Quick Overview
Salary
$80 - $90/hr
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
18 hours ago
Active DirectoryPKIZero Trust
Job Description
Role Summary
The Cybersecurity Architect is responsible for designing and implementing Comply-to-Connect (C2C) policy frameworks and enforcement strategies across enterprise environments. This role provides technical leadership for C2C implementation, translating current security requirements into actionable designs and deployment strategies. The position develops technical documentation, conducts gap analyses, and collaborates with stakeholders to support effective cybersecurity policy integration and enforcement.
Responsibilities
- Design device profiling, posture assessment, interrogation, automated remediation, and enforcement policies across the C2C security framework.
- Define enforcement strategies, including monitoring, phased deployment, quarantine and remediation approaches, and rollback criteria.
- Develop gap analyses, technical design documentation, and change management materials to support policy deployment.
- Develop procedures for managing exception devices, including MAB and segmentation approaches, in collaboration with stakeholders.
- Design integrations with vulnerability assessment tools, endpoint security solutions, Active Directory/PKI, RADIUS, SIEM, and CMDB systems.
- Review and validate technical deliverables and help resolve technical challenges affecting implementation.
- Capture lessons learned and develop reusable policy templates to support deployments across multiple environments.
- Collaborate with cross-functional teams to support alignment with applicable cybersecurity standards and best practices.
- Communicate technical risks, considerations, and tradeoffs to both technical and non-technical stakeholders.
- Support continuous improvement through lessons learned and process refinement.
Qualifications
- 10+ years of experience in cybersecurity or network security, including 5+ years designing Network Access Control (NAC), Zero Trust, or Comply-to-Connect solutions.
- Active Secret security clearance required.
- Experience designing and deploying NAC or C2C solutions supporting access control for large-scale production environments.
- Strong knowledge of 802.1X, EAP-TLS, MAB, CoA, RADIUS/TACACS+, and PKI/CAC-based authentication.
- Working knowledge of C2C frameworks, Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), and vulnerability assessment practices.
- Experience with network access control platforms such as Forescout and/or Cisco ISE.
- Strong communication skills with the ability to explain technical risks and tradeoffs to non-technical stakeholders.
- Ability and willingness to travel up to 75% to locations within the continental United States.
Preferred Qualifications
- Experience with C2C or Zero Trust implementations in regulated or security-focused environments.
- Experience with enterprise integrations, including orchestration, APIs, and SIEM solutions.
- Experience developing or supporting ATO/RMF documentation and security authorization packages.
- Security+ certification required.
- CISSP or CASP+ certification preferred.
- Vendor-specific architect or professional certification related to Forescout, Cisco Security/ISE, or comparable technologies preferred.
Publishing Pay Range: $80.00 - $90.00 USD Hourly
This is a fully remote role and can be performed from an approved location.
Similar jobs
- MA
Personnel Security Specialist
NewMANTECH
Los Angeles, California🇺🇸Hybrid1 hour agoData Entry - MA
Acquisition Security Analyst
NewMANTECH
Los Angeles, California🇺🇸Hybrid1 hour agoTechnology - RT
Senior Security Engineer
NewRequest Technology, LLC
Chicago, IL🇺🇸$135k - $165k/yrHybrid18 hours agoEncryptionActive DirectoryAzure+5Technology - MA
Physical and Industrial Security Specialist
NewMANTECH
El Segundo, California🇺🇸On-site1 hour agoAdministrative - BT
OKTA Engineer
NewBoston Technology Corporation
Malvern, PA🇺🇸Hybrid18 hours agoEngineering - DT
SOC Analyst
NewDhaka Technologies Limited Company
Washington, DC🇺🇸On-site18 hours agoTCP/IPPerlPowerShellTechnology