Booz Allen Hamilton logo
Booz Allen HamiltonPosted 1 month ago

Cyber Data Platform Architect

$86,800–$198,000 year

On-siteArlington, Virginia, United States or Washington, District of Columbia, United States

Full TimeSenior LevelHigh School Or EquivalentEnterprise

Job Summary

Design security data pipeline architectures for cloud, managed services, and service-oriented architectures, resolving routine data architecture issues in collaboration with business analysts and technology teams. Lead the design of detection engineering pipelines, threat hunting workflows, and automated response capabilities while establishing processes to facilitate technological innovation. Deploy platforms across cloud, on-premises, and disconnected environments using orchestration tools such as Kubernetes and RedHat OpenShift, operating within classified or compartmented environments with strict access controls. This role requires 8+ years of experience in defensive cyber operations and 5+ years designing security data pipelines, including SIEM platforms and stream processing tools. Candidates must hold a TS/SCI clearance. Booz Allen delivers advanced technology solutions for America's defense, civil, and national security priorities.

Required Qualifications

  • 8+ years of experience in defensive cyber operations, cybersecurity engineering, or security platform architecture
  • 5+ years of experience designing security data pipeline architectures such as log collection, normalization, enrichment, and routing
  • 3+ years of experience with SIEM platforms such as Splunk Enterprise Security, Elastic Security, Microsoft Sentinel, and Google Chronicle, and stream processing and data brokering tools such as Cribl, Apache Kafka, Logstash, and Fluentd
  • Experience architecting detection engineering pipelines, threat hunting workflows, and automated response capabilities
  • Experience deploying platforms across cloud, on-premises, and disconnected environments using orchestration tools such as Kubernetes and RedHat OpenShift
  • Experience operating in classified or compartmented environments with strict access controls
  • Knowledge of Zero Trust, DoD or IC cybersecurity frameworks, and federal compliance standards
  • TS/SCI clearance
  • HS diploma or GED
  • Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information

Desired Qualifications

  • Experience with IC-specific authorization process such as ICD 503 or CNSSI 1253
  • Experience with cyber threat intelligence platforms, including STIX/TAXII integration
  • Experience with data lake and analytics platforms such as Databricks, Apache Iceberg, and Snowflake, and integrating EDR, NDR, and full-packet capture solutions, including CrowdStrike, Corelight, and Trellix
  • Experience with threat detection or anomaly-based behavioral analysis
  • Experience with SOAR platforms such as Swimlane, XSOAR, or Phantom
  • Experience with DevSecOps CI/CD pipelines in IL5 or IL6 environments
  • Experience with Python or scripting languages for security automation

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce