Cybersecurity Architect
IT
Baltimore, MD, USA
Architecture & Solution Design
Develop enterprise-wide security architectures aligned to NIST standards (e.g., NIST CSF, SP 800-53, SP 800-171, SP 800-207).
Design scalable, secure solutions that address identified risks and business objectives across cloud, on-premises, and hybrid environments.
Translate business and technical requirements into secure solution blueprints.
Contribute to the development of reference architectures and security patterns.
Leverage hands on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
Solution Review & Risk Mitigation
Lead architecture and security reviews for new technologies, applications, and systems.
Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
Provide technical guidance to project and product teams throughout the system development lifecycle.
Governance & Standards
Develop and maintain security architecture standards, policies, and control frameworks in alignment with NIST and industry best practices.
Participate in or lead internal security governance boards and architecture review boards.
Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CCPA, NYDFS, PCI DSS).
Contribute to maturity assessments and continuous improvement efforts for cybersecurity architecture.
Collaboration & Leadership
Act as a subject matter expert on cybersecurity architecture for stakeholders across IT, engineering, compliance, and risk teams.
Mentor junior architects and security engineers.
Communicate complex technical and risk concepts clearly to business leaders and non-technical audiences.
Stay up to date on emerging threats, technologies, and changes to the NIST ecosystem.
Required Qualifications
7–10 years of experience in cybersecurity, with 3+ years in a security architecture or similar role.
Deep working knowledge of NIST frameworks (CSF, SP 800-53, 800-171, 800-207 Zero Trust).
Demonstrated experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g., AWS, Azure).
Practical experience translating security architecture requirements into implemented controls, technical configurations, and operational procedures.
Strong understanding of cybersecurity domains including identity and access management (IAM), network security, data protection, and application security.
Strong understanding of LLMs, AI, and GenAI solutions including agentic AI and MCP hardening.
Experience validating control effectiveness through testing, monitoring, evidence collection, or audit support.
Experience working in a regulated environment and aligning technical controls to compliance frameworks. Excellent communication, collaboration, and documentation skills.
Preferred
Industry certifications such as CISSP, CISM, CISA, SABSA, or AWS Certified Security.
Experience with Zero Trust Architecture and modern security models.
Experience with security automation, control orchestration, policy-as-code, or continuous control monitoring.
Experience implementing security controls in cloud-native, hybrid, and complex enterprise-scale environments.
Familiarity with DevSecOps and infrastructure-as-code security.