Full-Time

Cloud Security Architect / Engineer

Posted on 9/4/2026

9th Way Insignia

9th Way Insignia

51-200 employees

AI-enabled federal IT, cybersecurity, and automation

Compensation Overview

$98.1k - $150k/yr

Washington, DC, USA

In Person

Bachelor's

Category
Cybersecurity
Required Skills
FedRAMP
Threat modeling
Cybersecurity
DevOps
HIPAA

Get referred to 9th Way Insignia

See people who can refer or advise you

Requirements
  • At least 10 years of information security experience, including at least 5 years of cybersecurity and cloud security experience at a large government agency similar in size and scope to GSA, IRS, DoD, or VA.
  • Expertise in incorporating cybersecurity architecture, engineering requirements, and authorizations, including FedRAMP and the Risk Management Framework, into systems and applications.
  • Expertise in information technology and cloud security architecture design, security engineering, development, systems engineering, and implementation efforts.
  • Expertise with cloud solutions in the federal and/or commercial industry.
  • Expertise with Federal Assessment and Authorization and Authority to Operate activities.
  • Expertise with security compliance requirements and regulatory standards, including NIST, FISMA, FedRAMP, CIS Controls, and HIPAA.
Responsibilities
  • Design, develop, assess, and implement secure cloud architectures and engineering solutions supporting VA enterprise systems, applications, platforms, and modernization initiatives.
  • Translate cybersecurity, business, technical, and regulatory requirements into practical cloud security architectures, controls, engineering requirements, and implementation approaches.
  • Integrate FedRAMP and Risk Management Framework requirements into cloud systems, applications, platforms, and technical solutions.
  • Support Federal Assessment and Authorization and Authority to Operate activities for cloud-based systems and services.
  • Apply Zero Trust, defense-in-depth, least privilege, and secure-by-design principles to cloud architecture and engineering decisions.
  • Conduct security architecture reviews, cloud architecture risk and gap analyses, threat modeling, security posture reviews, and compliance assessments for cloud systems and services.
  • Identify architectural weaknesses, security-control gaps, configuration risks, compliance deficiencies, attack paths, and residual risks, and recommend mitigation strategies or compensating measures.
  • Review cloud solution designs, applications, platforms, networks, identity services, data architectures, and technical design artifacts for security risks and incorporated security requirements.
  • Develop Security Reference Architectures, Solution Architectures, Security Patterns, reusable cloud security design guidance, configuration baselines, security requirements, configuration reports, and security assessment reports.
  • Document logical, physical, conceptual, and data-flow architectures for cloud solutions and supporting enterprise integrations.
  • Provide cloud-security subject matter expertise during technical design reviews, architecture reviews, pilots, modernization initiatives, and enterprise transformation efforts.
  • Evaluate existing environments and recommend migration, re-architecture, modernization, or security-hardening approaches.
  • Assess cloud-native platforms against approved security baselines, identify configuration deviations and compliance gaps, and recommend remediation actions.
  • Support lifecycle governance, traceability, and authorization by gathering, validating, and maintaining evidence demonstrating implementation of required security controls.
  • Identify, evaluate, monitor, and communicate cloud cybersecurity risks using Federal and VA risk-management processes.
  • Evaluate cloud services and architectures for compliance with NIST, FISMA, FedRAMP, CIS Controls, HIPAA, VA security, and privacy requirements.
  • Support implementation of cloud identity and access-management, networking, data protection, application security, infrastructure hardening, integration, lifecycle management, and security-tool requirements.
  • Assist system owners and technical teams in resolving ATO, accreditation, security-control, and compliance issues associated with cloud services.
  • Collaborate with DevSecOps engineers, cybersecurity architects, security engineers, developers, system owners, risk and compliance analysts, program managers, and Government stakeholders throughout the cloud solution lifecycle.
  • Provide technical input into VA security policies, standards, guidelines, technical positions, white papers, and risk-mitigation recommendations involving cloud technologies.
  • Develop technical briefings and presentations explaining cloud architecture, risk posture, security findings, compliance status, and recommended courses of action to technical and executive stakeholders.
  • Participate in VA governance boards, technical-review committees, architecture forums, and engineering working groups involving cloud security or modernization.
  • Monitor emerging threats, technology changes, compliance requirements, and evolving Federal cloud-security standards to support continuous improvement.
  • Ensure cloud architectures remain aligned with enterprise security architecture, modernization initiatives, technology roadmaps, and Government strategic objectives throughout their lifecycle.
Desired Qualifications
  • Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field.
  • CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, or CCNP Security certification.

9th Way Insignia is a Service-Disabled Veteran-Owned Small Business that delivers AI-enabled digital solutions to U.S. federal agencies. Founded in 2018 and expanded through its 2019 acquisition of Insignia Technology Services, it offers cybersecurity, automation, data science, and artificial intelligence services, partnering with platforms such as ServiceNow and Alteryx to modernize legacy systems and secure critical infrastructure. What sets 9th Way Insignia apart is its veteran-led leadership, ISO 9001:2015 and CMMI Level 2 certified quality management, and a people-first culture rooted in innovation over convention. The goal is to help government clients cut costs, strengthen security, and improve mission performance through intelligent automation.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Ashburn, Virginia

Founded

2006

Get referred to 9th Way Insignia

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • March 31, 2026 USPTO SMP win added $28M of backlog.
  • January 2026 SHIELD IDIQ and December 2025 EASS wins widened defense and civilian exposure.
  • July 10, 2026 promoted Kimberly Cole to Chief Performance Officer, signaling operational scaling.

What critics are saying

  • Revenue concentration in federal contracting ties growth to agency procurement cycles.
  • USPTO, MDA, and VA recompetes decide whether 2026 wins become durable revenue.
  • A lost major vehicle, especially USPTO SMP, would crush utilization and trigger layoffs.

What makes 9th Way Insignia unique

  • SDVOSB status opens federal set-asides other IT vendors cannot touch.
  • ServiceNow-heavy federal delivery aligns with USPTO SMP and other agency modernization work.
  • Portfolio spans VA T4NG, GSA, Navy Seaport NxG, and MDA SHIELD vehicles.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

401(k) Retirement Plan

Paid Vacation

Paid Holidays

Health Savings Account/Flexible Spending Account