Job Description
Cloud Security Architect
Location Washington, DC
Duration: Long Term
Type: Contract
Job Description
• Develop and implement strategies and policies related to cloud security, risk management and compliance for enterprise-wide projects.
• Consult on project teams dealing with significant risk, security, and compliance issues.
• Lead the development of risk management, security, and compliance plans for projects.
• Conduct risk, security, and compliance audits and assessments.
• Monitor emerging trends in IT security, risk management and compliance.
• Establish and maintain a framework for internal controls and processes.
• Design controls, standards and key risk and performance indicators.
• Educate colleagues in the area of expertise and develop awareness and compliance training programs.
• Administer tools related to their area of expertise.
• Provide guidance to project teams on security, risk management, and compliance issues.
• Lead programs to enhance security, compliance, and risk awareness across the organization.
• Develop innovative solutions and contribute new insights to resolve complex problems.
• Participate in the evaluation of emerging technologies in the information systems industry.
• Provide guidance on application security, risk assessment, and data protection based on data sensitivity and associated business risks.
• Implement robust security practices and protocols to ensure the protection and integrity of APIs.
• Guide project team in remediating common application vulnerabilities.
Required Skills/Abilities
• Extensive knowledge of IT, enterprise architecture, software development life cycle, and information security platforms and applications.
• Hands-on experience with Infrastructure as Code (IaaC).
• Knowledge of Artificial Intelligence, Machine Learning, and Generative AI.
• Strong experience in API security.
• Excellent written and verbal communication skills.
• Understanding of security protocols, cryptography, authentication, and authorization.
• Understanding of DevSecOps, Infrastructure-as-Code, Policy-as-code.
• Knowledge of standards for enterprise security architecture.
• Knowledge of common web vulnerabilities as per SANS 25 or OWASP Top 10 specifications.
• Excellent interpersonal skills and ability to collaborate with senior management stakeholders.
Certification Requirements
• Certified Information Systems Security Professional (CISSP) is a plus.
• GCP, AWS or Microsoft Certified Cloud Solution Architect certification is a plus.
Responsibilities
- Develop and implement strategies and policies related to cloud security, risk management and compliance for enterprise-wide projects
- Consult on project teams dealing with significant risk, security, and compliance issues
- Lead the development of risk management, security, and compliance plans for projects
- Conduct risk, security, and compliance audits and assessments
- Monitor emerging trends in IT security, risk management and compliance
- Establish and maintain a framework for internal controls and processes
- Design controls, standards and key risk and performance indicators
- Educate colleagues in the area of expertise and develop awareness and compliance training programs
- Administer tools related to their area of expertise
- Provide guidance to project teams on security, risk management, and compliance issues
- Lead programs to enhance security, compliance, and risk awareness across the organization
- Develop innovative solutions and contribute new insights to resolve complex problems
- Participate in the evaluation of emerging technologies in the information systems industry
- Provide guidance on application security, risk assessment, and data protection based on data sensitivity and associated business risks
- Implement robust security practices and protocols to ensure the protection and integrity of APIs
- Guide project team in remediating common application vulnerabilities
Requirements
- Required Skills/Abilities
- Extensive knowledge of IT, enterprise architecture, software development life cycle, and information security platforms and applications
- Hands-on experience with Infrastructure as Code (IaaC)
- Knowledge of Artificial Intelligence, Machine Learning, and Generative AI
- Strong experience in API security
- Excellent written and verbal communication skills
- Understanding of security protocols, cryptography, authentication, and authorization
- Understanding of DevSecOps, Infrastructure-as-Code, Policy-as-code
- Knowledge of standards for enterprise security architecture
- Knowledge of common web vulnerabilities as per SANS 25 or OWASP Top 10 specifications
- Excellent interpersonal skills and ability to collaborate with senior management stakeholders