIPAA, HITRUST, state privacy laws), ensuring audit readiness and sustained compliance.
* Defines, tracks, and reports meaningful security and risk metrics to business and executive stakeholders to support informed decision-making.
* Acts as a trusted advisor and subject matter expert to executive management, translating technical and cyber risk into clear business and financial impact.
* Influences business and technology leaders to adopt secure-by-design practices and risk-aware decision-making without direct operational authority.
* Mentors and develops security and risk management capabilities within the Business Unit and across enterprise teams.
* Must be capable of providing top-tier support for 6 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) SecurityArchitecture and Design, 11) Telecommunications and Network Security.
Minimum Requirements:
Requires BS/BA in Information Technology or related field of study and a minimum of 10 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities & Experiences:
* Broad-based experience to plan and design highly complex systems is strongly preferred.
* Expert knowledge and understanding of industry-accepted data processing controls and concepts strongly preferred as applied to Security Certifications: CISSP preferred and other advanced technical security certifications (e.g. Information Systems SecurityArchitecture Professional, Information Systems Security Engineering Professional, Certification and Accreditation or equivalent certifications).
Job Level:
Non-Management Exempt
Workshift:
1st Shift (United States of America)
Job Family:
IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
$104k-157k yearly est. 5d ago
Information Systems Security Officer / ISSO- Active TS/SCI with CI Poly
ENS Solutions, LLC
Security architect job in Norfolk, VA
Job Description
As an ISSO on our program, you'll detect, evaluate, and document the security configuration of developmental and operational tools and security impacts, and make improvement recommendations. Coordinate work with in-house teams, subcontractors, and vendors to identify the right mix of tools and techniques to translate your customers' IT needs and future goals into a plan that will enable secure and effective solutions.
As an ISSO on our team, you'll advise the client, leading the discovery of their cyber risks, understanding applicable policies, and developing a mitigation plan. You'll oversee the analysis of technical, environmental, and personnel details from technical subject matter experts and engineers as your team reviews the entire threat landscape. Then, you'll guide your client through a plan of action with presentations, whitepapers, and milestones. Your client will rely on you to translate security concepts, so they can make the best decisions to secure their mission-critical systems.
Requirements
3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Analyst (ISSA)
Experience conducting tools assessments and configuration analysis against best practices, vendor specifications, and government security guidelines and requirements
Experience with the implementation, oversight, and maintenance of the security configuration, practices, and procedures for systems
Experience with implementing controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels, including applying them to the design and implementation of information technology solutions to achieve an authorization to operate (ATO)
Experience with eMASS or Xacta IA Manager
Ability to perform risk analysis
Active TS/SCI clearance; willingness to take a polygraph exam
Associate's degree and 5+ years of experience supporting IT projects and activities, Bachelor's degree and 3+ years of experience supporting IT projects and activities, or Master's degree and 1+ years of experience supporting IT projects and activities
DoD 8570 IAT Level II Certification, including CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP Certification
Must obtain a DoD 8570.01-M CSSP Infrastructure Support Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND certification prior to start date on the contract
Additional Qualifications:
Experience with DoD security technical implementation guides (STIGs), checklists, and testing tools, including STIG Viewer, SCAP, and ACAS scanning tool
Experience assessing configuration changes, such as new COTS tools or web application upgrades, to system security boundary
Experience drafting tool implementation CONOPS and reviewing tool or capabilities topologies, CONOPS, and vulnerability scans to assess risk
Experience with cyber-related tools such as Ansible, Terraform, Splunk, or STIG Viewer
Knowledge of cloud-native security tools, including HBSS
Knowledge of Zero Trust principles and concepts
Ability to plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks
Ability to work within a collaborative team and a fast-paced dynamic environment
Possession of excellent written, organizational, presentation, and verbal communication skills
AWS, Azure, or GCP Certification
$74k-100k yearly est. 3d ago
Public Key Infrastructure (PKI) Auditor & Trainer/Information Systems Security Officer (ISSO)
Input Technology Solutions
Security architect job in Norfolk, VA
Input is currently seeking a Public Key Infrastructure (PKI) Auditor & Trainer/Information Systems Security Officer (ISSO) for a potential contract to assist the Department of the Navy (DON) Public Key Infrastructure (KPI) and Key Management Infrastructure (KMI) Services.
Location(s): Andrews AFB, MD; Norfolk, VA; San Diego, CA; and Pearl Harbor, HI
Key Responsibilities:
Maintain Naval Communications Security Material System (NCMS) PKI Registration Authority (RA) and Local RA (LRA) systems, perform operating system updates and validate machines are operating in accordance with Authority to Operate (ATO).
Coordinated with Navy Marine Corps Intranet (NMCI) for machine and network troubleshooting.
Maintain standard system security and disaster recovery plans and ensure implementation across the detachment.
Maintain enterprise architecture Standard Operating Procedures (SOPs) and documentation to include illustrations network topology, system access requirements and processes for obtaining material and replacement hardware and software.
