{"schemaVersion":"jobsearcher.job.v1","id":"5815f79e6ce468e79cbf5f4b","url":"https://jobsearcher.com/jobs/5815f79e6ce468e79cbf5f4b","canonicalUrl":"https://jobsearcher.com/jobs/5815f79e6ce468e79cbf5f4b","title":"Security Architect","description":"Security ArchitectJob Overview: We are seeking a Security Architect / A&A Lead for our McLean, VA team. The candidate will lead Assessment and Authorization (A&A) activities for Drupal applications hosted in Microsoft Azure and support the ongoing security compliance of Federal information systems. This role is responsible for managing Authority to Operate (ATO) activities, maintaining Risk Management Framework (RMF) documentation, supporting continuous monitoring, and coordinating with security stakeholders throughout the system lifecycle. Experience with Cyber Security Assessment and Management (CSAM) and Governance, Risk, and Compliance (GRC) tools is highly desired. Additional duties may be assigned to meet business needs.Responsibilities:Lead A&A activities for Azure-hosted Drupal and WordPress applications.Develop, maintain, and update RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Privacy Impact Assessments (PIAs), and Contingency Plans.Prepare, submit, maintain, and renew ATO packages.Manage security compliance controls activities using CSAM and other GRC platforms.Coordinate with Information System Security Officers (ISSOs), Information System Owners (ISOs), Security Control Assessors (SCAs), and Authorizing Officials (AOs) throughout the authorization process.Review system architectures, cloud configurations, and application implementations to ensure compliance with Federal security requirements.Support continuous monitoring activities, including vulnerability management, remediation tracking, annual assessments, and audit support.Review vulnerability scan results, Security Technical Implementation Guides (STIGs), and security artifacts to ensure compliance and support remediation efforts.Collaborate with developers, cloud engineers, and project stakeholders to integrate security requirements throughout the System Development Life Cycle (SDLC).Provide security guidance on cloud architecture, secure development practices, and Federal compliance requirements.Qualifications:The ability to obtain and maintain a Public Trust with the Federal government is mandatory.Employer-based sponsorship is not available for this role.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field and 7 years of experience supporting Federal cybersecurity, RMF, or A&A activities.Demonstrated experience developing and maintaining ATO packages for Federal information systems.Certified Information Systems Security Professional (CISSP) or equivalent cybersecurity certification required.Knowledge, Skills, and Abilities:Strong knowledge of RMF, National Institute of Standards and Technology (NIST) Special Publications 800-37 and 800-53, Federal Information Security Modernization Act (FISMA), and related Federal cybersecurity requirements.Experience supporting Microsoft Azure or Azure Government environments.Experience preparing and maintaining SSPs, SARs, POA&Ms, PIAs, and other security authorization artifacts.Experience using CSAM and GRC tools to manage security controls, assessments, and continuous monitoring activities.Experience supporting vulnerability management, security assessments, audit activities, and STIG compliance.Experience supporting Drupal applications, content management systems, or public-facing web applications.Familiarity with Agile development methodologies and DevSecOps practices.Experience supporting Federal civilian agencies.Experience with Federal Risk and Authorization Management Program (FedRAMP) and Zero Trust Architecture principles.Microsoft Certified: Azure Security Engineer Associate, or equivalent cloud security certification preferred.Strong analytical, organizational, problem-solving, written, and verbal communication skills.Location:Hybrid;","company":"Sara Software Systems","rawCompany":"sara software systems","city":"McLean","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-22T11:30:13.959Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Architect","description":"Security ArchitectJob Overview: We are seeking a Security Architect / A&A Lead for our McLean, VA team. The candidate will lead Assessment and Authorization (A&A) activities for Drupal applications hosted in Microsoft Azure and support the ongoing security compliance of Federal information systems. This role is responsible for managing Authority to Operate (ATO) activities, maintaining Risk Management Framework (RMF) documentation, supporting continuous monitoring, and coordinating with security stakeholders throughout the system lifecycle. Experience with Cyber Security Assessment and Management (CSAM) and Governance, Risk, and Compliance (GRC) tools is highly desired. Additional duties may be assigned to meet business needs.Responsibilities:Lead A&A activities for Azure-hosted Drupal and WordPress applications.Develop, maintain, and update RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Privacy Impact Assessments (PIAs), and Contingency Plans.Prepare, submit, maintain, and renew ATO packages.Manage security compliance controls activities using CSAM and other GRC platforms.Coordinate with Information System Security Officers (ISSOs), Information System Owners (ISOs), Security Control Assessors (SCAs), and Authorizing Officials (AOs) throughout the authorization process.Review system architectures, cloud configurations, and application implementations to ensure compliance with Federal security requirements.Support continuous monitoring activities, including vulnerability management, remediation tracking, annual assessments, and audit support.Review vulnerability scan results, Security Technical Implementation Guides (STIGs), and security artifacts to ensure compliance and support remediation efforts.Collaborate with developers, cloud engineers, and project stakeholders to integrate security requirements throughout the System Development Life Cycle (SDLC).Provide security guidance on cloud architecture, secure development practices, and Federal compliance requirements.Qualifications:The ability to obtain and maintain a Public Trust with the Federal government is mandatory.Employer-based sponsorship is not available for this role.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field and 7 years of experience supporting Federal cybersecurity, RMF, or A&A activities.Demonstrated experience developing and maintaining ATO packages for Federal information systems.Certified Information Systems Security Professional (CISSP) or equivalent cybersecurity certification required.Knowledge, Skills, and Abilities:Strong knowledge of RMF, National Institute of Standards and Technology (NIST) Special Publications 800-37 and 800-53, Federal Information Security Modernization Act (FISMA), and related Federal cybersecurity requirements.Experience supporting Microsoft Azure or Azure Government environments.Experience preparing and maintaining SSPs, SARs, POA&Ms, PIAs, and other security authorization artifacts.Experience using CSAM and GRC tools to manage security controls, assessments, and continuous monitoring activities.Experience supporting vulnerability management, security assessments, audit activities, and STIG compliance.Experience supporting Drupal applications, content management systems, or public-facing web applications.Familiarity with Agile development methodologies and DevSecOps practices.Experience supporting Federal civilian agencies.Experience with Federal Risk and Authorization Management Program (FedRAMP) and Zero Trust Architecture principles.Microsoft Certified: Azure Security Engineer Associate, or equivalent cloud security certification preferred.Strong analytical, organizational, problem-solving, written, and verbal communication skills.Location:Hybrid;","datePosted":"2026-08-22T11:30:13.959Z","dateModified":"2026-08-22T11:30:13.959Z","hiringOrganization":{"@type":"Organization","name":"Sara Software Systems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5815f79e6ce468e79cbf5f4b"},"url":"https://jobsearcher.com/jobs/5815f79e6ce468e79cbf5f4b"}}