Principal Cloud Security Architect

INFT Solutions Inc


Job Location:

Madison, WI - USA

Monthly Salary: Not Disclosed
Posted on: 2 hours ago
Vacancies: 1 Vacancy

Job Summary

Job Opening title: Principal Cloud Security Architect

Job Location: MadisonWisconsin

2. Scope

The consultant shall perform hands-on engineering deliver strategic CISO advisoryand provide direct mentoring across the following core operational pillars:

2.1 CISO Strategic Advisory and Engineering

Act as a direct technical advisor to the CISO translating federal mandatesemerging AI threat models and architectural gaps into actionable enterprisesecurity directives.

Execute a hands-on knowledge transfer model co-engineering data pipelinesand security automation alongside internal DET staff to institutionalize elitetechnical skills.

Deliver real time training and co-develop automation playbooks within thesecurity operations (SecOps) using live demonstration approach.

2.2 Flaw Remediation (SI-2) Standard Operationalization

Tier Optimization & Enforcement: Architect automated tracking logging andvalidation mechanisms to implement compliance with the States updated SI-2timeframes:

o Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities CISAKEV listings active exploits and identity/privileged system flawsimplement approved mitigations or compensating controls within 24

hours with full remediation closed inside 7 calendar days.

o Tier 2 (High-Risk/Internal): Configure alerting and metric reporting tovalidate mitigation within 48 hours and full remediation within 15 calendardays.

o Tier 3 (Moderate/Low): Establish repeatable monthly scheduling toensure remediation within 30 calendar days.

Clean Deployment Architectures: Partner with agency development teams topivot away from manual in-place patching. Author and implement automatedtemplates for clean deployments using virtualized system images containers and cloud-native configurations.

DevSecOps Integration: Embed secure builds automated software testingcode scanning and dependency updates natively into agency deploymentpipelines.

2.3 AI Capability Deployment & Toolchain Integration

Operationalize Gemini Government and Google Codemender or equivalentdirectly inside active workflows showing security analysts and applicationdevelopers how to leverage generative AI to automate log parsing threat

hunting and source-code remediation.

Engineer automated data pipelines to feed the centralized enterprise platform(incorporating telemetry from Google Mandiant ASM Microsoft AzureArc Splunk and Google SecOps) to maintain a single authoritative pane ofglass.

Ensure all AI-assisted capabilities comply strictly with State privacy dataclassification and logging safeguards preventing non-public vulnerability metricsfrom leaking into unvetted environments.

2.4 Governance Safeguards & Escalation Automation

Build automated low-code workflows to manage the SI-2 time-bound exceptionlifecycle ensuring every granted exception maps back to a named ownerspecific compensating controls and an explicit financial tiedown capturing

technical debt.

Configure automated alert thresholds and workflow routing for significantbusiness risks that exceed normal management tolerance ensuring rapidescalation in line with the SI-2 update.

3. Project Timeline

4. Minimum Qualifications and Core Competencies

The designated expert must demonstrate a unique blend of strategic advisory presenceand deep practical engineering capability:

Executive Advisory: Proven experience serving as a trusted technical advisorto CISOs CIOs or senior executive leaders within public sector or heavily

federated enterprise environments.

Teach-by-Doing Expertise: Documented success as a technical mentor traineror engineering lead focused on pair-engineering and technical upskilling of

infrastructure and security operations staff.

Security Control Mastery (SI-2): Comprehensive expertise operationalizingsecurity controls including tiering models compensating control validation and

time bound risk governance structures.

Advanced Tooling Fluency: enterprise cyber stack Google Threat Intel orVirusTotal Google SecOps Mandiant ASM Microsoft Azure Arc GitHub GitHub Advanced Security Ansible Tower and Gemini/Anthropic AI

security frameworks.

Cloud Architecture & DevSecOps Engineering

5. Performance Monitoring & Safeguards

Knowledge Transfer Auditing: Progress will be measured not only by technicaldeployment velocity but also by the documented proficiency gains of internalDET staff who assume ownership of the deployed tools.

Data Isolation Guardrails: The consultant is strictly forbidden from utilizingpublic or unvetted commercial AI models for analyzing State code logs or assetdata. All engineering must occur exclusively within authorized state-managedenterprise security instances.

Requirements

Top Required Skills & Years of Experience:

Must be able to demonstrate prior experience doing the following in a large/complex environment:

- Proven experience serving as a trusted technical advisor to CISOs CIOs or senior executive leaders within public sector or heavily federated enterprise environments.

- Documented success as a technical mentor trainer or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.

- Comprehensive expertise operationalizing security controls including tiering models compensating control validation and time bound risk governance structures.

- Enterprise cyber stack Google Threat Intel or VirusTotal Google SecOps Mandiant ASM Microsoft Azure Arc GitHub GitHub Advanced Security Ansible Tower and Gemini/Anthropic AI security frameworks.

-Cloud Architecture & DevSecOps Engineering

Nice to have Skills:

-Federated/Government environment

-Tech Stack to include: Google Microsoft AWS Splunk


Required Skills:

Cloud

Job Opening title: Principal Cloud Security Architect Job Location: MadisonWisconsin 2. Scope The consultant shall perform hands-on engineering deliver strategic CISO advisoryand provide direct mentoring across the following core operational pillars: 2.1 CISO Strategic Advisory and Engineering Act...