Cybersecurity Architect / Strategic Advisor
Quick Overview
Job Description
Our client is looking for a Cybersecurity Architect/ Strategic Advisor to serve as a strategic advisor to the CISO and drive the statewide implementation of the Accelerated Exposure Reduction Plan.
This role balances high-level strategic advisory with hands on engineering, operating on a "teach-by-doing" knowledge transfer model. The primary objective is to build long-term internal capabilities while operationalizing and enforcing the State''s newly updated Flaw Remediation (SI-2) Standard. This initiative transitions the State from reactive, manual vulnerability management to an AI-accelerated, continuous authorization, and automated DevSecOps posture.
<>Tasks:2.1 CISO Strategic Advisory and Engineering
· Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives.
· Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal staff to institutionalize elite technical skills.
· Deliver real time training and co-develop automation playbooks within the security operations (SecOps) using live demonstration approach.
2.2 Flaw Remediation (SI-2) Standard Operationalization
· Tier Optimization & Enforcement: Architect automated tracking, logging, and validation mechanisms to implement compliance with the State’s updated SI-2 timeframes:
· Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities, CISA KEV listings, active exploits, and identity/privileged system flaws implement approved mitigations or compensating controls within 24 hours, with full remediation closed inside 7 calendar days.
· Tier 2 (High-Risk/Internal): Configure alerting and metric reporting to validate mitigation within 48 hours and full remediation within 15 calendar days.
· Tier 3 (Moderate/Low): Establish repeatable monthly scheduling to ensure remediation within 30 calendar days.
· Clean Deployment Architectures: Partner with agency development teams to pivot away from manual, in-place patching. Author and implement automated templates for clean deployments using virtualized system images, containers, and cloud-native configurations.
· DevSecOps Integration: Embed secure builds, automated software testing, code scanning, and dependency updates natively into agency deployment pipelines.
2.3 AI Capability Deployment & Toolchain Integration
· Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, showing security analysts and application developers how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation.
· Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass.
· Ensure all AI-assisted capabilities comply strictly with privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments.
2.4 Governance Safeguards & Escalation Automation
· Build automated low-code workflows to manage the SI-2 time-bound exception lifecycle, ensuring every granted exception maps back to a named owner, specific compensating controls, and an explicit financial tiedown capturing technical debt.
· Configure automated alert thresholds and workflow routing for significant business risks that exceed normal management tolerance, ensuring rapid escalation in line with the SI-2 update.
Candidate MUST be a WI resident or willing to relocate to WI prior to starting the role at their own expense. This position can work 100% remote with occasional onsite visits 1-2 times required throughout the duration of the contract
Location: Madison, WI
Contract: 1 year
Skills Required:
- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
- Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
- Comprehensive expertise in operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
- Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
- Cloud Architecture & DevSecOps Engineering
Skills Desired – A plus to have:
- Federal/Government environment
- Experience with tech Stack including Google, Microsoft, AWS, and Splunk
*** Rate depends on experience
*** Candidates authorized to work in the US are encouraged to apply. We can accept H1b, , TN, and other valid work visas for IT. However, we cannot accept OPT or CPT visas at this time.
*** Companies submitting candidates should only submit direct W2 employees for this position.
Please submit your resume by using the "URL" below
Skills
Similar jobs
ServiceNow developer
ePace Technologies, Inc · Washington, United States
1 minute agoData Scientist III with Security Clearance
Black Eagle Defense · Fort Meade, United States
17 minutes ago$128k - $185k/yrSr. JDE EnterpriseOne Developer
MetaSense, Inc. · United States
18 minutes agoOracle OCI Cloud Engineer
Beacon Systems, Inc · Richmond, United States
18 minutes agoAI Enterprise Architect - 12+ yrs - Charlotte Onsite
Systems Management Group, Inc · Charlotte, United States
20 minutes agoSoftware Connected/IoT devices Engineer *********
SGIC Cloud Technologies Inc. · Peachtree Corners, United States
20 minutes ago€45/hr