Cloud Network Security Architecture Manager (TIC 3.0)

gdit

Martinsburg (WV)

Hybrid

USD 115,000 - 155,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

GDIT is seeking a Cloud Network Security Architecture Manager to lead TIC 3.0‑aligned, Zero‑Trust‑enabled security architectures across VAs hybrid and multi‑cloud environments in Martinsburg/Austin. You will transform legacy perimeter models into trust zones, PEP‑based enforcement, and cloud‑native controls with continuous monitoring.

You will design and manage trust zones, guide PEP implementations, and integrate with SIEM pipelines while mentoring engineers and coordinating with multiple

Qualifications

  • Bachelors degree or equivalent experience.
  • Hands-on design or support of federal-grade Zero-Trust architectures.
  • Experience with TIC 3.0 concepts, trust zones, distributed enforcement.
  • Background in cloud, network, or security architecture (AWS, Azure, hybrid networking).
  • Hands-on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations.
  • Strong knowledge of NIST CSF, NIST SP 800-207 (ZTA), NIST SP 800-53.
  • Experience with automation, scripting, or IaC (Terraform, Ansible, CloudFormation, ARM templates).
  • Effective communicator able to coordinate across multiple teams.
  • Ability to support emergency incidents, escalations, and critical events.

Responsibilities

  • Lead TIC 3.0 modernization, shifting security to distributed trust zones and PEP-based enforcement.
  • Architect Zero-Trust, identity-centric controls, segmentation, and dynamic policy enforcement.
  • Design and manage trust-zone mappings, cloud boundary protections, and secure interconnects.
  • Guide implementation of policy enforcement points across cloud, on-prem, remote, and mobile use cases.
  • Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
  • Partner with engineering, cyber, SOC, network, and operations teams to embed security.
  • Oversee gateway transformation, including redesign and modernization aligned with TIC 3.0.
  • Communicate architectural decisions, risks, and modernization strategies to VA leadership.
  • Evaluate emerging technologies and lead pilots and PoCs for adoption strategies.
  • Support escalations and critical events involving cloud networks and identity systems.
  • Produce architecture diagrams, trust-zone definitions, PEP mappings, and compliance artifacts.
  • Mentor engineers and promote security best practices across teams.

Skills

Cloud Platform
IT Service Management (ITSM)
Network Architecture

Education

Bachelors degree or equivalent experience

Job description

Type of Requisition

Regular

Clearance Level Must Currently Possess

None

Clearance Level Must Be Able to Obtain

None

Public Trust/Other Required

MBI (T2)

Job Family

IT Infrastructure and Operations

Job Qualifications
Skills

Cloud Platform, IT Service Management (ITSM), Network Architecture

Certifications

None

Experience

10 + years of related experience

US Citizenship Required

No

Job Description

Join GDIT in modernizing the Department of Veterans Affairs’ network security posture under the NEDIIS program. As the Cloud Network Security Architecture Manager, you will lead the design and implementation of TIC 3.0‑aligned, Zero‑Trust‑enabled, distributed security architectures across VA’s hybrid and multi‑cloud environments.

This role transforms legacy perimeter models into risk‑based trust zones, policy enforcement points (PEPs), cloud‑native security controls, and continuous monitoring‑integrated architectures, consistent with evolving federal cybersecurity guidance.

