Cloud Network Security Architecture Manager; TIC
Listed on 2026-10-04
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Network Security
Type of
Requisition :
Regular Clearance Level Must Currently Possess:
None Clearance Level Must Be Able to Obtain:
None Public Trust/Other
Required:
MBI (T2) Job Family: IT Infrastructure and Operations
Job Qualifications:
Skills:
Cloud Platform, IT Service Management (ITSM), Network Architecture
Certifications:
None
Experience:
10 + years of related experience US Citizenship
Required:
No
Join GDIT in modernizing the Department of Veterans Affairs’ network security posture under the NEDIIS program. As the Cloud Network Security Architecture Manager, you will lead the design and implementation of TIC 3.0‑aligned, Zero‑Trust‑enabled, distributed security architectures across VA’s hybrid and multi‑cloud environments. This role transforms legacy perimeter models into risk‑based trust zones, policy enforcement points (PEPs), cloud‑native security controls, and continuous monitoring‑integrated architectures, consistent with evolving federal cybersecurity guidance.
HowYou Will Make an Impact
- Lead TIC 3.0 modernization, shifting security from centralized gateways to distributed trust‑zone and PEP‑based enforcement across AWS, Azure, and enterprise networks.
- Architect Zero‑Trust‑aligned identity‑centric controls, segmentation, dynamic policy enforcement, and continuous validation.
- Design and manage trust‑zone mappings, cloud boundary protections, secure interconnects, and mission‑aligned risk‑based traffic flows.
- Guide implementation of policy enforcement points for cloud, on‑prem, remote, and mobile use cases.
- Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
- Partner with engineering, cyber, SOC, network, and operations groups to embed security across distributed systems.
- Oversee gateway transformation, including redesign, scaling, load distribution, and modernization aligned with TIC 3.0.
- Communicate architectural decisions, risks, and modernization strategies to VA leadership.
- Evaluate emerging technologies, lead pilots/proofs of concept, and recommend mission‑aligned adoption strategies.
- Support escalations and critical events involving cloud networks, identity systems, boundary controls, and PEP operations.
- Produce architecture diagrams, trust‑zone definitions, PEP mappings, documentation, and compliance artifacts.
- Mentor engineers and promote security best practices across cloud and network architecture teams.
- Hands‑on experience designing or supporting federal‑grade, Zero‑Trust‑aligned architectures (identity‑centric access, micro‑segmentation, encrypted traffic inspection, cloud boundary protections).
- Experience with TIC 3.0 concepts, trust zones, distributed enforcement, and cloud/mobility use cases is required.
- Background in cloud, network, or security architecture (AWS, Azure, hybrid networking, segmentation).
- Hands‑on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations.
- Strong understanding of NIST Cybersecurity Framework, NIST SP 800‑207 (ZTA), NIST SP 800‑53, and broader federal cybersecurity standards.
- Experience with automation, scripting, or IaC (Terraform, Ansible, Cloud Formation, ARM templates).
- Effective communicator able to coordinate across multiple teams.
- Ability to support emergency incidents, escalations, and critical events.
- AWS Solutions Architect – Professional
- Azure Solutions Architect Expert
- Kubernetes / Open Shift (CKA / CKAD)
- VMware certifications
- Terraform Associate
Visa sponsorship will not be provided for this position.
This role will require you to obtain and maintain Public Trust Suitability and will require you to provide onsite fingerprinting at a designated facility. This investigation may review personal and criminal behavior, financial…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).