Security Architect, Networks
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Staff Security Architect, Networks
Denver, CO or Long Beach, CA
Space is a war fighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
Your MissionAs a Staff Security Architect – Networks, you will be a critical technical expert responsible for understanding program requirements, defining architecture, and designing and deploying terrestrial networks that underpin our classified capabilities. You will work as part of the Mission Security Engineering team, translating complex DoD and Intelligence Community requirements into secure, compliant, and scalable network architectures that span multiple classification levels and locations across the United States.
This is a senior individual contributor role with broad impact across multiple in-flight programs. You will own the network architecture that connects on-premise and IL-6+ cloud environments across the country, partnering with cloud, security, and systems engineering teams to ensure our endpoint networks are designed, authorized, and operated to the highest federal standards. You will bring deep expertise in IP networking, DoD classified network requirements, and cloud network design — and the technical maturity to drive complex initiatives from requirements through authorization with minimal direction.
This position requires an active TS clearance with SCI eligibility in order to start.
Responsibilities- Define, design, and deploy terrestrial network architectures for classified capabilities spanning multiple on-premise locations across the U.S., with a focus on IL-6+ environments
- Translate program security and mission requirements into end-to-end IT network architectures that support an array of ongoing classified programs
- Architect and implement endpoint networks connecting on-premise IL-6+ infrastructure across geographically distributed locations
- Lead network authorization activities under NIST SP 800-53, ensuring architectures are designed for compliance from the outset and support efficient ATO achievement and maintenance
- Evaluate, select, and specify network hardware and software in accordance with applicable Approved Products Lists (APLs) and Trade Agreements Act (TAA) compliance requirements
- Architect and define the network interfaces and integration points between classified cloud environments (AWS/Azure IL-6+), USG networks, and end-user physical networks, working in close partnership with cloud engineers to ensure consistent security posture, control inheritance, and seamless interoperability across all domains
- Partner with ISSEs, industrial security personnel, cloud engineers, and systems engineers to ensure network designs meet program security, operational, and compliance requirements
- Develop and maintain network architecture documentation including topology diagrams, interface control documents, and system security artifacts required for RMF and ATO activities
- Implement and validate network security controls including boundary protection, segmentation, traffic filtering, and encrypted communications across classification domains
- Identify and remediate network-layer findings from STIGs, vulnerability scans, and SCA activities to maintain ATO posture
- Ensure compliance with NIST 800-53, CNSSI 1253, ICD 503, JSIG, and other applicable frameworks for National Security Systems handling classified information up to TS/SCI
- Stay current on emerging network security technologies, DoD policy changes, and APL updates, advocating for adoption where appropriate
- 10+ years of hands-on experience in network engineering or architecture, with deep technical and procedural expertise across the full lifecycle of classified network environments — including requirements definition, hardware acquisition (APL/TAA compliance), design, deployment, and ongoing operations — at classification levels up to and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).