Cloud Security Architect
Overview
BigBear.ai is seeking a Cloud Security Architect with an active TS/SCI with Poly clearance to design and implement secure cloud architectures that support an ATO Automation Platform deployment while ensuring compliance with federal security requirements. This role leads the technical implementation of an ATO Automation Platform across multi-cloud and hybrid environments, establishes secure integrations with cloud service providers, and ensures the platform operates within customer security boundaries and authorization scopes. This position will be based out of our Columbia, MD office but will support multiple customers in the Baltimore/Washington corridor and beyond.
What you will do
- Design secure reference architectures for deploying an ATO Automation Platform in AWS GovCloud, Azure Government, and on-premises environments
- Implement secure API integrations between the ATO Automation Platform and cloud service provider platforms for real-time configuration analysis
- Configure cloud security services (AWS GuardDuty, Azure Security Center) to feed security findings into the ATO Automation Platform’s compliance monitoring
- Establish security boundaries and authorization scopes for systems under the ATO Automation Platform’s management
- Implement data protection controls including encryption at rest and in transit for compliance artifacts processed by the ATO Automation Platform
- Design network security architectures supporting the ATO Automation Platform deployment in classified environments
- Conduct security assessments of an ATO Automation Platform components and validate compliance with customer security overlays
- Develop cloud infrastructure-as-code templates that incorporate security controls mappable by the ATO Automation Platform
- Design AWS GovCloud reference architecture for deploying the ATO Automation Platform in FedRAMP High environment with appropriate VPC segmentation and encryption
- Configure the ATO Automation Platform’s integration with Azure Government APIs to enable automated analysis of NSG rules and Key Vault configurations
- Implement cross-account IAM roles enabling the ATO Automation Platform to perform read-only assessments of 50+ AWS accounts across an agency
- Design hybrid cloud architecture supporting the ATO Automation Platform deployment for systems spanning on-premises data centers and commercial cloud
- Conduct security assessment of the ATO Automation Platform’s LLM processing to ensure compliance with agency data handling requirements
What you need to have
- Bachelor's Degree with a Technical concentration with at least 10 years of professional experience
- TS/SCI with an active Poly clearance
- Deep expertise in cloud security architectures across AWS GovCloud and Azure Government
- Strong understanding of cloud security services and compliance capabilities
- Experience with FedRAMP authorization processes and cloud security requirements
- Proficiency in cloud IAM design and least-privilege access models
- Knowledge of network security architecture including VPCs, security groups, and network segmentation
- Experience with encryption technologies and key management services
- Understanding of API security and secure integration patterns
- Familiarity with cloud compliance frameworks (AWS Security Best Practices, Azure Security Benchmark)
What we'd like you to have
- Experience deploying security platforms in classified cloud environments (AWS Secret/Top Secret regions, Azure Government Secret)
- Knowledge of DoD Cloud Computing Security Requirements Guide (SRG) implementation
- Prior experience with compliance automation platform deployments
- Certifications: AWS Certified Security Specialty, Azure Security Engineer Associate, CCSP (Certified Cloud Security Professional)
- Understanding of zero-trust architecture principles and implementation
- Experience with Infrastructure as Code security scanning (Checkov, tfsec, Terrascan)
- Familiarity with container security in cloud environments
- Background in federal cloud migration projects and Cloud Smart strategy
About BigBear.ai
BigBear.ai is a leading provider of AI-powered decision intelligence solutions for national security, supply chain management, and digital identity. Customers and partners rely on Bigbear.ai’s predictive analytics capabilities in highly complex, distributed, mission-based operating environments. Headquartered in McLean, Virginia, BigBear.ai is a public company traded on the NYSE under the symbol BBAI. For more information, visit and follow BigBear.ai on LinkedIn: @BigBear.ai and X: @BigBearai.
BigBear.ai is an Equal opportunity employer all protected groups, including protected veterans and individuals with disabilities.
#J-18808-LjbffrRecommended Jobs
*Computer Programmer IV
The Computer Programmer IV recommends the redesign of programs, investigates and analyzes feasibility and program requirements, and develops programming specifications. Assigned programs typically aff…
Residential Property Inspector - Alexandria, VA.
Looking to Supplement Your Income or Just Be Productive? Become an Independent Residential Insurance Inspector with CIS Group! Are you looking for a flexible, rewarding opportunity that allows y…
Mission-Critical Software Engineer (TS/SCI)
A technology solutions provider in McLean, Virginia is looking for a Software Engineer skilled in Python and AWS. The successful candidate will design and maintain production systems, develop APIs, an…
Certified Substance Abuse Counselor
Responsibilities Certified Substance Abuse Counselor Poplar Springs Hospital i s a 183 bed acute care and residential facility. For more than 30 years Poplar Springs Hospital has been…
Part Time Cook Senior Living
Part Time Cook Senior Living Location Staunton, VA : Designed and purpose built for seniors, our communities incorporate resort-style amenities and social activities to provide seniors a carefree, ma…
Lead UAV Propulsion Systems Engineer
A defense technology company in Ashburn, VA, is seeking a Lead Systems Engineer responsible for defining and managing hardware/software requirements for propulsion subsystems in unmanned aircraft. Can…
Program Scheduler
Title: Program Scheduler KBR is seeking a Program Scheduler SETA. The successful candidate will assist and support the Government customer Program Office in coordination of scheduling activitie…
Travel Nurse RN - Neuro ICU - $1,955 per week
Cross Country Nurses is seeking a travel nurse RN Neuro ICU for a travel nursing job in Richmond, Virginia. Job Description & Requirements ~ Specialty: Neuro ICU ~ Discipline: RN ~ Start D…
Seafood Team Member (Service Counter) - Part Time
A career at Whole Foods Market is more than just the work you do- it's about your personal growth and creating meaningful change. Our purpose is to nourish people and the planet. That means improving…
Travel Nurse RN - NICU - Neonatal Intensive Care - $2,490 per week
MedPro Healthcare Staffing is seeking a travel nurse RN NICU - Neonatal Intensive Care for a travel nursing job in Norfolk, Virginia. Job Description & Requirements ~ Specialty: NICU - Neonatal…