Security Architect | IT Security Senior Specialist

State of WashingtonMultiple Locations Statewide, WA
Hybrid

About The Position

This is a telework/hybrid position. The candidate of choice may work from anywhere within the state of Washington with a reliable internet connection. Travel may be required. This recruitment is open to current, permanent DOC employees only. Are you a cybersecurity professional who thinks beyond today’s threats and plans for what’s next? As a Security Architect (IT Security Senior Specialist), you’ll play a critical role in protecting the Washington State Department of Corrections’ technology and information by building security into the design of enterprise systems from the ground up. In this position, you’ll have a cradle-to-grave role in designing, analyzing, and implementing new technology and equipment within the Department’s enterprise network architecture. You’ll evaluate solutions throughout their lifecycle and ensure cybersecurity controls are incorporated early in the design and implementation process, helping identify and address vulnerabilities before they become risks. Collaboration is key as you will work closely with stakeholders across the Department, Washington State, and federal agencies to assess security requirements, develop effective controls, and ensure technology solutions meet established cybersecurity standards. Your attention to detail and ability to anticipate potential threats will be essential in protecting the Department’s systems, data, and operations from cyberattacks and security breaches. This is an opportunity to make a meaningful impact through cybersecurity. Your expertise will help strengthen DOC’s technology environment, reduce risk, and protect the systems and information that support the Department’s mission of improving public safety.

Requirements

  • High school diploma or equivalent
  • A minimum of four years dedicated continuous work with in the information technology field.
  • A minimum of two years cumulative experience in network or security design review on information systems in an organization with at least 1,000 employees or staff
  • One-year, professional IT experience, in a cybersecurity awareness role OR An Associate degree or higher in computer science, information assurance or related field from an accredited institution whose accreditationisrecognizedbytheU.S.DepartmentofEducation or the Council for Higher Education Accreditation (CHEA), or a foreign equivalent
  • A minimum of four years dedicated continuous work with in the information technology field.
  • A minimum of two years cumulative experience in network or security design review on information systems in an organization with at least 1,000 employees or staff
  • Knowledge of computer networking fundamentals
  • Knowledge of how system components are installed, integrated, and optimized
  • Knowledge of industry-standard and organizationally accepted analysis principles and methods
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of Defense-in-Depth)