Function as the NCMS PKI liaison to external LRA sites providing assistance and information pertaining to System access, network access, peripheral devices. Liaison support also includes working with the government Information System Security Managers (ISSM), and Information System Security Officers (ISSO) to achieve and maintain ATO requirements.
Perform Cybersecurity tasks to include validation of Assured Compliance Assessment System (ACAS) scans and patching, apply Security Technical Implementation Guides (STIGs).
Properly secure and maintain PKI archives until moved to long term storage facility.
Perform backups, validate scans, perform software updates as needed, and review workstation system logs.
Complete compliance audits in accordance with Joint Force Head Quarters Department of Defense Information Network (JFHQ-DODIN) PKI Audit requirements, audits drafts, reports, track audit Plan of Action and Milestones (POA&M), schedule audits and perform Training and Assist Visits (TAV).
Schedule, conduct and update PKI LRA, Trusted Agent (TA), System Administrator (SA), ISSO classroom training for newly appointed personnel through the Navy.
Qualifications:
Understanding of Department of Defense (DoD) Common Access Card (CAC) characteristics and CAC/Smart card operation and procedures to include CAC middleware and hardware, with a least one-year experience.
Knowledge of the principles, concepts, and methodology of Information Technology (IT) processing and a working knowledge of computer system architecture, performance characteristics and DoD and Service IT security policies with a least one-year experience.
Familiar with DoD 8520.02, Public Key Infrastructure and Public Key Enabling.
Skilled verbal and written communication techniques required to conduct meetings, and prepare reports and other correspondence
Must be able to work independently.
Possess analytical processing skills.
Possess DoD 8140 qualification of 461 Basic or 451 Intermediate upon first day of employment and continue to maintain extended training requirements as identified in SECNAV M-5239.2. Navy COOL - Navy Cyber Workforce (CWF) Program - CWF Model
JFHQ-DODIN PKI Auditor Qualified or served as Navy RA, LRA or PKI ISSO for 3 years.
$74k-100k yearly est. 60d+ ago
Security Engineer - Virginia Beach, VA
Serco 4.2
Security architect job in Virginia Beach, VA
Arlington, Virginia, US Hampton, Virginia, US Newport News, Virginia, US Crystal City, Virginia, US Panama City Beach, Florida, US Virginia Beach, Virginia, US Engineering 12701 Full-Time Yes - May Consider Occasional/Part Time Teleworking for this position $67889.77 - $113149.62
**Position Description & Qualifications**
**Position Description & Qualifications**
If you love high profile and challenging programing projects supporting the United States Navy - Serco has a great opportunity for you! This Information Security Test Engineer will be on a dynamic team responsible for testing afloat and shore based systems at our offices in Virginia Beach, VA, Panama City Beach FL, or Washington DC. Bring your expertise and collaborative skills to make an impact towards our national security homeland defense.
**This position is contingent upon your ability to obtain/maintain/transfer your Secret clearance.**
Serco supports the US Navy in the acquisition of new technology used to defend our nation. Our team reviews acquisition documentation, develops cyber test plans, executes cyber test events, collects, and analyzes data and writes test reports.You will be part of a team that works closely with the customers and other Serco teams to deliver cyber-secure systems to the Navy. The team has been supporting Cybersecurity Assessment and Authorization for over 15 years and has been recognized by the Navy for their outstanding contributions.
In this role, you will:
+ Perform activities necessary for system Assessment and Authorization
+ Support the program office in creating/gathering necessary artifacts necessary to support an Authorization decision.
+ Perform both manual and automated cybersecurity testing of systems and components.
+ Document test results and provide preliminary risk assessment to the Program Manager.
+ Provide weekly status updates for systems under your purview.
+ Supports development of Cyber Test Plan for executes test events, collects, and analyzes data, and provides a report on the results.
+ Create/ update Cybersecurity policies and procedures.
+ Works directly with senior technical personnel, stakeholders, and project managers in the planning and execution of test events.
To be successful in this role, you will have:
+ Bachelor's degree and 3 years of experience
+ An Associates degree and 5 years of experience.
+ Active DoD Secret Security Clearance.
+ A Cybersecurity certification. (i.e. CompTIA Security+ CE or higher-level certification)
+ Proficiency in technical writing.
+ Proficiency with MS-Office software to include MS Word, MS Excel, MS Power Point.
+ The ability to travel up to 25%.
Additional desired experience and skills:
+ Previous experience with DoD Risk Management Framework.
+ NQV (Navy Qualifier Validator) certification.
If you are interested in supporting and working with our military and sailors and a passionate Serco team- then submit your application now for immediate consideration. It only takes a few minutes and could change your career!
**Company Overview**
Serco Inc. (Serco) is the Americas division of Serco Group, plc. In North America, Serco's 9,000+ employees strive to make an impact every day across 100+ sites in the areas of Defense, Citizen Services, and Transportation. We help our clients deliver vital services more efficiently while increasing the satisfaction of their end customers. Serco serves every branch of the U.S. military, numerous U.S. Federal civilian agencies, the Intelligence Community, the Canadian government, state, provincial and local governments, and commercial clients. While your place may look a little different depending on your role, we know you will find yours here. Wherever you work and whatever you do, we invite you to discover your place in our world. Serco is a place you can count on and where you can make an impact because every contribution matters.
