Cybersecurity Architect

Idaho National LaboratoryIdaho Falls, ID
$95,256 - $234,336Onsite

About The Position

This role involves conducting in-depth security assessments of high-risk applications, cloud-native services, and architectures. The Cybersecurity Architect will continuously monitor and assess cloud environments (AWS/Azure) for misconfigurations and exposures, partnering with engineering teams to embed security controls into CI/CD pipelines. The position requires developing and maintaining cloud security and DevSecOps standards, reviewing cloud-native and application architectures for security-by-design, and assisting in the protection of critical cyber defense infrastructure. Responsibilities also include developing, implementing, and maintaining cyber security technical controls, analyzing cyber defense policies for compliance, and performing technical and non-technical risk and vulnerability assessments. The role involves identifying potential conflicts with cyber defense tools, implementing Risk Management Framework (RMF)/Security Assessment and Authorization (SA&A) requirements, and other duties as assigned. This position is multi-level and will be placed at the appropriate level (Level 3 or Level 4) dependent on depth and breadth of proven experience and skills.

Requirements

  • Bachelor's degree in computer science, computer engineering, or related field.
  • Level 3: Bachelor’s and 5 years of experience, OR Master’s and 2 years of experience, OR PhD and 2 years of experience.
  • Level 4: Bachelor’s and 9 years of experience, OR Master’s and 6 years of experience, OR PhD and 4 years of experience.
  • Experience with Cloud Services such as AWS and Azure.
  • Experience with Cloud Security Posture Management.
  • Experience commensurate with level.
  • Must be a US Citizen and have the ability to obtain and maintain a DOE “L” or “Q” clearance.

Nice To Haves

  • Masters degree in a related technical field including computer science, computer engineering, etc.
  • Experience with Crowdstrike Falcon Cloud Security

Responsibilities

  • Conduct in-depth security assessments of high-risk applications, cloud-native services, and architectures (deep design/code/config review beyond automated tool output) and deliver actionable, risk-prioritized findings directly to engineering leadership and business stakeholders.
  • Continuously monitor and assess cloud environments (AWS/Azure) for misconfigurations, excessive permissions, and policy drift using tooling. Identify and remediate exposures by working with relevant administrators such as open storage buckets, overly permissive IAM roles, unencrypted data stores, and insecure network configurations against benchmarks (CIS, NIST, cloud-provider well-architected frameworks).
  • Partner with engineering teams to embed security controls directly into CI/CD pipelines so vulnerabilities are caught pre-deployment. Provide hands-on guidance to developers on remediating findings and tuning tools to reduce false positives without slowing delivery.
  • Develop and maintain cloud security and DevSecOps standards (secure coding baselines, container/IaC hardening guides, branch/deploy approval gates) and map them to NIST compliance frameworks.
  • Review cloud-native and application architectures (microservices, containers/Kubernetes, serverless) for security-by-design, advising on secrets management, network segmentation, least-privilege IAM, and secure API design before and during build.
  • Assist in identifying, prioritizing, and coordinating the protection of critical cyber defense infrastructure and key resources. Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, security robustness).
  • Develop, implement, and maintain cyber security technical controls and operational systems.
  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives. Coordinate with intelligence analysts to correlate threat assessment data.
  • Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications).
  • Identify potential conflicts with implementation of any cyber defense tools (e.g., tool and signature testing and optimization).
  • Implement Risk Management Framework (RMF)/Security Assessment and Authorization (SA&A) requirements for dedicated cyber defense systems within the enterprise, and document and maintain records.
  • Other duties as assigned

Benefits

  • Compensation decisions are determined using factors such as education, relevant experience, and other credentials.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service