Subject Matter Expert - Cloud Security Architect

AI overview

Lead the design of secure, scalable AWS cloud architectures for federal mission systems, ensuring compliance with security requirements while accelerating authorization timelines.

Harnessing Technology to Improve Financial Stewardship for the Welfare, Defense, and Security of Our Nation

Blake Willson Group (BWG) unites deep domain experts with technologists who leverage industry-leading financial management solutions to address the most critical mission objectives. Headquartered in the National Capital Region, the firm delivers measurable outcomes through technology-forward strategies and advanced solutions that drive mission success.

Blake Willson Group has a distinguished track record of exceptional performance, achieving operational efficiencies that allow our clients to do more with less. BWG has earned the confidence of its clients by consistently exceeding expectations through its unwavering commitment to best value solutions, implemented with speed.

Job Location: 

This role is 100% remote.

Clearance:

Must be currently authorized to work in the United States on a full-time basis and have the ability to obtain a Public Trust Security Clearance. 

Job Description:

In this position as a Cloud Security Architect, you will lead the design of secure, scalable AWS cloud architectures that support federal mission systems and comply with DOJ/BOP security requirements and FedRAMP control baselines. You will integrate cloud architecture, security engineering, and ATO requirements to accelerate authorization timelines while maintaining a strong security posture. In this position, you will also:

  • Design secure, scalable AWS cloud architectures aligned with DOJ/BOP security policies and FedRAMP baselines.
  • Architect multi-account and multi-VPC environments with appropriate segmentation, centralized inspection, and secure connectivity to on-premise BOP networks.
  • Translate NIST and FedRAMP security control requirements into repeatable, reusable cloud architecture patterns.
  • Ensure system designs support Rapid ATO timelines through pre-approved architectures and secure design standards.
  • Develop and maintain system boundary diagrams, data flow diagrams, trust zone documentation, and other architectural artifacts required for ATO packages.
  • Support development of System Security Plans (SSPs) by providing architecture narratives and diagrams.
  • Collaborate with ISSOs, security assessors, engineers, and program stakeholders to ensure architectural decisions meet control implementation expectations.
  • Serve as a subject matter expert during security assessments, ATO reviews, and leadership briefings.

Required Skills:

  • Master's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Computer Engineering, Business, or a related field.
  • 10 years of experience designing and securing cloud and cloud security solutions within federal government systems.
  • 5 years of networking experience, including AWS native firewall services, AWS Direct Connect, AWS Outposts networking, reverse proxy architectures, and related automation.
  • 5 years of experience designing and implementing Continuous Monitoring (ConMon) solutions for cloud-based systems and applications.
  • 3 years of experience designing AI-enabled compliance automation tools capable of scanning cloud environments, collecting FedRAMP-specific evidence, storing artifacts centrally, and identifying unmet requirements.

Desired Skills:

  • Prior Department of Justice (DOJ) and/or Bureau of Prisons (BOP) experience and domain knowledge.
  • Strong experience analyzing security events, alerts, and reports generated by SIEM platforms such as Splunk.
  • Proficiency reviewing and interpreting outputs from AWS security services, including GuardDuty, Security Hub, and Amazon Inspector.
  • In-depth understanding of end-to-end data encryption in transit and at rest, including SSL/TLS implementation.
  • Demonstrated ability to identify vulnerabilities, particularly those related to data exposure, configuration drift, and tampering.

At Blake Willson Group, we believe in transparency and fairness in compensation practices. For this position, we offer a competitive salary range of $150,000 to $185,000 in the United States. Your individual salary within this range will be determined by various factors, including but not limited to your education, experience, skills, and geographic location. We also provide a comprehensive Total Rewards package, which includes major medical benefits such as dental and vision coverage, a 401(k)-contribution plan, holiday and personal time off, professional development training & certification benefits, health & wellness subsidies, paid time off for community service, and more. We value your contributions and are committed to recognizing and rewarding your performance and the value you bring to our business.

The statements above describe the general nature and level of work anticipated for this role. They are not intended to be an exhaustive list of all duties, responsibilities, or skills required. Blake Willson Group reserves the right to modify, assign, or add job-related responsibilities as business needs require. Where feasible, reasonable accommodations may be provided for individuals to perform essential job functions.
Blake Willson Group is an Equal Employment Opportunity (EEO) employer and is committed to maintaining a professional, respectful, and harassment-free workplace. All employment decisions are based on business needs, qualifications, and merit. We comply with all applicable federal, state, and local employment laws and do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, genetic information, or any other legally protected status. Blake Willson Group prohibits unlawful discrimination, harassment, and retaliation.
Blake Willson Group complies with federal equal employment opportunity requirements. The “Know Your Rights: Workplace Discrimination Is Illegal” poster is available to applicants and employees. View the official poster here: Know Your Rights: Workplace discrimination is illegal
If you require a reasonable accommodation during the application process, please contact us at 202-381-0603, Ext. 3.
Blake Willson Group participates in E-Verify to confirm employment eligibility and will provide the federal government with your Form I-9 information to verify authorization to work in the United States. 

Harnessing Technology to Improve Financial StewardshipBlake Willson Group (BWG) is a fast-growing firm delivering comprehensive professional services and technology solutions to Civilian, Defense, and Intelligence Community customers. Headquartered in Arlington, Virginia, Blake Willson Group has grown rapidly since its inception, securing consecutive years on the Inc. 5000 list, a prestigious honor designated for America’s most successful companies. We are internationally recognized for quality management practices and nationally recognized as a Continuing Professional Education (CPE) training provider. Built on our foundational values of Service to Others, Leadership, Diversity, Dependability, Integrity, and Grit, BWG commits to Empowering Our People and Improving Our Nation. Members of the Blake Willson Group team are passionate and enthusiastic, working towards a common goal of exceptional client support.

View all jobs
Salary
$150,000 – $185,000 per year
Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Cloud Security Architect Q&A's
Report this job
Apply for this job