Security Architect - Aviation
Job description
About the role
The is responsible for owning the end-to-end security strategy and architecture for a critical Defense Aviation platform operating within the AWS GovCloud environment. This role defines the foundational security controls, identity management, and zero-trust access models that protect federal aviation operations. The position requires a deep partnership with solutions architects and engineering teams to ensure security is designed into the architecture from the outset, not added as an afterthought. You will translate complex DoD security requirements and regulatory mandates into practical, enforceable designs that align with established control frameworks. The architect will guide the platform through the rigorous authorization process, supporting efforts to achieve and maintain ATO readiness. This role sets the standards and guardrails that ensure defense-in-depth principles are applied consistently across all system components. You will own the security blueprint, influencing technical decisions that impact resilience, compliance, and operational continuity. The position is pivotal in bridging the gap between high-level security policies and the detailed implementation by engineering teams.
Key facts
What you'll do
Define and document the comprehensive security architecture for a Defense Aviation platform hosted in AWS GovCloud, ensuring alignment with federal mission requirements.
Develop and maintain a robust security blueprint that encompasses controls, identity, zero-trust access, monitoring strategies, and authorization mechanisms specific to aviation operations.
Collaborate closely with solutions architects and security engineers to translate DoD and federal security directives into technically sound and implementable designs.
Lead the development of control frameworks and standards that guide the secure configuration and operation of cloud-based systems and services.
Partner with data teams to establish security policies for data classification, handling, and protection throughout the data lifecycle in aviation environments.
Guide the platform through the Authorization to Operate (ATO) process by providing the necessary architectural evidence, risk assessments, and compliance documentation.
Review and assess proposed system designs to identify potential security gaps and recommend mitigations that enforce defense-in-depth principles.
Champion zero-trust access strategies by designing and advocating for identity-centric security models, least-privilege permissions, and continuous verification mechanisms.
Mentor and guide engineers on security best practices, ensuring that secure coding, configuration, and deployment are integral to the development lifecycle.
Monitor the evolving threat landscape and regulatory changes to proactively adjust the security architecture and controls for emerging risks in defense aviation.
Collaborate with stakeholders to prioritize security initiatives based on risk, compliance requirements, and operational impact.
Serve as the primary technical authority on security matters for the aviation platform, providing clear rationale and guidance for architectural decisions.
Ensure that security requirements are traceable through the system development lifecycle, from initial design through implementation and authorization.
Drive the collection and analysis of security telemetry to inform monitoring, detection, and response strategies within the aviation ecosystem.
Requirements
U.S. citizenship is required due to the sensitivity of the defense and aviation workloads handled on this platform.
Candidates must possess a current Top Secret security clearance with the ability to obtain and maintain a TS/SCI clearance.
A minimum of 10 years of progressive experience in IT security or information assurance roles is required, demonstrating a deep understanding of security frameworks and controls.
Experience designing and implementing security architectures for cloud-based platforms, particularly within AWS environments, is mandatory.
Demonstrated expertise with federal security regulations, including but not limited to NIST SP 800-53, is essential for ensuring compliance with government standards.
Proficiency with identity and access management (IAM) concepts and technologies is required, including federation, single sign-on, and privileged access management.
Knowledge of zero-trust architecture principles and implementation strategies is required to guide the platform toward resilient, least-privilege access models.
Experience with cloud security tools and services, such as AWS GuardDuty, AWS Config, and CloudTrail, is required for effective monitoring and governance.
Strong understanding of defense aviation systems and the associated security challenges is required to address the unique requirements of this mission domain.
Nice to have
Experience with FedRAMP and ATO processes is preferred, given the role's responsibilities in supporting authorization activities.
Familiarity with DevSecOps practices and tools is preferred to help integrate security seamlessly into agile development pipelines.
Experience with container security and Kubernetes protection in cloud environments is preferred for modern platform protection.
Knowledge of risk assessment methodologies and security rating services is preferred to support continuous risk monitoring.
Experience with Security Information and Event Management (SIEM) platforms is preferred to enhance monitoring and response capabilities.
Practical notes
This is a hybrid position based in Vienna, VA.
U.S. citizenship and a current Top Secret clearance with the ability to obtain TS/SCI are mandatory due to the nature of the defense aviation work.
Candidates must be able to pass a background investigation in support of the clearance requirement.
The role requires close collaboration with federal clients and government stakeholders, demanding strong communication and professional skills.
Travel may be required to support federal customer needs, and candidates should be prepared to engage on-site when necessary.
The position involves significant responsibility for the security and compliance of a critical aviation platform, requiring a proactive and detail-oriented approach.