Enterprise Security Architect, Lead
Listed on 2026-07-20
-
IT/Tech
Cybersecurity
The Opportunity:
Security must be architected, not bolted on. You understand how to embed security into every layer of an enterprise system, from data pathways to identity flows, to network segmentation and cloud control planes. We are seeking an Enterprise Security Architect to design security solutions for clients with complex network, platform, and data‑protection needs that withstand advanced cyber threats. In this role, you will help define, enhance, implement, and maintain security solutions for one or more networks and technology platforms while guiding adherence to information security policies and procedures.
In this role, you will apply risk modeling and secure design methodologies to develop tailored controls for client and industry exposures, then translate those designs into practical architectures for network and application deployments. You will advise on security technologies and communicate security complexities clearly to technical teams, stakeholders, and senior management. You will partner with engineering teams, cybersecurity SMEs, cloud and platform owners, and business stakeholders.
You’ll assess current‑state environments, identify architectural gaps, evaluate emerging technologies, and build roadmaps that advance enterprise security maturity. This is an opportunity to shape hardened systems that support the mission and to learn from a team of experts while doing it.
- 7+ years of experience in cybersecurity
- 3+ years of experience in security architecture or security design
- Experience designing enterprise‑scale secure cloud or hybrid architectures, and developing architecture documents such as diagrams, models, SSPs, and data flows
- Experience with network security appliances using technologies such as F5 or Palo Alto
- Experience with data security engineering, including DLP, encryption at rest and in transit, and tokenization
- Experience with security technologies such as HSMs, SASE, and cloud security platforms
- Knowledge of Zero Trust architectures, NIST SP 800‑53 or 800‑207, and secure engineering principles
- Knowledge of enterprise information security architecture, information assurance, and network security
- Secret clearance
- Bachelor’s degree
- Experience with cloud security platforms such as AWS, Azure, or Google Cloud
- Experience with enterprise logging, SIEM or SOAR integrations, and detection engineering alignment
- Experience supporting compliance or accreditation processes, including RMF, ATO, FedRAMP, and ICD 503
- Experience with Agile development methodologies and Dev Sec Ops practices
- Experience with container or Kubernetes security and micro‑segmentation
- Experience creating reusable secure architecture patterns or reference designs
- Experience working in a fast‑paced environment with multiple stakeholders and priorities
- Knowledge of cybersecurity frameworks and standards such as NIST, ISO 27001, and COBIT
- TS/SCI clearance
- Security Architecture Certification such as CISSP‑ISSAP or TOGAF Certification
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Secret clearance is required.
At Booz Allen, we celebrate your contributions and provide benefits that support your health, life, disability, financial, and retirement well‑being, as well as paid leave, professional development, tuition assistance, work‑life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance. Full‑time and part‑time employees working at least 20 hours a week on a regular basis are eligible for Booz Allen’s benefit programs.
The projected annualized salary range for this position is $86,800.00 to $. This posting will close within 90 days from the Posting Date.
Work Model:- Remote:
If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid:
If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite:
If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where you will collaborate directly with colleagues and customers as required by the role.
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).