To review Serco benefits please visit: ************************************************ . If you require an accommodation with the application process please email: ******************** or call the HR Service Desk at ************, option 1. Please note, due to EEOC/OFCCP compliance, Serco is unable to accept resumes by email.
Candidates may be asked to present proof of identify during the selection process. If requested, this will require presentation of a government-issued I.D. (with photo) with name and address that match the information entered on the application. Serco will not take possession of or retain/store the information provided as proof of identity. For more information on how Serco uses your information, please see our Applicant Privacy Policy and Notice.
Serco does not accept unsolicited resumes through or from search firms or staffing agencies without being a contracted approved vendor. All unsolicited resumes will be considered the property of Serco and will not be obligated to pay a placement or contract fee. If you are interested in becoming an approved vendor at Serco, please email ********************* .
Serco is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.
**Pay Transparency**
Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.
Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities.
Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):
+ Medical, dental, and vision insurance
+ Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
+ 401(k) plan that includes employer matching funds
+ Tuition reimbursement program
+ Life insurance and disability coverage
+ Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
+ Birth, adoption, parental leave benefits
+ Employee Assistance Plan
To review all Serco benefits please visit: ******************************************* .
Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: ******************** .
$67.9k-113.1k yearly Easy Apply 4d ago
Security Engineer Sr - C
Telos 4.6
Security architect job in Virginia Beach, VA
The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security.
Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. Our employees enjoy more than just a great work environment!
This position is contingent on contract award.
This position will be based at Virginia Beach, VA.
Responsibilities:
The Engineer, Cybersecurity II provides advanced cybersecurity engineering support across Navy systems under the Naval Surface Warfare Center Dahlgren Division (NSWCDD). This role integrates cybersecurity requirements throughout the systems engineering lifecycle, supporting both afloat and ashore networks. The position contributes to system design, risk management, and cyber resilience initiatives aligned with DoD and NAVSEA standards.
Cyber Engineering and Analysis:
Conduct system and software engineering analyses to ensure compliance with cybersecurity standards and best practices.
Support Risk Management Framework (RMF) activities by developing and maintaining technical artifacts, assessment documentation, and ATO packages.
Review and support the implementation of Security Technical Implementation Guides (STIGs) and vulnerability remediation processes.
Perform configuration management of cybersecurity baselines, ensuring changes to system design maintain compliance with RMF and NIST SP 800-53 controls.
Apply system hardening techniques and zero-trust security principles across operating systems, applications, and network devices.
Analyze and support interconnection security agreements (ISAs) and ensure compliance within approved Authorization boundaries.
Utilize and support cybersecurity assessment tools including ACAS, STIG Viewer, eMASS, and Security Compliance Checker.
System Life-Cycle Security:
Participate in the design and implementation of secure systems architecture, providing cybersecurity engineering input from concept through sustainment.
Conduct risk and vulnerability assessments for systems undergoing upgrades or changes, including penetration and regression testing.
Support secure coding practices and software assurance reviews to detect and mitigate exploitable flaws.
Contribute to development and documentation of cybersecurity procedures, security plans, and network diagrams.
Assist in hardware and software patch management, version control, and baseline integrity monitoring.
Operations & Maintenance
Provide system administration support for Windows, Linux, and network environments, ensuring cybersecurity compliance.
Execute cybersecurity best practices during lab and field operations, including monitoring, incident response coordination, and risk reporting.
Maintain technical documentation, POA&Ms, and audit trails in support of cybersecurity posture tracking.
Requirements
Qualifications:
Education: Bachelor's degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information System,
Information Technology, Computer, Electrical, or Electronics Engineering, Software Engineering, Computer
Science, Mathematics with a concentration in Computer Science, or equivalent to above disciplines.
Certification:
• DoD 8570.01-M in accordance with (IAW) DFARS ************ Baseline Certification,
minimum IAT Level II.
Experience:
Five (5) year of full-time professional experience performing system hardening with demonstrated
experience in the following areas: Experience supporting Navy, NAVSEA, or DoD cybersecurity programs.
Proficiency with DISA STIGs, eMASS, ACAS, Nessus, and RMF documentation.
Knowledge of system hardening, zero-trust frameworks, and cross-domain security solutions.
Working knowledge of NIST SP 800-37, 800-53, and 800-160 cybersecurity engineering standards.
Hands-on experience with Windows Server, Linux, and network device administration.
Strong technical writing and documentation skills for cybersecurity deliverables (CDRLs, POA&Ms, risk assessments, etc.).
Desired Attributes:
Detail-oriented with a systems-thinking approach to cybersecurity.
Strong communication and collaboration skills to work across engineering and program teams.
Demonstrated ability to balance mission assurance, security compliance, and system performance.
The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship.
Telos maintains a drug-free workplace and will conduct drug testing on all applicants who have accepted an offer of employment.
Telos Corporation participates in the E-Verify program. Therefore, any employment with Telos will also be contingent upon confirmation from the Social Security Administration ("SSA") and/or the Department of Homeland Security ("DHS") of your authorization to work in the United States. Telos offers excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future.
