Koniag Advisory and Business Solutions LLC a Koniag Government Services company is seeking a Senior Applied Security Architect to support KABS and our government customer in Washington DC. The position is hybrid will require 3 days onsite. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and Senior Applied Security role provides advanced cybersecurity leadership technical architecture and compliance oversight for systems workflows and data supporting the DOE Office of Technology Commercializations SBIR/STTR programs. This position ensures secure handling of sensitive proposal information applicant data and program records; strengthens security-by-design across platforms and tools; and drives continuous monitoring and risk reduction. The senior specialist partners with program managers IT/security teams national laboratories reviewers and support contractors to design and enforce controls that align with federal requirements and DOE mission Responsibilities:Lead security architecture and design for SBIR/STTR program systems data flows and integrations (onprem cloud and hybrid).Develop and maintain security policies standards and procedures for identity access data protection logging and incident risk assessments threat modeling vulnerability management and remediation planning; maintain POA&Ms and drive and optimize controls for safeguarding sensitive information (e.g. proposal data PII) including encryption tokenization and security compliance activities mapping controls to applicable federal frameworks and DOE requirements; support ATO secure workflows for solicitation development proposal intake/review portfolio tracking reporting and outreach and manage role-based access least privilege models and privileged access management for SBIR/STTR continuous monitoring log aggregation/SIEM use cases alert tuning and metrics dashboards for leadership incident response planning tabletop exercises and after-action reviews; ensure timely reporting and corrective third-party tools and vendors used for program operations; conduct security due diligence and integration senior technical guidance and coaching to program and contractor teams; deliver security training and awareness process improvements that enhance security posture reduce operational risk and improve user experience without compromising Qualifications:Bachelors degree in computer science information security engineering or a related of 7 years experience in applied cybersecurity security architecture/engineering or compliance in federal or regulated experience designing and implementing security controls for cloud and hybrid systems (e.g. identity encryption logging IR).Handson experience with vulnerability assessment tools SIEM/monitoring endpoint protection and configuration understanding of data protection for sensitive and personal information; experience operationalizing privacy/security written and verbal communication skills including developing policies standards and leadership ability to lead cross-functional teams manage complex initiatives and drive remediation through to with security frameworks and control baselines; ability to translate requirements into practical auditable implementations.U.S. citizenship and ability to meet federal suitability requirements if Qualifications:Experience supporting DOE or other federal research/innovation programs including SBIR/STTR with federal cybersecurity frameworks and standards (e.g. NIST SP 800 series FISMA) cloud security best practices and zero trust protecting proposal/intellectual property workflows applicant portals data lakes and analytics/reporting such as CISSP CCSP CISM CASP or GIAC (e.g. GSEC GCCC GCIH).Knowledge of secure DevSecOps practices automation infrastructure as code and compliance-as-code in energy sector technologies or scientific R&D Requirement:Ability to obtain a Public TrustKey Competencies:Security Architecture & EngineeringRisk Management and ComplianceData Protection and PrivacyIncident Response and Continuous MonitoringStakeholder Collaboration and CommunicationProcess and Workflow ImprovementAnalytical and Critical ThinkingLeadership and MentorshipKnowledge Skills and Abilities (KSAs)Knowledge:Understanding of federal cybersecurity requirements control frameworks and DOE mission context for research of secure cloud/hybrid architectures identity/access patterns encryption methods logging/telemetry and IR best :Designing and implementing technical controls policies and procedures across complex program risk assessments threat modeling vulnerability management and mitigation dashboards reports and briefings that translate security posture and metrics for security tools (e.g. SIEM EDR scanners configuration baselines) and integrating them with program :Ability to lead multifunctional teams and drive consensus on security priorities and remediation to communicate clearly with technical and nontechnical audiences and convert requirements into actionable to balance strong security controls with usability performance and mission to manage multiple initiatives deadlines and emergent incidents in a dynamic Environment:This is a hybrid position requiring periodic onsite participation at DOE headquarters or designated facilities. Remote work is supported for routine tasks. Travel may be required for meetings workshops security assessments or program Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352
Required Experience:
Senior IC
Koniag Advisory and Business Solutions LLC a Koniag Government Services company is seeking a Senior Applied Security Architect to support KABS and our government customer in Washington DC. The position is hybrid will require 3 days onsite. This position requires the candidate to be able to obtain a ...
