Chief Security Architect, Developer
Listed on 2026-06-05
-
IT/Tech
Cybersecurity, IT Consultant, Security Manager
Chief Security Architect, Developer Experience
"Wanted:
The architect who sees that the ATO process isn't a compliance problem-it's an engineering problem-and knows how to build the solution."
Large-scale software delivery in regulated, defense-focused environments runs into the same wall everywhere you look. The compliance process was designed to create an audit trail. It wasn't designed to enforce security. SSPs capture intent. ATOs authorize environments at a point in time. And by the time the ink is dry, the system has already moved.
The developers building mission-critical software know this pattern. The security organizations know it too. The question has never been whether this model needs to change—it’s whether anyone has the engineering depth and the security credibility to build something that actually replaces it.
That's why this role exists.
We're building the platform that is transforming how thousands of Leidos engineers build and deliver software. At the center of that platform is a fundamental re-architecture of how compliance works: not as a gate you pass through, but as code woven into the infrastructure itself. Policy-as-code. Continuous compliance evidence. A platform ATO that programs inherit rather than pursue on their own.
The goal is a platform that the enterprise security organization looks at and says: this is the thing we've been trying to build for years. These people aren't going around us. They're handing us superpowers.
You're the person who builds it. And you're the person who makes that realization inevitable.
Why This Role MattersSecurity and compliance in defense-sector software delivery have long lived in a structural paradox: the processes designed to protect mission software are the same processes that slow it down. Manual authorization cycles. Point-in-time snapshots. Documentation that proves intent but not execution. Every program team re-solves the same compliance problems. Every platform that wants to help them has to run the gauntlet first.
What you'll build isn't a workaround. It's a better architecture: policy-as-code that enforces compliance at the moment of deployment, continuous evidence that gives auditors real-time proof instead of point-in-time packages, and a platform-level ATO that program teams can inherit rather than pursue. The result is a security posture that's demonstrably stronger than manual review-stricter, more consistent, and infinitely more scalable.
Leidos is one of the largest engineering organizations supporting national security, with thousands of developers building mission-critical software across hundreds of programs. What you build here will shape how that software is delivered—and whether the security guaranteeing it is a paper promise or an enforced fact.
If you've spent your career knowing this was possible and waiting for an organization big enough to matter and willing enough to move—it’s it.
What You'll Do- Architect the compliance engine. Design and build the policy-as-code infrastructure that sits at the heart of the platform: the enforcement points, evidence pipeline, continuous compliance dashboards, and attestation framework that make "approved to deploy" a machine-verifiable fact, not a permission you wait on. You know this toolchain—the policy engines, the evidence frameworks, the supply chain attestation standards—and you've put it to work in production.
- Own the platform ATO strategy. Chart the path from where we are to a platform-level ATO that programs can inherit. Navigate RMF, NIST 800-53, NIST 800-171, NIST 800-160, and DoD IL4/IL5 requirements alongside the realities of working with internal security reviewers and external auditors (3
PAOs, DCMA). You've done this before. You know which shortcuts are real and which are traps. - Be the enterprise security team's most important technical partner. Attend the meetings. Build the trust. Co-author the policies. Make the case—technically, patiently, relentlessly that policy-as-code is more rigorous than manual reviews, not less. You can speak the language of ISSOs and ISSMs, help them see their role shifting from gatekeepers to policy authors, and make that shift feel…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).