Telos Corporation and its subsidiaries are committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. Telos Corporation will make reasonable accommodations for known physical or mental limitations of otherwise qualified employees and applicants with disabilities unless the accommodation would impose an undue hardship on the operation of our business. If you are interested in applying for an employment opportunity and feel you need a reasonable accommodation pursuant to the ADA, please contact us at **************. If you require relay service assistance, please click on the following link to review information on your state's relay service: **********************************
Telos Corporation is an EEO/AA employer.
$90k-123k yearly est. 60d+ ago
Cyber Network Defense Analyst
Spectrum Comm Inc. 4.2
Security architect job in Hampton, VA
We're seeking a Cyber Network Defense Analyst (CND) to support the Intelligence, Surveillance, Reconnaissance (ISR) Wing Security Office and the Distributed Common Ground System (DCGS) Processing, Exploitation, Dissemination (PED) Operations Center (DPOC).
Job Responsibilities:
Performs forensic analysis of digital information and gathers and handles evidence.
Identifies network computer intrusion evidence and perpetrators.
Investigates computer fraud or other electronic crimes, crack files and system passwords, detects steganography and recovers deleted, fragmented and corrupted data from digital media of all types.
Ensures chain of custody and control procedures, documents procedures and findings in a manner suitable for courtroom presentation and prepares comprehensive written notes and reports.
May be required to testify in court as expert witnesses.
Required Skills and Experience:
BA/BS
3+ years of network operations experience
Active TS/SCI
CompTIA Security+
CompTIA Cybersecurity Analyst (CYSA)
Shift work required
Preferred Skills and Experience:
Working knowledge of AF DCGS and AF ISR operations is desired
Spectrum is proud of our diverse workforce and diligently committed to remaining an Equal Opportunity Employer. Spectrum governs all employment related decisions without regard to an individual's race, color, sex, religion, national origin, age, disability, veteran status or any other protected classification.
[EEO/AA/Protected Veterans/Individuals with Disability employer].
Work schedule: 10-hour rotational shift work. Rotations are quarterly between day and mid shifts and monthly between weekday and weekend shifts.
$84k-121k yearly est. Auto-Apply 60d+ ago
Data Security Analyst, Intermediate
Looper Consulting, LLC
Security architect job in Norfolk, VA
Job DescriptionDescription:
Job Title: Data Security Analyst, Intermediate
Company: Trimitron Corporation Position Type: Full-Time Equivalent (FTE)
Trimitron Corp is seeking an experienced Data Security Analyst (Intermediate) to provide cybersecurity, data protection, and information assurance support to the Naval Information Warfare Center (NIWC) Pacific's Positioning, Navigation, and Timing (PNT) Division. This role plays a critical part in safeguarding sensitive PNT-related data, ensuring compliance with Navy and DoD cybersecurity standards, and supporting mission-critical research, engineering, and operational activities.
The ideal candidate brings strong analytical skills, deep knowledge of data security principles, and experience working in complex technical environments where data integrity and confidentiality are paramount
Key Responsibilities:
Develop, refine, and implement data security requirements to protect sensitive and mission-critical information.
Determine what data can be safely stored in vulnerable or distributed environments, applying risk-based decision-making.
Design and document data protection procedures that account for system capacity, performance limitations, and operational constraints.
Analyze data flows and information structures to create sensitivity-based data segregation protocols, ensuring only authorized individuals or processes can access high-security information.
Conduct quality assurance evaluations of data security controls, identifying gaps and recommending improvements.
Assess vulnerabilities related to malware, cyberattacks, unauthorized access, and internal misuse.
Review and validate data access rules for departments, managers, and technical teams.
Analyze access footprints, including user behavior, access times, and access locations, to identify anomalies or potential security risks.
Support NIWC Pacific's PNT Division by ensuring secure handling, storage, and transmission of PNT-related data, models, and technical artifacts.
Collaborate with PNT engineers, program managers, and cybersecurity personnel to ensure data security requirements align with Navy and DoD cybersecurity frameworks.
Assist in developing and maintaining PNT-specific data protection protocols, ensuring compliance with mission, operational, and classification requirements.
Provide data security insights during PNT program reviews, technical discussions, and risk assessments.
Support incident response activities related to PNT data systems, including analysis, documentation, and remediation recommendations.
Required Qualifications:
Six (6) years of directly applicable experience in data security, cybersecurity, or information assurance.
Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or a related field.
An advanced degree may substitute for two years of experience.
Strong understanding of data classification, access control, vulnerability assessment, and cybersecurity best practices.
Experience analyzing data structures, access logs, and system behaviors to identify risks or anomalies.
Ability to design and document technical procedures and data protection protocols.
Strong analytical, problem-solving, and communication skills.
Preferred Qualifications:
Experience supporting DoD, Navy, or NIWC programs, especially in research, engineering, or operational environments.
Familiarity with cybersecurity frameworks such as RMF, NIST 800-53, DoD 8500-series, or Navy cybersecurity policies.
Experience supporting mission-critical or high-sensitivity data environments.