Koniag Advisory and Business Solutions LLC a Koniag Government Services company is seeking a Senior Applied Security Architect to support KABS and our government customer in Washington DC. The position is hybrid will require 3 days onsite. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and Senior Applied Security role provides advanced cybersecurity leadership technical architecture and compliance oversight for systems workflows and data supporting the DOE Office of Technology Commercializations SBIR/STTR programs. This position ensures secure handling of sensitive proposal information applicant data and program records; strengthens security-by-design across platforms and tools; and drives continuous monitoring and risk reduction. The senior specialist partners with program managers IT/security teams national laboratories reviewers and support contractors to design and enforce controls that align with federal requirements and DOE mission Responsibilities:Lead security architecture and design for SBIR/STTR program systems data flows and integrations (onprem cloud and hybrid).Develop and maintain security policies standards and procedures for identity access data protection logging and incident risk assessments threat modeling vulnerability management and remediation planning; maintain POA&Ms and drive and optimize controls for safeguarding sensitive information (e.g. proposal data PII) including encryption tokenization and security compliance activities mapping controls to applicable federal frameworks and DOE requirements; support ATO secure workflows for solicitation development proposal intake/review portfolio tracking reporting and outreach and manage role-based access least privilege models and privileged access management for SBIR/STTR continuous monitoring log aggregation/SIEM use cases alert tuning and metrics dashboards for leadership incident response planning tabletop exercises and after-action reviews; ensure timely reporting and corrective third-party tools and vendors used for program operations; conduct security due diligence and integration senior technical guidance and coaching to program and contractor teams; deliver security training and awareness process improvements that enhance security posture reduce operational risk and improve user experience without compromising Qualifications:Bachelors degree in computer science information security engineering or a related of 7 years experience in applied cybersecurity security architecture/engineering or compliance in federal or regulated experience designing and implementing security controls for cloud and hybrid systems (e.g. identity encryption logging IR).Handson experience with vulnerability assessment tools SIEM/monitoring endpoint protection and configuration understanding of data protection for sensitive and personal information; experience operationalizing privacy/security written and verbal communication skills including developing policies standards and leadership ability to lead cross-functional teams manage complex initiatives and drive remediation through to with security frameworks and control baselines; ability to translate requirements into practical auditable implementations.U.S. citizenship and ability to meet federal suitability requirements if Qualifications:Experience supporting DOE or other federal research/innovation programs including SBIR/STTR with federal cybersecurity frameworks and standards (e.g. NIST SP 800 series FISMA) cloud security best practices and zero trust protecting proposal/intellectual property workflows applicant portals data lakes and analytics/reporting such as CISSP CCSP CISM CASP or GIAC (e.g. GSEC GCCC GCIH).Knowledge of secure DevSecOps practices automation infrastructure as code and compliance-as-code in energy sector technologies or scientific R&D Requirement:Ability to obtain a Public TrustKey Competencies:Security Architecture & EngineeringRisk Management and ComplianceData Protection and PrivacyIncident Response and Continuous MonitoringStakeholder Collaboration and CommunicationProcess and Workflow ImprovementAnalytical and Critical ThinkingLeadership and MentorshipKnowledge Skills and Abilities (KSAs)Knowledge:Understanding of federal cybersecurity requirements control frameworks and DOE mission context for research of secure cloud/hybrid architectures identity/access patterns encryption methods logging/telemetry and IR best :Designing and implementing technical controls policies and procedures across complex program risk assessments threat modeling vulnerability management and mitigation dashboards reports and briefings that translate security posture and metrics for security tools (e.g. SIEM EDR scanners configuration baselines) and integrating them with program :Ability to lead multifunctional teams and drive consensus on security priorities and remediation to communicate clearly with technical and nontechnical audiences and convert requirements into actionable to balance strong security controls with usability performance and mission to manage multiple initiatives deadlines and emergent incidents in a dynamic Environment:This is a hybrid position requiring periodic onsite participation at DOE headquarters or designated facilities. Remote work is supported for routine tasks. Travel may be required for meetings workshops security assessments or program Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352
What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate
... View more