How You Will Make an Impact
  • Lead TIC 3.0 modernization, shifting security from centralized gateways to distributed trust‑zone and PEP-based enforcement across AWS, Azure, and enterprise networks.
  • Architect Zero‑Trust‑aligned identity‑centric controls, segmentation, dynamic policy enforcement, and continuous validation.
  • Design and manage trust‑zone mappings, cloud boundary protections, secure interconnects, and mission‑aligned risk‑based traffic flows.
  • Guide implementation of policy enforcement points for cloud, on‑prem, remote, and mobile use cases.
  • Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
  • Partner with engineering, cyber, SOC, network, and operations groups to embed security across distributed systems.
  • Oversee gateway transformation, including redesign, scaling, load distribution, and modernization aligned with TIC 3.0.
  • Communicate architectural decisions, risks, and modernization strategies to VA leadership.
  • Evaluate emerging technologies, lead pilots/proofs of concept, and recommend mission‑aligned adoption strategies.
  • Support escalations and critical events involving cloud networks, identity systems, boundary controls, and PEP operations.
  • Produce architecture diagrams, trust‑zone definitions, PEP mappings, documentation, and compliance artifacts.
  • Mentor engineers and promote security best practices across cloud and network architecture teams.
What You’ll Need to Succeed
  • Bachelor’s degree or equivalent experience.
  • Hands‑on experience designing or supporting federal‑grade, Zero‑Trust‑aligned architectures (identity‑centric access, micro‑segmentation, encrypted traffic inspection, cloud boundary protections).
  • Experience with TIC 3.0 concepts, trust zones, distributed enforcement, and cloud/mobility use cases is required.
  • Background in cloud, network, or security architecture (AWS, Azure, hybrid networking, segmentation).
  • Hands‑on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations.
  • Strong understanding of NIST Cybersecurity Framework, NIST SP 800‑207 (ZTA), NIST SP 800‑53, and broader federal cybersecurity standards.
  • Experience with automation, scripting, or IaC (Terraform, Ansible, CloudFormation, ARM templates).
  • Effective communicator able to coordinate across multiple teams.
  • Ability to support emergency incidents, escalations, and critical events.
Preferred (Not Required)
  • AWS Solutions Architect – Professional
  • Azure Solutions Architect Expert
  • Kubernetes / OpenShift (CKA / CKAD)
  • VMware certifications
  • Terraform Associate

Visa sponsorship will not be provided for this position.

Security & Location

Public Trust clearance required.

Hybrid position in Martinsburg, WV or Austin, TX – must work a regular weekly schedule with 2 to 3 days onsite as needed.

Visa sponsorship will not be provided for this position.

GDIT IS YOUR PLACE
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY

Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours

40

Travel Required

Less than 10%

Telecommuting Options

Hybrid

Work Location

USA WV Martinsburg

Total Rewards at GDIT
  • Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • To ensure our employees are able to protect their income, other offerings such as short and long‑term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
  • We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Network Security Architecture Manager (TIC 3.0)
Cloud Network Security Architecture Manager (TIC 3.0)

General Dynamics Information Technology • Martinsburg (WV)

Hybrid
USD 115,000 - 155,000
Hybrid work model
Competitive benefits
401K with company match
Cloud Network Security Architecture Manager (TIC 3.0)
Cloud Network Security Architecture Manager (TIC 3.0)

General Dynamics Information Technology, Inc. • Martinsburg (WV)

Hybrid
USD 115,000 - 155,000
Enterprise Architect
Enterprise Architect

gdit • Falls Church (VA)

Hybrid
USD 119,000 - 161,000
401(k) with company match
Paid time off
Health insurance options
Principal Network Engineer - Cloud
Principal Network Engineer - Cloud

General Dynamics Corporation • Springfield (VA)

On-site
USD 128,000 - 173,000
Principal Network Engineer - Cloud
Principal Network Engineer - Cloud

General Dynamics Information Technology, Inc. • Newington (VA)

Hybrid
USD 128,000 - 173,000
401K with company match
Paid time off
Flexible work weeks
+1
Cloud Administrator - TS/SCI with Polygraph
Cloud Administrator - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • Vienna (VA)

On-site
USD 162,000 - 219,000
401K with company match
Health and wellness packages
Internal mobility and career growth
+3
Network Engineer (Cloud) - TS/SCI with Polygraph
Network Engineer (Cloud) - TS/SCI with Polygraph

gdit • Vienna (VA)

On-site
USD 162,000 - 219,000
401K with company match
Comprehensive health packages
Professional growth & certifications
+2
Network Architect
Network Architect

General Dynamics Information Technology, Inc. • Washington

On-site
USD 170,000 - 229,000
Flex work weeks
Paid time off
401(k) with company match
+2
Solutions Architect/Lead
Solutions Architect/Lead

General Dynamics Information Technology, Inc. • Arlington (VA)

On-site
USD 153,000 - 207,000
Growth opportunities
Internal mobility team
Competitive pay & benefits
Information Security Director
Information Security Director

gdit • Bellevue Second IV Precinct (NE)

On-site
USD 170,000 - 205,000
Health benefits
401(k) with company match
Educational assistance and eLearning
+3