Nice To Haves

  • At least one of the following professional Level-2 certifications as defined by the Department of Defense 8570.01 -M Information Assurance Workforce Improvement Program such as Security+, GSEC, CISSP, SCNP or SSCP
  • Bachelor's degree or higher in Computer Science or related field in information management, information security or cyber security from an accredited institution whose accreditation is recognized by the U.S. Department of Education or the Council for Higher Education Accreditation (CHEA)
  • At least one of the following computing environment certifications, Certified Risk and Information Systems Controls (CRISC), Global Information Assurance Certifications — Certified Intrusion Analyst (GCIA) or, Certified Incident Handler (GCIH), or EC-Council Certified Security Analyst (ECSA)
  • IT Security expertise in ICS/PCD environments
  • Relevant architectural experience and knowledge at the global enterprise level
  • An understanding of 'Next Gen' ICS solutions
  • Experience architecting and implementing SIEM, AV, Web Content Filtering, DLP, IDS/IPS, and Vulnerability Management solutions
  • Experience (or familiarity) with SANs ICS and NIST 800-82 R2 concerning industrial control systems
  • Experience in network security audits and compliance monitoring for wireless devices, modems, encryption systems, IT cyber security policies, programs, standards and procedures
  • Knowledge of encryption algorithms (e.g., IPSEC, AES, GRE, IKE, MD5, SHA, 3DES)
  • Knowledge of IT security principles and methods, such as firewalls, demilitarized zones, and encryption
  • Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol (TCP) and Internet Protocol (IP), Open System Interconnection Model (OSI), Information Technology Infrastructure Library, v3 (ITIL))
  • Skill in applying and incorporating IT technologies into proposed solutions
  • Knowledge of access authentication methods
  • Knowledge of computer algorithms
  • Knowledge of computer networking fundamentals
  • Knowledge of cryptology
  • Knowledge of database systems
  • Knowledge of embedded systems
  • Knowledge of encryption algorithms (e.g., IPSEC, AES, GRE, IKE, MD5, SHA, 3DES)
  • Knowledge of fault tolerance
  • Knowledge of how system components are Installed, integrated, and optimized
  • Knowledge of human-computer interaction principles
  • Knowledge of CIA principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Knowledge of industry-standard and organizationally accepted analysis principles and methods
  • Knowledge of information theory
  • Knowledge of interpreted and compiled computer languages
  • Knowledge of IT architectural concepts and frameworks
  • Knowledge of IT security principles and methods, such as firewalls, demilitarized zones, and encryption
  • Knowledge of IT supply chain security/risk management policies, requirements, and procedures
  • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not be used standard IT) for safety, performance, and reliability
  • Knowledge of microprocessors
  • Knowledge of network access, identity and access management (e.g., public key infrastructure, PKI)
  • Knowledge of network design processes, to include understanding of security objectives, operational objectives, and tradeoffs
  • Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools
  • Knowledge of operating systems
  • Knowledge of organization's enterprise information security architecture system
  • Knowledge of organization's evaluation and validation requirements
  • Knowledge of parallel and distributed computing concepts
  • Knowledge of risk management processes', including steps and methods for assessing risk
  • Knowledge of secure configuration management techniques
  • Knowledge of Security Assessment and Authorization process
  • Knowledge of security management
  • Knowledge of security system design tools, methods, and techniques
  • Knowledge of server and client operating systems
  • Knowledge of software engineering
  • Knowledge of system design tools, methods, and techniques, including automated systems analysis and design tools
  • Knowledge of system testing and evaluation methods
  • Knowledge of technology integration processes
  • Knowledge of the enterprise IT architecture
  • Knowledge of the methods, standards, and approaches for describing, analyzing, and documenting an organization's enterprise IT architecture (e.g., Open Group Architecture Framework (TOGAF), Department of Defense Architecture Framework (DODAF)
  • Knowledge of the organization
  • Knowledge of the systems engineering process
  • Skill in applying and incorporating IT technologies into proposed solutions
  • Skill in designing the integration of hardware and software solutions
  • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks
  • Skill in the use of design modeling (e.g., unified modeling language)

Responsibilities

  • Assuming the role of Subject Matter Expert (SME) for security architecture, technical and administrative security controls, and security best business practices for applications, information systems, and network infrastructure which could include: Representing the Cybersecurity Unit as a voting member in Architecture Board, Change Control, and Release Coordination
  • Representing the Department as the lead technical security point of contact for State level Security Design reviews
  • Developing and maintaining the Department’s Cybersecurity architecture guidance and governance by documenting design specifications, installation instructions, and other system-related information to address the organization's information security, information assurance, and systems security engineering/architecture requirements
  • Advising on industry standards and best practices as they relate to current Cybersecurity trends and Department security architecture
  • Researching emerging IT cyber security trends
  • Maintaining up to date knowledge and information regarding vulnerabilities
  • Developing tactical and strategic plans for the Department's IT cyber security infrastructure and providing expert guidance to IT executives for planning and implementation which could include: Consulting with agency project managers and stakeholders to ensure that cybersecurity requirements are coordinated and implemented in all phases of the project, from start to finish
  • Analyzing business needs to plan security architecture requirements for systems
  • Collaborating with third party vendors, system developers, and users to select appropriate security solutions
  • Determining security requirements by evaluating business strategies and requirements
  • Researching information security best business practices, industry standards, and Federal/State regulation standards
  • Conducting cost to benefit analysis for monetary and business impact to the Department using an impact and likelihood based assessment process

Benefits

  • Comprehensive family insurance for medical, dental, and vision
  • Remote/telework/flexible schedules (depending on position)
  • Up to 25 paid vacation days a year
  • 8 hours of paid sick leave per month
  • 12 paid holidays a year
  • Generous retirement plan
  • Flex Spending Accounts
  • Dependent Care Assistance
  • Deferred Compensation
  • Bereavement leave (Teamsters 117 represented positions receive 3 days)
  • Washington Public Employees' Retirement System (PERS)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service