Apply with hirly
Enterprise Architect / Security Engineer - FEMA ITSA
OneGlobe LLC · Washington, DC
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Description What You'll Get To Do as a Enterprise Architect / Security Engineer: We are seeking a senior Enterprise Architect & Security Engineer to evaluate how a federal agency's IT systems align to mission, enterprise architecture, and cybersecurity requirements. You will assess authorization and security posture, hosting and technical environments, mission criticality, and cost, and you will shape modernization recommendations that strengthen security and reduce sustainment risk. The role combines enterprise architecture judgment with practical federal cybersecurity expertise on an enterprise IT assessment engagement, with opportunities to support follow-on modernization and implementation work.
- Evaluate each system's Authorization to Operate (ATO) status and overall cybersecurity posture using authorized documentation and interviews.
- Review known risks, findings, weaknesses, and POA&Ms, and assess compliance with DHS 4300A, NIST (RMF, SP 800-53), and agency cybersecurity requirements.
- Assess identity, credential, and access management (ICAM), multifactor authentication implementation, and privileged access controls.
- Evaluate logging and monitoring maturity at a high level and identify security risks tied to unsupported technologies or legacy architectures.
- Analyze the cybersecurity implications of each modernization option, including Zero Trust alignment.
- Conduct all work within authorized boundaries. The role does not involve penetration testing or vulnerability exploitation.
- Assess hosting environments, infrastructure models, and platform dependencies against enterprise architecture standards.
- Evaluate scalability, availability, resiliency, environment complexity, and data storage architecture.
- Review backup, continuity, and disaster recovery arrangements and the use of modern development and operations practices.
- Determine whether current environments are suitable for future mission needs and alignment with the target-state architecture.
- Assess each system's mission purpose, the business functions it supports, its system owner, and its user community.
- Evaluate alignment to agency mission priorities, mission criticality, operational dependency, and the consequences of an outage or degradation.
- Characterize user populations and internal and external stakeholder reliance, and capture operational pain points.
- Determine whether each system remains fit for purpose.
- Analyze O&M, DME, licensing, hosting, and contractor support costs, along with cost drivers and trends.
- Identify consolidation and shared-service opportunities and the financial risks of sustaining insecure or legacy systems.
- Contribute security and architecture rationale to disposition recommendations (retain, rehost, replatform, reengineer, replace, consolidate, retire).
- Identify risks, dependencies, complexity, and implementation considerations, and recommend priority and sequencing from a security and EA perspective. Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent experience.
- 15 or more years of progressive IT experience, including enterprise architecture and information security engineering.
- Strong working knowledge of the NIST Risk Management Framework,
Nist Sp
800-53 and 800-37, FISMA, and the federal ATO process.
- Experience assessing ICAM, MFA, privileged access management, and security logging and monitoring in enterprise environments.
- Experience with enterprise architecture frameworks and practices (e.g., TOGAF, FEAF, DoDAF) and with evaluating systems against a target-state architecture.
- Knowledge of cloud security, FedRAMP, and Zero Trust Architecture principles (e.g.,
Nist Sp
800-207, the CISA Zero Trust Maturity Model).
- Excellent analytical, interviewing, and technical writing skills. Preferred Qualifications
- Experience with DHS or DHS component cybersecurity programs, including DHS 4300A.
- Familiarity with OMB Circulars A-130 and A-123, the Privacy Act, and federal privacy and records management requirements.
- Certifications such as CISSP, CISSP-ISSAP, CISM, CCSP, CGEIT, or TOGAF Enterprise Architecture Practitioner.
- Experience supporting mission-critical, continuity, or emergency operations systems. Security and Eligibility Requirements
- Must be a U.S. citizen
- Must be able to obtain and maintain a favorably adjudicated Public Trust suitability determination (Tier 2 or Tier 4, depending on position risk designation) prior to start.
- Must complete required federal security, privacy, and insider threat awareness training within the client's required timeframes and recertify annually.
- Work is performed primarily from company facilities or remotely, with periodic travel to Government facilities in the Washington, DC metropolitan area and northern Virginia.