SteerBridge
Security Architect - Aviation
Employment
Full-timeFrom the employer
Full-time
Level
Not statedTeam
Tech Team / AviationCountry assessment
Not doable from Austria because the employer's own board marks it as not remote.
Our assessment is guidance. Confirm arrangements with the employer.
Skills mentioned in this posting
Job description
Position Overview
SteerBridge is seeking a Security Architect to define the security architecture and compliance strategy for a mission-critical Defense Aviation platform running in AWS GovCloud for federal customers. This role owns the security blueprint—controls, identity, zero-trust access, monitoring, and authorization strategy—for environments supporting federal aviation operations.
The architect will work directly with solutions architects, security and cloud engineers, data teams, and stakeholders to translate DoD security requirements into enforceable, well-architected designs and to guide the platform toward and through authorization (ATO).
This role stays close to implementation. The ideal candidate sets security standards, designs control frameworks, reviews architectures, and guides engineers in implementing defense-in-depth and zero-trust access.
This is a hybrid position based in Vienna, VA.
Key Responsibilities
-
Define and maintain security architecture for AWS GovCloud workloads, including identity, zero-trust access, network segmentation, encryption, monitoring, and data protection.
-
Design and own zero-trust access architecture using Zscaler (ZTNA/SASE) and establish standards for least-privilege IAM, secure access, and hardened baselines.
-
Design defense-in-depth security frameworks and ensure alignment with DoD and DISA requirements, including DoDI 8510, CNSSI 1253, STIGs, DoD CC SRG, and ATO processes.
-
Develop security architecture documentation, control mappings, decision records, implementation strategies, and evidence required to support audits and assessments.
-
Review architectures and designs to embed security from the outset and lead security and threat-model reviews.
-
Guide engineering teams in implementing security controls, detection and response capabilities, remediation activities, and POA&M priorities.
-
Partner with cloud and solutions architects to develop secure-by-design platforms and establish reusable security standards and reference patterns.
-
Assess and communicate security posture, risks, and trade-offs to technical and non-technical stakeholders, advise leadership on security strategy, and mentor engineers to strengthen security practices.
Required Qualifications
-
Eligibility requirements: U.S. citizenship is required for this position under applicable federal contract requirements. Candidates must also be able to obtain and maintain the security clearance required for the role.
-
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or a related field.
-
10+ years of security experience, including 3+ years in a security architecture or lead role, with experience leading security initiatives across multidisciplinary teams.
-
Deep expertise in AWS cloud security architecture, identity, network segmentation, and zero-trust design, including experience with Zscaler or a comparable ZTNA/SASE platform.
-
Strong knowledge of DoD security frameworks and authorization requirements, including DoDI 8510, CNSSI 1253, STIGs, DoD CC SRG, and experience guiding systems through ATO and authorization processes.
-
Demonstrated ability to translate operational requirements into security controls and design resilient, defense-in-depth architectures using least-privilege principles, network security concepts, firewalls, demilitarized zones, encryption, and other cybersecurity methods.
-
Ability to develop and maintain security architectures aligned with organizational objectives, assess the impact of changing operational conditions, and produce clear architecture documentation and risk assessments.
-
One or more of the following certifications: CISSP, CISM, CCNP Enterprise, GCIA, GDSA, GICSP, ISSAP, or ISSEP.
Preferred Qualifications
-
Master’s or PhD in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or a related field.
-
Extensive experience with AWS GovCloud or other federal or highly regulated environments.
-
Advanced experience architecting Zscaler or comparable ZTNA/SASE solutions and integrating them with identity and conditional access.
-
Experience with continuous monitoring, SIEM strategy, incident response programs, and data security for analytics and Medallion architectures.
-
Senior-level certifications such as CCSP or AWS Certified Security – Specialty, and/or experience supporting aviation, defense, logistics, or fleet management systems.