Ability to collaborate with multidisciplinary teams, including engineers, analysts, and program leadership.
Why Join Trimitron Corp.?
This position offers the opportunity to contribute to mission-critical defense projects, work alongside highly skilled professionals, and engage in challenging systems engineering tasks that directly impact national security operations.
Benefits: We offer competitive pay and generous benefits including comprehensive medical insurance package, 401k with company match, employee assistance program and company paid benefits.
Requirements:
$70k-101k yearly est. 16d ago
Cyber Security Architect
Caci International 4.4
Security architect job in Norfolk, VA
Cyber SecurityArchitectJob Category: Information TechnologyTime Type: Full time Minimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Continental US* * *
The Opportunity:
Join CACI as the prime contractor on a growing program supporting NAVSEA 03D3 Digital Program Office as a Cyber SecurityArchitect supporting the Navy Maintenance and Modernization Enterprise Solution (NMMES), a mission-critical program that supports over 45,000 users executing naval ship and submarine maintenance operations worldwide.
Key Responsibilities:
Perform specialized technology tasks related to Information Assurance requirements
Conduct security assessments and provide security consulting services
Analyze information security requirements for complex systems
Apply DoD and DoN Information Assurance rules and regulations
Design, develop, and implement solutions to Multilevel Security (MLS) requirements
Gather and organize technical information about organizational mission goals, needs, and security products
Perform risk analyses and assessments
Provide technical support for secure software development and integration tasks
Review work products for correctness and adherence to security standards
Work with Security/IA products such as PKI, VPN, firewalls, and intrusion detection systems
Analyze and recommend security/IA solutions based on product knowledge and limitations
Support both legacy and modern application security requirements
Qualifications:
Required:
Bachelor's Degree in Computer Science, Information Security, or related field
Up to 3 years of experience in cybersecurity or related area
Knowledge of DoD and DoN Information Assurance rules and regulations
Understanding of security technologies and frameworks
Experience with security assessment and risk analysis
Desired:
Security certifications (e.g., Security+, CISSP, CEH)
Experience with DoD/Navy programs or similar government IT systems
Knowledge of FedRAMP and DISA security requirements
Familiarity with Risk Management Framework (RMF)
Experience with security tools and technologies
Understanding of cloud security principles
Knowledge of secure development practices
SAFe certification
Specific labor category determined by years of experience + educational degrees as stated below:
Cyber SecurityArchitect I - Bachelors degree and 3+ years of experience in Cyber Security or related area.
Cyber SecurityArchitect II - Bachelors degree and 5+ years of experience in Cyber Securityarchitecture.
Additional Information:
This position offers an opportunity to protect critical Navy maintenance systems and data. The ideal candidate will combine strong technical security skills with an understanding of DoD security requirements and regulations.
Success in this role requires:
Strong understanding of cybersecurity principles
Knowledge of DoD security requirements
Analytical and problem-solving skills
Attention to detail
Good documentation abilities
Effective communication skills
Note: Position supports NMMES software suite which includes both legacy software applications and current web application technologies running on multiple operating systems. Must be comfortable working with diverse technology stacks and security requirements.
Key Success Factors:
Understanding of securityarchitecture principles
Knowledge of security assessment methodologies
Familiarity with security tools and technologies
Understanding of compliance requirements
Ability to perform risk assessments
Knowledge of secure development practices
The role requires someone who can:
Assess security requirements
Implement security solutions
Conduct risk analyses
Support secure development
Document securityarchitectures
Stay current with security threats and solutions
Work effectively with development and operations teams
Special Requirements:
Must be able to obtain and maintain required security clearances
Must understand and comply with DoD security policies and procedures
Must maintain knowledge of current security threats and mitigation strategies
Must be able to work in a classified environment when required
This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI.
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
________________________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here.
The proposed salary range for this position is:
$53,100-$106,300
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
$53.1k-106.3k yearly Auto-Apply 21d ago
SOC Cyber Defense Analyst - SME (Journeyman)
Akira Technologies Inc. 4.1
Security architect job in Norfolk, VA
Akira Technologies is seeking a SOC Cyber Defense Analyst (SME / Journeyman) to support a government client in Norfolk, VA. This role provides hands-on cybersecurity monitoring, incident response, and forensic analysis across Operational Technology (OT), Industrial Control Systems (ICS), and enterprise network environments, including on-premises and cloud systems.
The ideal candidate has 5-7 years of cybersecurity operations experience, operates independently on complex incidents, and serves as a technical subject matter expert within the SOC while supporting and mentoring junior analysts.
This is an onsite position supporting NAVFAC in Norfolk, VA. This role requires Top Secret or higher clearance.
Key Responsibilities
Perform cyber defense monitoring and forensic analysis across host and network systems, including malware triage, log correlation, and timeline reconstruction.
Investigate security incidents using MITRE ATT&CK and Cyber Kill Chain methodologies.
Support containment, eradication, and recovery actions in accordance with established incident response procedures.
Serve as a journeyman-level SME, providing technical guidance and mentoring to junior SOC analysts.
Monitor, tune, and enhance SIEM platforms (e.g., Splunk Enterprise Security, Elastic SIEM, Cribl) to improve detection and threat visibility.
