Caliola logo
CaliolaPosted 1 month ago

Lead Infrastructure and Cybersecurity Architect

$150,000–$185,000 year

On-siteColorado Springs, Colorado, United States

Full TimeSenior LevelSmall

Job Summary

Design, build, and maintain secure, resilient, and scalable core infrastructure across on-premises, cloud, hybrid, and multi-site environments while driving modernization initiatives including cloud integration, virtualization, and Infrastructure as Code automation. Evaluate, integrate, and govern enterprise network technologies, implement security monitoring technologies, and architect secure cloud and hybrid architectures using Microsoft Entra ID and Azure Government environments. Lead technical implementation of GRC controls aligned with CMMC Level 2, NIST SP 800-171, and DoD cybersecurity requirements, providing hands-on support during security incidents and overseeing disaster recovery strategies. Partner across engineering, cybersecurity, compliance, and program teams to embed security throughout the system lifecycle, mentor technical staff, and prepare technical roadmaps for infrastructure and compliance sustainment.

Required Qualifications

  • Active Secret Clearance
  • Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field, or equivalent professional experience
  • 10+ years of progressive experience in enterprise infrastructure architecture, network engineering, cybersecurity architecture, cloud security, systems architecture, or related technical roles
  • Experience supporting DoD, Federal Government, defense contractor, or similarly regulated environments
  • Advanced knowledge of enterprise network and infrastructure architecture, including routing, switching, firewalls, VPNs, wireless, VLANs, network segmentation, secure connectivity, and high availability / disaster recovery architectures
  • Experience designing, administering, or supporting Microsoft GCC High, Azure Government, or comparable secure cloud, identity, endpoint, collaboration, monitoring, or data protection environments
  • Strong working familiarity with CMMC Level 2, NIST SP 800-171, RMF, DFARS cybersecurity requirements, DISA STIGs, and related DoD cybersecurity expectations
  • Hands-on experience with security hardening, vulnerability management, vulnerability remediation, configuration baselines, endpoint protection, access control, logging, SIEM/security monitoring, and incident response support, including Microsoft Sentinel or comparable platforms
  • Ability to translate business, program, compliance, engineering and emerging technology needs into secure technical architecture, implementation plans, and operational documentation
  • Ability to mentor technical teammates, collaborate effectively across engineering, cybersecurity, compliance, facilities, and program teams, and influence outcomes without direct management authority
  • Must possess exceptional written and verbal English communication skills, with the ability to convey complex technical concepts to both technical and non-technical audiences
  • Ability to multitask across multiple programs, manage competing priorities, and maintain high focus in a fast-paced environment
  • Ability to navigate an office or server room setting, including prolonged periods at a workstation
  • Ability to bend, kneel, crouch, or reach to install, inspect, or maintain IT hardware, server racks, and cabling
  • Close visual acuity required for analyzing data, engineering diagrams, and extensive reading
  • Fine motor skills and dexterity to manipulate small technical devices and components
  • Ability to occasionally lift, move, and set up infrastructure equipment weighing up to 35 lbs

Desired Qualifications

  • Active Top Secret or TS/SCI security clearance
  • Direct involvement in CMMC Level 2 sustainment, C3PAO or DIBCAC assessments, secure rooms, classified systems, SSPs, POA&Ms, audit evidence, and continuous compliance
  • Deep knowledge of Microsoft GCC High, Azure Government, Entra ID, Intune, Defender, Sentinel, Purview, Conditional Access, MFA/PIM, Zero Trust Architecture, FedRAMP, DoD SRG, or related federal cloud/security frameworks
  • Familiarity with Cisco, Palo Alto, Fortinet, Aruba, Juniper or comparable network platforms
  • Windows/Linux server administration and infrastructure automation using tools such as Windows Server, Ubuntu, RHEL, Terraform, Ansible, Bicep, PowerShell, Bash, or Python
  • Secure AI architecture and governance, including approved tools, workflows, access controls, logging, monitoring, and data boundary protections
  • Relevant certifications such as CISSP, CISM, CCNP, CCIE, Microsoft Cybersecurity Architect Expert, Microsoft Azure Solutions Architect Expert, Certified CMMC Professional, Security+, Network+, or SANS/GIAC

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce