Haystack
← Back to Jobs
Technology
9W

Technical Lead Chief Security Architect / Engineer

9th Way InsigniaUnited States🇺🇸United StatesPosted 3 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
United States
Posted
20 hours ago
HIPAAZero TrustIoTQuantum Computing5G

Job Description

Team (Project) Introduction
The Department of Veterans Affairs (VA) Cybersecurity Operations Systems Engineering (COSE) project serves as an overarching technical engine that unifies Architecture and Engineering Services throughout the VA Enterprise. This program implements cohesive organizational security architecture and underlying engineering components that utilize national security standards, guidelines, and frameworks. COSE bridges the gap between high-level business requirements and technical structures, enabling the consistent deployment of secure technologies through implementation guidance and the establishment of an analytic library. Systems security engineering within COSE contributes a holistic perspective to the systems engineering effort, ensuring that stakeholder protection needs are addressed throughout the entire system life cycle from concept and development to production, support, and decommissioning. By drawing upon well-established systems engineering and security principles, COSE adapts and supplements practices to protect intellectual property, data, and the methods used to create VA systems. These activities improve the security posture of VA applications to prevent, deter, or detract from cyberattacks by nefarious adversaries or insider threats.

9 th  Way Insignia is looking for a Hybrid Manager/Technical Lead (Technical Skills), Technical Lead Chief Security Architect / Engineer to join this team.

Professional Level Information:
A Hybrid Manager at 9th Way Insignia accomplishes department objectives by managing staff and processes and evaluating department activities. Focuses on leading a team and working hands-on with projects involving technology. Hybrid Managers require skills and qualifications such as exceptional leadership, communication and interpersonal skills.


Functional Job (LCAT) Information:
The Technical Lead Chief Security Architect / Engineer will serve as the senior technical authority for cybersecurity architecture and engineering activities supporting the VA COSE program. The individual will lead the development, assessment, modernization, and governance of enterprise security architectures and guide multidisciplinary engineering teams in translating mission, cybersecurity, and business requirements into secure, scalable, standards-aligned technical solutions.


Responsibilities:

  • Provide senior-level technical leadership and architectural direction for enterprise cybersecurity architecture and engineering activities across the VA environment.
  • Serve as a principal security architecture and engineering subject matter expert, advising Government leadership, program managers, architects, engineers, and technical teams on complex cybersecurity and technology decisions.
  • Translate customer, mission, business, cybersecurity, and regulatory requirements into enterprise security architectures, engineering requirements, technical strategies, and implementation guidance.
  • Lead and coordinate architecture and engineering teams to ensure technical requirements are clearly understood, assigned, implemented, and validated.
  • Conduct and oversee enterprise and system-level security architecture reviews for new, existing, and modernized systems.
  • Assess whether proposed architectures adequately address threats, vulnerabilities, regulatory requirements, security controls, and enterprise risk tolerance.
  • Perform and oversee architecture risk and gap analyses to evaluate compliance with VA and Federal policies, standards, frameworks, and strategic objectives.
  • Develop technically sound and actionable risk-mitigation strategies and architectural recommendations for identified security weaknesses.
  • Apply Zero Trust, defense-in-depth, least privilege, and secure-by-design principles to enterprise and solution architectures.
  • Lead or provide oversight for security threat modeling, including identification of attack vectors, threat actors, misuse cases, attack paths, control gaps, architectural weaknesses, residual risks, and mitigations.
  • Guide the development and maintenance of Security Reference Architectures, Solution Architectures, Security Patterns, and supporting enterprise architecture artifacts.
  • Ensure architectures include appropriate logical, physical, conceptual, network, and data-flow views and accurately represent system components, interfaces, dependencies, and security controls.
  • Ensure security architectures remain aligned with enterprise goals, cybersecurity strategies, modernization initiatives, and technology roadmaps.
  • Provide technical leadership for modernization of both legacy and emerging health IT architectures.
  • Evaluate and guide adoption or integration of emerging technologies identified in the PWS, including cloud computing, mobile technologies, Internet of Things (IoT), APIs, VR/XR, 5G, Data Loss Prevention (DLP), cryptography, Post-Quantum Cryptography (PQC), quantum computing, and Artificial Intelligence (AI).
  • Analyze emerging technologies to determine potential security, architectural, operational, integration, compliance, and enterprise-risk implications.
  • Lead or support specialized security-posture reviews for evolving technology areas and develop associated risk findings and recommendations.
  • Perform research and analysis of complex cybersecurity, architecture, engineering, and technology problems and develop defensible technical recommendations.
  • Conduct detailed trade-off analyses of technical requirements against cost, schedule, performance, security, implementation complexity, and enterprise risk.
  • Develop strategies for resolving complex technical requirements, architectural conflicts, risks, dependencies, and implementation issues.
  • Coordinate with program and project leaders to analyze architectures during conceptual design, technical design reviews, implementation planning, and modernization activities.
  • Provide architectural oversight throughout the technology lifecycle to ensure security requirements remain incorporated from concept through implementation, operations, authorization, modernization, and retirement.
  • Lead or support development of security requirements baselines and traceability from foundational controls and architectural requirements through implementation and final Authority to Operate (ATO).
  • Review system, application, cloud, network, data, identity, and platform designs for security risks and control gaps before implementation.
  • Develop or recommend compensating controls and mitigation approaches when technical constraints prevent straightforward implementation of security requirements.
  • Provide technical leadership for enterprise configuration and security baseline strategies across traditional and emerging technologies.
  • Evaluate enterprise security-engineering processes and recommend integrated workflows that improve configuration management, architectural alignment, traceability, and lifecycle security consistency.
  • Support the assessment, management, and tracking of cybersecurity risks in alignment with NIST SP 800-53, OMB mandates, and the NIST Cybersecurity Framework.
  • Guide technical teams in interpreting and applying relevant Federal security policies, standards, and compliance frameworks, including NIST, FISMA, FedRAMP, CIS Controls, and HIPAA as applicable.
  • Provide technical input supporting Federal A&A, accreditation, ATO, continuous monitoring, and risk-management activities.
  • Participate in and provide technical leadership to VA governance boards, technical review committees, engineering working groups, architecture forums, and modernization initiatives.
  • Establish and communicate architectural positions, engineering decisions, technical standards, and security requirements across multiple program and technical teams.
  • Assist in the development of VA security policies, guidelines, standards, technical positions, and white papers.
  • Develop executive and technical briefings communicating architecture findings, security posture, risks, threat analyses, technical recommendations, performance considerations, and strategic guidance.
  • Present complex cybersecurity and architectural issues in a manner appropriate for executive leadership, Government stakeholders, technical teams, engineers, and non-technical decision-makers.
  • Provide technical oversight and quality assurance for architecture and engineering deliverables to ensure recommendations are consistent, technically sound, actionable, and aligned with Government requirements.
  • Review architectural artifacts and technical documentation for completeness, accuracy, consistency, and compliance with established VA architecture and engineering standards.
  • Mentor and provide technical direction to security architects, cloud engineers, DevSecOps engineers, AI engineers, cryptography specialists, risk analysts, and other technical personnel supporting the program.
  • Facilitate collaboration across security, engineering, operations, governance, development, cloud, data, identity, and program-management functions.
  • Identify areas where technical teams or initiatives are not architecturally aligned and recommend actions to restore consistency with enterprise strategy and security requirements.
  • Support technical planning for pilots, prototypes, use cases, proof-of-concept activities, and enterprise transformation initiatives.
  • Ensure architecture and engineering decisions support secure modernization while maintaining confidentiality, integrity, availability, compliance, and mission effectiveness.
  • May require up to two onsite travel visits

Requirements:

  • Minimum of 15 years of Enterprise Security Architecture Information Security experience at a large company or Government agency similar in size/scope to GSA, IRS, DoD or VA. 
  • An additional advanced degree (e.g. Master’s or PhD) in an IT related field may substitute for up to 5 years of the required experience. 
  • Expertise in project management, security architecture and security engineering with ability to translate customer requirements and relay them to the team. 
  • Expertise and ability to advance the development of legacy and new health IT digital architectures including cloud, mobile, IoT, APIs, VR/XR, 5G, PQC, DLP, Cryptography, Quantum Computing and Artificial Intelligence (AI) technologies. 
  • Expertise in risk management.  
  • Expertise in using Enterprise Architecture (EA) tools.  
  • Expertise in guiding architecture tool processes and products (e.g. SABSA) 
  • Expertise in performing analysis and research of complex problems and processes relating to the subject matter. 
  • Expertise in coordinating with program and project leaders to analyze system architectures during design reviews and throughout the conceptual design lifecycle. 
  • Expertise in identifying strategies for addressing requirements, risks, and issues, conducting detailed trade-off analysis of requirements against fiscal, schedule, and performance issues.  
  • Expertise in creating diagrams and documentation with all components that comprise IT systems including network topology. 
  • Expertise in security frameworks and Federal policies, processes, and standards. (e.g., NIST, FISMA, FedRAMP, CIS Controls, HIPAA). 

Preferred/Desired:

  • Master’s degree in Cybersecurity, Math, Engineering, Computer Science, Information Technology, Information Systems Architecture, Telecommunications Systems Design, Architecture Implementation, Information Systems Integration, Software Development Methodologies, Security Engineering, and Network Systems Communications Management. 
  • CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, CCNP Security

Similar jobs