Cybersecurity Architect
KBR, Inc.About the role
Title:
Cybersecurity ArchitectProgram Summary:
KBR’s Mission Engineering Division delivers complex technical solutions and expert support to the U.S. Department of War, specializing in modeling and simulation, cyber transformation, air vehicle mission integration, and lifecycle support. As a trusted partner with a proven history in mission technology, KBR collaborates closely with clients to develop innovative and effective solutions. With a strong ethical framework, KBR prioritizes data security, privacy, and responsible information management to ensure mission success.
Job Summary:
The Cybersecurity Architect designs, implements, and maintains secure enterprise architectures aligned with Risk Management Framework (RMF) standards. This role ensures that systems, applications, and infrastructure incorporate robust security controls, effective access management, and regulatory compliance. The ideal candidate brings extensive experience supporting U.S. Government software programs, including the integration of Commercial Off-the-Shelf (COTS) solutions. They possess deep expertise in security policy, secure system design, and DevOps integration, with a proven ability to operate effectively in Agile/SAFe environments using Azure DevOps (ADO).
Roles and Responsibilities:
- Design and implement enterprise security architectures aligned with RMF (NIST Risk Management Framework) requirements
- Define and enforce security design principles across applications, infrastructure, and cloud environments
- Develop and maintain access control models, including RBAC, ABAC, identity governance, and least privilege strategies
- Ensure integration of security practices into DevOps pipelines (DevSecOps), including automated testing, code scanning, and secure deployment
- Work within SAFe Agile frameworks, participating in planning, architecture reviews, and continuous improvement initiatives
- Utilize Azure DevOps (ADO) for backlog management, CI/CD pipelines, and governance of secure development practices
- Conduct system security architecture reviews, threat modeling, and risk assessments
- Effectively collaborate with development, infrastructure, and business teams to embed security into system lifecycles
- Define and implement security controls, ensuring compliance with regulatory and organizational requirements
- Support Authority to Operate (ATO) processes and ensure proper documentation and RMF artifact development.
- Provide guidance on secure system integration and cloud security architecture
- Monitor evolving threat landscapes and adjust security architecture accordingly
- Develop and maintain security standards, policies, and architecture documentation
- Must possess exceptional communication skills.
Key Competencies
- Strategic thinking and system-level architecture design
- Strong analytical and risk assessment skills
- Excellent communication with both technical and non-technical stakeholders
- Ability to influence and guide secure development practices
- Continuous learning mindset aligned with evolving security threats
Work Environment
- Agile/SAFe collaborative team environment
- Integration with cross-functional teams (engineering, DevOps, compliance, operations)
- Cloud-first and security-focused enterprise ecosystem
Success Metrics
- Compliance with RMF and successful ATO outcomes
- Security posture improvements and risk reduction
- Effectiveness of DevSecOps integration
- Timely delivery of secure architecture solutions within SAFe increments
- Adoption of access control and security design best practices
Basic Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field (or equivalent experience)
- U.S. Citizen. Active DoD Secret clearance or higher required.
- 5+ years of experience in cybersecurity, with at least 3+ years in security architecture roles
- Experience supporting U.S. Government software programs
- Experience integrating Commercial Off-the-Shelf (COTS) Identity Management solutions
- Strong experience with NIST RMF and related frameworks (NIST 800-53, 800-37)
- Proven expertise in access control mechanisms (IAM, RBAC, ABAC, Zero Trust principles)
- Deep understanding of secure system and application design
- Hands-on experience integrating security into DevOps/DevSecOps pipelines
- Experience performing risk assessments, threat modeling, and vulnerability management <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s