Lead Infrastructure and Cybersecurity Architect
Caliola Engineering, LLC · Colorado Springs, CO · 1 mo ago
Engineering$150k–$185k/yrFull-time
About the role
Ciola is seeking a Lead Infrastructure and Cybersecurity Architect to support the design, modernization, security, and governance of our internal infrastructure, enterprise networks, cloud environments, and regulated systems.
Responsibilities
- Design, build, and maintain secure, resilient, and scalable core infrastructure across on-premises, cloud, hybrid, and multi-site environments.
- Drive modernization initiatives including cloud integration, virtualization, software-defined networking, LAN/WAN, SD-WAN, VPN, network segmentation, and Infrastructure as Code automation.
- Evaluate, integrate, and govern enterprise network technologies, including routers, switches, firewalls, IDS/IPS, NAC, load balancing, encryption, wireless, and secure connectivity solutions.
- Implement, configure, tune, and improve security monitoring technologies, including endpoint protection, SIEM/SOAR, Microsoft Defender, Microsoft Sentinel, logging, alerting, dashboards, and incident-response integrations.
- Architect, administer, and support Microsoft GCC High, Azure Government, and hybrid commercial cloud environments in accordance with federal security requirements.
- Govern foundational systems, backup environments, identity, endpoint, collaboration, monitoring, and data protection capabilities.
- Implement and govern secure cloud and hybrid architectures using Microsoft Entra ID, Conditional Access, MFA/PIM, Intune, Purview, AvePoint, and related tools to support resource protection, access control, monitoring, and compliance.
- Secure and harden foundational IT components, including software development environments, databases, endpoints, servers, cloud resources, and network devices by applying DISA STIGs, configuration baselines, vulnerability remediation, and risk mitigation strategies.
- Provide hands-on technical support during security incidents, including investigation, containment, remediation, recovery, documentation, and follow-up hardening.
- Secure and harden foundational IT components, including software development environments, databases, endpoints, servers, cloud resources, and network devices by applying DISA STIGs, configuration baselines, vulnerability remediation, and risk mitigation strategies.
- Support internal assessments, remediation planning, customer reviews, and external C3PAO assessments.
- Develop and maintain compliance and engineering artifacts, including System Security Plans, POA&Ms, configuration management documentation, HLDs/LLDs, network diagrams, technical standards, implementation plans, incident response procedures, and security control evidence.
- Participate in architecture reviews, risk assessments, vendor evaluations, change management, and IT Configuration Control Board activities.
- Prepare and maintain technical roadmaps and standards for infrastructure, cybersecurity tooling, cloud architecture, network modernization, endpoint management, disaster recovery, secure AI adoption, and compliance sustainment.
- Provide technical guidance and mentorship to engineering and technical staff to build organization-wide capability in secure design, cloud operations, infrastructure engineering, and cybersecurity practices.
- Evaluate emerging technologies, threats, and industry trends to guide strategic upgrades while balancing long-term architecture goals with operational needs.
Requirements
- Active Secret Clearance
- Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field, or equivalent professional experience.
- 10+ years of progressive experience in enterprise infrastructure architecture, network engineering, cybersecurity architecture, cloud security, systems architecture, or related technical roles.
- Experience supporting DoD, Federal Government, defense contractor, or similarly regulated environments.
- Advanced knowledge of enterprise network and infrastructure architecture, including routing, switching, firewalls, VPNs, wireless, VLANs, network segmentation, secure connectivity, and high availability / disaster recovery architectures.
- Experience designing, administering, or supporting Microsoft GCC High, Azure Government, or comparable secure cloud, identity, endpoint, collaboration, monitoring, or data protection environments.
- Strong working familiarity with CMMC Level 2, NIST SP 800-171, RMF, DFARS cybersecurity requirements, DISA STIGs, and related DoD cybersecurity expectations.
- Hands-on experience with security hardening, vulnerability management, vulnerability remediation, configuration baselines, endpoint protection, access control, logging, SIEM/security monitoring, and incident response support, including Microsoft Sentinel or comparable platforms.
- Ability to translate business, program, compliance, engineering and emerging technology needs into secure technical architecture, implementation plans, and operational documentation.
- Ability to mentor technical teammates, collaborate effectively across engineering, cybersecurity, compliance, facilities, and program teams, and influence outcomes without direct management authority.
Qualifications
- Relevant certifications such as CISSP, CISM, CCNP, CCIE, Microsoft Cybersecurity Architect Expert, Microsoft Azure Solutions Architect Expert, Certified CMMC Professional, Security+, Network+, or SANS/GIAC.
Skills
- Exceptional written and verbal English communication skills.
- Ability to multitask across multiple programs, manage competing priorities, and maintain high focus in a fast-paced environment.
- Ability to navigate an office or server room setting, including prolonged periods at a workstation.
- Ability to bend, kneel, crouch, or reach to install, inspect, or maintain IT hardware, server racks, and cabling.
- Close visual acuity required for analyzing data, engineering diagrams, and extensive reading.
- Fine motor skills and dexterity to manipulate small technical devices and components.
- Ability to occasionally lift, move, and set up infrastructure equipment weighing up to 35 lbs.
Benefits
Caliola offers a competitive compensation structure designed to support long-term growth, including annualized salary range of $150,000 – $185,000 commensurate with experience, flexible PTO, subsidized health insurance, 401(k) matching, and professional development opportunities.
Pay
Annualized Salary Range: $150,000 – $185,000 commensurate with experience.
Schedule
Type and Schedule: Full-Time, Salary/Exempt, on-site in Colorado Springs, CO.