Staff Security Architect, Networks
True Anomaly · Long Beach, CA · 3 days ago
On-siteInformation Technology$170k–$245k/yrFull-time
Responsibilities
- Define, design, and deploy terrestrial network architectures for classified capabilities spanning multiple on-premise locations across the U.S., with a focus on IL-6+ environments
- Translate program security and mission requirements into end-to-end IT network architectures that support an array of ongoing classified programs
- Architect and implement endpoint networks connecting on-premise IL-6+ infrastructure across geographically distributed locations
- Lead network authorization activities under NIST SP 800-53, ensuring architectures are designed for compliance from the outset and support efficient ATO achievement and maintenance
- Evaluate, select, and specify network hardware and software in accordance with applicable Approved Products Lists (APLs) and Trade Agreements Act (TAA) compliance requirements
- Architect and define the network interfaces and integration points between classified cloud environments (AWS/Azure IL-6+), USG networks, and end-user physical networks, working in close partnership with cloud engineers to ensure consistent security posture, control inheritance, and seamless interoperability across all domains
- Partner with ISSEs, industrial security personnel, cloud engineers, and systems engineers to ensure network designs meet program security, operational, and compliance requirements
- Develop and maintain network architecture documentation including topology diagrams, interface control documents, and system security artifacts required for RMF and ATO activities
- Implement and validate network security controls including boundary protection, segmentation, traffic filtering, and encrypted communications across classification domains
- Identify and remediate network-layer findings from STIGs, vulnerability scans, and SCA activities to maintain ATO posture
- Ensure compliance with NIST 800-53, CNSSI 1253, ICD 503, JSIG, and other applicable frameworks for National Security Systems handling classified information up to TS/SCI
- Stay current on emerging network security technologies, DoD policy changes, and APL updates, advocating for adoption where appropriate
Requirements
- 10+ years of hands-on experience in network engineering or architecture, with deep technical and procedural expertise across the full lifecycle of classified network environments — including requirements definition, hardware acquisition (APL/TAA compliance), design, deployment, and ongoing operations — at classification levels up to and including TS/SCI and special access networks
- Active Top Secret clearance with SCI eligibility required
- DoD 8140 IAT Level III certification (CASP+, CISSP, CISA, or equivalent) required
- Deep expertise in IP networking including routing protocols, switching, VLANs, subnetting, QoS, and network boundary protection
- Strong working knowledge of NIST SP 800-53 authorization regimes and how they apply to network architecture design and documentation
- Experience with DoD Approved Products Lists (APLs) and Trade Agreements Act (TAA) compliance requirements for network hardware and software procurement
- Domain expertise in cloud network design and authorization across AWS and/or Azure classified environments
- Experience supporting RMF processes end-to-end, including network control implementation, assessment preparation, and ATO documentation
- Strong documentation skills, with experience producing network architecture diagrams, topology maps, interface control documents, and SSP contributions
- Excellent communication skills with the ability to articulate complex network requirements and architectural decisions to security teams, program leadership, and government stakeholders
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field (or equivalent experience)