Develop and maintain SIEM correlation rules, dashboards, and continuous monitoring content using data models and tstats.
Evaluate system and network configurations for vulnerabilities and recommend remediation aligned with DoD cybersecurity standards.
Support STIG compliance activities and assist with Information Assurance Vulnerability Management (IVAM) actions.
Utilize asset mapping and inventory tools to validate authorized devices and identify unauthorized or anomalous systems.
Handle digital evidence in accordance with government forensic and chain-of-custody best practices.
Produce concise technical and executive-level reports detailing findings, impacts, and mitigation recommendations.
Collaborate with SOC leadership and government stakeholders to improve SOC workflows, threat hunting, and operational effectiveness.
Required Qualifications
Active Top Secret clearance (or higher).
5-7 years of experience in cybersecurity operations, SOC analysis, or incident response.
Strong knowledge of Windows and Linux operating systems, network traffic analysis, and security monitoring.
Experience working within DoD cybersecurity frameworks and compliance-driven environments.
Hands-on experience with tools such as Splunk (Enterprise Security preferred), Palo Alto, Elastic SIEM, Cribl, Nessus, CrowdStrike, VMware, or similar technologies.
Demonstrated ability to independently lead investigations and communicate findings to technical and non-technical audiences.
Preferred Qualifications
Experience supporting OT / ICS / SCADA environments.
Advanced Splunk Enterprise Security content development experience.
Familiarity with GrayNoise, Shodan, MODBus, PCAP analysis, or industrial protocols.
Relevant certifications such as GCIH, CEH, GCED, OSCP, CISSP, or equivalent.
Leveling Summary
Performs independently on complex incidents.
Acts as a technical SME within the SOC.
Mentors junior analysts without formal program or SOC ownership.
Escalates advanced or strategic issues to senior or lead analysts.
Salary Range: $125,000 - $140,000
Akira's pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
General Description of Benefits
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental plans, and vision coverage, and a 401(k) plan with employer match. To promote work/life balance, Akira offers paid time off, including vacation and sick time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave. We also offer short and long-term disability benefits to protect employee income in the event of sickness or injury, life insurance, accidental death and dismemberment insurance, and critical illness insurance. Akira also offers tuition, training, and certification reimbursement for professional development and career advancement.
Akira regularly reviews our total rewards package to ensure our offerings remain competitive and reflect the values and needs expressed by our employees.
About Akira Technologies
Akira strives to meet and exceed the mission and objectives of US federal agencies. As a leading small business cloud modernization and data analytics services provider, we deliver trusted and highly differentiated solutions and technologies that serve the needs of our customers and citizens. Akira serves as a valued partner to essential government agencies across the intelligence, cyber, defense, civilian, and health markets. Every day, our employees deliver transformational outcomes, solving the most daunting challenges facing our customers.
Akira is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
$125k-140k yearly Auto-Apply 33d ago
Executive Advisor -Business Information Security Officer
Elevance Health
Security architect job in Norfolk, VA
**Executive Advisor - Business Information Security Officer** **Location:** This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The **Executive Advisor - Business Information Security Officer** serves as a dedicated security and risk management leadership function aligned to the major business and technology-enabling divisions of Elevance Health. BISOs are embedded security leaders - connecting executive business and innovation leaders, technology professionals, compliance management teams, and the Global Information Security organization.
**How You Will Make an Impact:**
+ Leads Information Security and Risk Management for an assigned Business Unit
+ Leads Information Security and Technology Risk Management for an assigned Business Unit, ensuring alignment with enterprise security strategy, business objectives, and regulatory obligations.
+ Serves as the primary business-facing point of contact for information security and technology risk matters, coordinating enterprise security capabilities and services as needed.
+ Acts as a key leadership contact during incident response activities, ensuring effective business engagement, executive communication, and post-incident remediation.
+ Owns the development and execution of the Business Unit security roadmap, aligned with enterprise priorities, business strategy, and defined risk tolerance.
+ Identifies, prioritizes, and recommends opportunities to reduce risk and improve security outcomes through targeted assessments, continuous monitoring, and metrics-driven analysis.
+ Participates in enterprise planning activities, including vendor and third-party risk assessment, technology platform selection and retirement, securityarchitecture alignment, prioritization, and integration planning.
+ Serves as the Information Security and Technology Risk lead for mergers, acquisitions, and divestitures, including due diligence, integration planning, and risk remediation.
+ Establishes and participates in governance forums to assess, accept, mitigate, or escalate technology risk in alignment with enterprise risk management practices.
+ Provides security leadership for healthcare regulatory and compliance requirements (e.g., HIPAA, HITRUST, state privacy laws), ensuring audit readiness and sustained compliance.
+ Defines, tracks, and reports meaningful security and risk metrics to business and executive stakeholders to support informed decision-making.
+ Acts as a trusted advisor and subject matter expert to executive management, translating technical and cyber risk into clear business and financial impact.
+ Influences business and technology leaders to adopt secure-by-design practices and risk-aware decision-making without direct operational authority.
