Principal Cyber Security Architect
Gaithersburg, MD - USA
Job Summary
This role is part of a growing program and hiring will depend on available funding. We review applications on a rolling basis but the timeline for interviews and offers may some cases we may extendcontingent offersthat become active once funding is confirmed.
This position is located inGaithersburg MD; Egg Harbor Township NJ; or Eagan MN. This is an opportunity to contribute to projects that impact millions of air travelers.
This is a hybrid position requiring 3 days onsite and 2 days remote work. Candidates should reside a commutable distance to one of the above locations.
Leidos is seeking a Cyber Security Architect to join the Air Traffic Business Area within the Homeland Sector supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical future-ready automation platform built on a hybrid cloud data mesh architecture enabling next-generation air traffic management capabilities. You will serve as a senior cybersecurity architect responsible for defining the security architecture across a large-scale hybrid cloud platform supporting national air traffic operations. We are building with an AI-first engineering mindset embracing emerging AI capabilities and modern development practices to accelerate delivery improve software quality and continuously evolve how we design and build mission-critical systems. This position supports government programs and requires the ability to obtain andmaintaina favorable Public Trust investigation.
What Youll Do
Define andmaintainthe cybersecurity architecture for the L-CAP platform
Develop and execute the FedRAMP compliance strategy across cloud environments
Lead Authority to Operate (ATO) planning and execution activities
Conduct threat modeling and vulnerability assessments across platform components
Design and implement zero trust architecture principles across the enterprise
Establish and govern the security controls framework aligned to NIST 800-53
Integrate security practices intoDevSecOpspipelines and CI/CD workflows
Provide cybersecurity governance across four Agile Release Trains (ARTs)
Define security requirements for platform services and application teams
Perform risk assessments and recommend mitigations for emerging threats
Define security architecture for distributed real-time ATC services including inter-service communication protection and API gateway security
Establish software supply chain integrity controls including SBOM generation artifact signing and dependency vulnerability management
Design security patterns for cloud-native service communications protecting mission-critical ATC data flows
Champion an AI-first engineering culture byidentifyingand applying AI-assisted development capabilities automation and emerging software engineering practices that improve developer productivity code quality testing and delivery.
Core Technical Qualifications:
Bachelors degree with 12 years of cybersecurity experience
Demonstrated cybersecurity architecture experience for enterprise platforms
Deep knowledge of FedRAMP authorization processes and requirements
Expertisein NIST 800-53 security controls and Risk Management Framework (RMF)
Experience leading ATO efforts for federal information systems
Knowledge of zero trust architecture principles and implementation patterns
Experience with safety-critical systems security requirements
Cloud securityexpertiseacross AWS and/or Azure environments
Understanding of distributed systems security challenges and solutions
Ability to obtain andmaintaina Public Trust clearance; US citizenship; subject to government background investigation
Experience securing distributed real-time services and microservice communication patterns
Knowledge of software supply chain security practices (SLSA SBOM artifact signing dependency scanning)
Ability to obtain and maintain a Public Trust
U.S. citizenship required
Successful completion of background investigations as required by the government customer
Preferred / Desired Qualifications
CISSP CISM or equivalent cybersecurity certifications
FAA or aviation-sector cybersecurity experience
Penetration testing and red team experience
SIEM architecture and security operations design
Mission assurance and continuity of operations experience
DoD or federal civilian agency cybersecurity programs
Experience securing real-time operational systems in aviation or air traffic control environments
Why Leidos
Youll work on systems where performance precision and reliability matter every second. This is not experimental AI for prototypes. This is disciplined responsible AI applied to mission-critical software that supports national infrastructure.
If youre excited by solving complex problems in regulated real-world environments and using AI as a force multiplier rather than a shortcut wed like to talk.
ATMC
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
Staff IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.