+ Mentors and develops security and risk management capabilities within the Business Unit and across enterprise teams.
+ Must be capable of providing top-tier support for 6 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) SecurityArchitecture and Design, 11) Telecommunications and Network Security.
**Minimum Requirements:**
Requires BS/BA in Information Technology or related field of study and a minimum of 10 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.
**Preferred Skills, Capabilities & Experiences:**
+ Broad-based experience to plan and design highly complex systems is strongly preferred.
+ Expert knowledge and understanding of industry-accepted data processing controls and concepts strongly preferred as applied to Security Certifications: CISSP preferred and other advanced technical security certifications (e.g. Information Systems SecurityArchitecture Professional, Information Systems Security Engineering Professional, Certification and Accreditation or equivalent certifications).
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
$104k-157k yearly est. 5d ago
Security Engineer Sr - C
Telos Corporation 4.6
Security architect job in Virginia Beach, VA
The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security.
Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. Our employees enjoy more than just a great work environment!
This position is contingent on contract award.
This position will be based at Virginia Beach, VA.
Responsibilities:
The Engineer, Cybersecurity II provides advanced cybersecurity engineering support across Navy systems under the Naval Surface Warfare Center Dahlgren Division (NSWCDD). This role integrates cybersecurity requirements throughout the systems engineering lifecycle, supporting both afloat and ashore networks. The position contributes to system design, risk management, and cyber resilience initiatives aligned with DoD and NAVSEA standards.
Cyber Engineering and Analysis:
* Conduct system and software engineering analyses to ensure compliance with cybersecurity standards and best practices.
* Support Risk Management Framework (RMF) activities by developing and maintaining technical artifacts, assessment documentation, and ATO packages.
* Review and support the implementation of Security Technical Implementation Guides (STIGs) and vulnerability remediation processes.
* Perform configuration management of cybersecurity baselines, ensuring changes to system design maintain compliance with RMF and NIST SP 800-53 controls.
* Apply system hardening techniques and zero-trust security principles across operating systems, applications, and network devices.
* Analyze and support interconnection security agreements (ISAs) and ensure compliance within approved Authorization boundaries.
* Utilize and support cybersecurity assessment tools including ACAS, STIG Viewer, eMASS, and Security Compliance Checker.
System Life-Cycle Security:
* Participate in the design and implementation of secure systems architecture, providing cybersecurity engineering input from concept through sustainment.
* Conduct risk and vulnerability assessments for systems undergoing upgrades or changes, including penetration and regression testing.
* Support secure coding practices and software assurance reviews to detect and mitigate exploitable flaws.
* Contribute to development and documentation of cybersecurity procedures, security plans, and network diagrams.
* Assist in hardware and software patch management, version control, and baseline integrity monitoring.
Operations & Maintenance
* Provide system administration support for Windows, Linux, and network environments, ensuring cybersecurity compliance.
* Execute cybersecurity best practices during lab and field operations, including monitoring, incident response coordination, and risk reporting.
* Maintain technical documentation, POA&Ms, and audit trails in support of cybersecurity posture tracking.
Job Requirements
Qualifications:
Education: Bachelor's degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information System,
Information Technology, Computer, Electrical, or Electronics Engineering, Software Engineering, Computer
Science, Mathematics with a concentration in Computer Science, or equivalent to above disciplines.
Certification:
* DoD 8570.01-M in accordance with (IAW) DFARS ************ Baseline Certification,
minimum IAT Level II.
Experience:
* Five (5) year of full-time professional experience performing system hardening with demonstrated
* experience in the following areas: Experience supporting Navy, NAVSEA, or DoD cybersecurity programs.
* Proficiency with DISA STIGs, eMASS, ACAS, Nessus, and RMF documentation.
* Knowledge of system hardening, zero-trust frameworks, and cross-domain security solutions.
* Working knowledge of NIST SP 800-37, 800-53, and 800-160 cybersecurity engineering standards.
* Hands-on experience with Windows Server, Linux, and network device administration.
* Strong technical writing and documentation skills for cybersecurity deliverables (CDRLs, POA&Ms, risk assessments, etc.).
Desired Attributes:
* Detail-oriented with a systems-thinking approach to cybersecurity.
* Strong communication and collaboration skills to work across engineering and program teams.
* Demonstrated ability to balance mission assurance, security compliance, and system performance.
The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship.
Telos maintains a drug-free workplace and will conduct drug testing on all applicants who have accepted an offer of employment.
Telos Corporation participates in the E-Verify program. Therefore, any employment with Telos will also be contingent upon confirmation from the Social Security Administration ("SSA") and/or the Department of Homeland Security ("DHS") of your authorization to work in the United States. Telos offers excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future.
Telos Corporation and its subsidiaries are committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. Telos Corporation will make reasonable accommodations for known physical or mental limitations of otherwise qualified employees and applicants with disabilities unless the accommodation would impose an undue hardship on the operation of our business. If you are interested in applying for an employment opportunity and feel you need a reasonable accommodation pursuant to the ADA, please contact us at **************. If you require relay service assistance, please click on the following link to review information on your state's relay service: **********************************
Telos Corporation is an EEO/AA employer.
Job Type
Full-Time
Location
Virginia Beach, VA 23461 US (Primary)
Telos offers an excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos and its subsidiaries are an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
$90k-123k yearly est. 60d+ ago
Security Engineer - Virginia Beach, VA
Serco 4.2
Security architect job in Newport News, VA
Arlington, Virginia, US Hampton, Virginia, US Newport News, Virginia, US Crystal City, Virginia, US Panama City Beach, Florida, US Virginia Beach, Virginia, US Engineering 12247 Full-Time Yes - May Consider Occasional/Part Time Teleworking for this position $67889.77 - $113149.62
**Position Description & Qualifications**
**Position Description & Qualifications**
If you love high profile and challenging programing projects supporting the United States Navy - Serco has a great opportunity for you! This Information Security Test Engineer will be on a dynamic team responsible for testing afloat and shore based systems at our offices in Virginia Beach, VA, Panama City Beach FL, or Washington DC. Bring your expertise and collaborative skills to make an impact towards our national security homeland defense.
**This position is contingent upon your ability to maintain/transfer your Secret clearance.**
Serco supports the US Navy in the acquisition of new technology used to defend our nation. Our team reviews acquisition documentation, develops cyber test plans, executes cyber test events, collects, and analyzes data and writes test reports.You will be part of a team that works closely with the customers and other Serco teams to deliver cyber-secure systems to the Navy. The team has been supporting Cybersecurity Assessment and Authorization for over 15 years and has been recognized by the Navy for their outstanding contributions.
In this role, you will:
+ Perform activities necessary for system Assessment and Authorization
+ Support the program office in creating/gathering necessary artifacts necessary to support an Authorization decision.
+ Perform both manual and automated cybersecurity testing of systems and components.
+ Document test results and provide preliminary risk assessment to the Program Manager.
+ Provide weekly status updates for systems under your purview.
+ Supports development of Cyber Test Plan for executes test events, collects, and analyzes data, and provides a report on the results.
+ Create/ update Cybersecurity policies and procedures.
+ Works directly with senior technical personnel, stakeholders, and project managers in the planning and execution of test events.
To be successful in this role, you will have:
+ Bachelor's degree and 3 years of experience
+ An Associates degree and 5 years of experience.
+ Active DoD Secret Security Clearance.
+ A Cybersecurity certification. (i.e. CompTIA Security+ CE or higher-level certification)
+ Proficiency in technical writing.
+ Proficiency with MS-Office software to include MS Word, MS Excel, MS Power Point.
+ The ability to travel up to 25%.
Additional desired experience and skills:
+ Previous experience with DoD Risk Management Framework.
+ NQV (Navy Qualifier Validator) certification.
If you are interested in supporting and working with our military and sailors and a passionate Serco team- then submit your application now for immediate consideration. It only takes a few minutes and could change your career!
**Company Overview**
Serco Inc. (Serco) is the Americas division of Serco Group, plc. In North America, Serco's 9,000+ employees strive to make an impact every day across 100+ sites in the areas of Defense, Citizen Services, and Transportation. We help our clients deliver vital services more efficiently while increasing the satisfaction of their end customers. Serco serves every branch of the U.S. military, numerous U.S. Federal civilian agencies, the Intelligence Community, the Canadian government, state, provincial and local governments, and commercial clients. While your place may look a little different depending on your role, we know you will find yours here. Wherever you work and whatever you do, we invite you to discover your place in our world. Serco is a place you can count on and where you can make an impact because every contribution matters.
To review Serco benefits please visit: ************************************************ . If you require an accommodation with the application process please email: ******************** or call the HR Service Desk at ************, option 1. Please note, due to EEOC/OFCCP compliance, Serco is unable to accept resumes by email.
Candidates may be asked to present proof of identify during the selection process. If requested, this will require presentation of a government-issued I.D. (with photo) with name and address that match the information entered on the application. Serco will not take possession of or retain/store the information provided as proof of identity. For more information on how Serco uses your information, please see our Applicant Privacy Policy and Notice.
Serco does not accept unsolicited resumes through or from search firms or staffing agencies without being a contracted approved vendor. All unsolicited resumes will be considered the property of Serco and will not be obligated to pay a placement or contract fee. If you are interested in becoming an approved vendor at Serco, please email ********************* .
Serco is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.
**Pay Transparency**
Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.
Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities.
Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):
+ Medical, dental, and vision insurance
+ Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
+ 401(k) plan that includes employer matching funds
+ Tuition reimbursement program
+ Life insurance and disability coverage
+ Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
+ Birth, adoption, parental leave benefits
+ Employee Assistance Plan
To review all Serco benefits please visit: ******************************************* .
Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: ******************** .
How much does a security architect earn in Portsmouth, VA?
The average security architect in Portsmouth, VA earns between $86,000 and $181,000 annually. This compares to the national average security architect range of $92,000 to $179,000.
Average security architect salary in Portsmouth, VA
$125,000
What are the biggest employers of Security Architects in Portsmouth, VA?
The biggest employers of Security Architects in Portsmouth, VA are: