An application made for this job — a tailored resume and cover letter that speak straight to the posting.
General Dynamics IT in the United States is seeking a Cloud Network Security Architecture Manager to lead TIC 3.0 modernization across VA's hybrid and multi‑cloud environments, transforming legacy perimeter models into distributed trust zones with policy enforcement points.
This role demands designing Zero‑Trust‑aligned, identity‑centric controls, segmentation, dynamic policy enforcement, and continuous validation.
Type of Requisition: Regular
Clearance Level Must Currently Possess: None
Clearance Level Must Be Able to Obtain: None
Public Trust/Other Required: MBI (T2)
Job Family: IT Infrastructure and Operations
Skills: Cloud Platform, IT Service Management (ITSM), Network Architecture
Certifications: None
Experience: 10 + years of related experience
US Citizenship Required: No
Join GDIT in modernizing the Department of Veterans Affairs' network security posture under the NEDIIS program. As the Cloud Network Security Architecture Manager , you will lead the design and implementation of TIC 3.0‑aligned, Zero‑Trust‑enabled, distributed security architectures across VA's hybrid and multi‑cloud environments.
This role transforms legacy perimeter models into risk‑based trust zones, policy enforcement points (PEPs), cloud‑native security controls, and continuous monitoring‑integrated architectures , consistent with evolving federal cybersecurity guidance.
Lead TIC 3.0 modernization , shifting security from centralized gateways to distributed trust‑zone and PEP-based enforcement across AWS, Azure, and enterprise networks.
Architect Zero‑Trust‑aligned identity‑centric controls, segmentation, dynamic policy enforcement, and continuous validation.
Design and manage trust‑zone mappings , cloud boundary protections, secure interconnects, and mission‑aligned risk‑based traffic flows.
Guide implementation of policy enforcement points for cloud, on‑prem, remote, and mobile use cases.
Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
Partner with engineering, cyber, SOC, network, and operations groups to embed security across distributed systems.
Oversee gateway transformation , including redesign, scaling, load distribution, and modernization aligned with TIC 3.0.
Communicate architectural decisions, risks, and modernization strategies to VA leadership.
Evaluate emerging technologies, lead pilots/proofs of concept, and recommend mission‑aligned adoption strategies.
Support escalations and critical events involving cloud networks, identity systems, boundary controls, and PEP operations.
Produce architecture diagrams, trust‑zone definitions, PEP mappings, documentation, and compliance artifacts.
Mentor engineers and promote security best practices across cloud and network architecture teams.
Bachelor's degree or equivalent experience.
Hands‑on experience designing or supporting federal‑grade, Zero‑Trust‑aligned architectures (identity‑centric access, micro‑segmentation, encrypted traffic inspection, cloud boundary protections).
Experience with TIC 3.0 concepts , trust zones, distributed enforcement, and cloud/mobility use cases.
Background in cloud, network, or security architecture (AWS, Azure, hybrid networking, segmentation).
Hands‑on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations .
Strong understanding of NIST Cybersecurity Framework, NIST SP 800‑207 (ZTA), NIST SP 800‑53 , and broader federal cybersecurity standards.
Experience with automation, scripting, or IaC (Terraform, Ansible, CloudFormation, ARM templates).
Effective communicator able to coordinate across multiple teams.
Ability to support emergency incidents, escalations, and critical events.
AWS Solutions Architect - Professional
Azure Solutions Architect Expert
Kubernetes / OpenShift (CKA / CKAD)
VMware certifications
Terraform Associate
Visa sponsorship will not be provided for this position.
This role will require you to obtain and maintain Public Trust Suitability and will require you to provide onsite fingerprinting at a designated facility. This investigation may review personal and criminal behavior, financial conduct, foreign influence, as well as other adjudications.
Public Trust clearance required.
Hybrid position in Martinsburg, WV or Austin, TX - must work a regular weekly schedule with 2 to 3 days onsite as needed.
Visa sponsorship will not be provided for this position.
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.
The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set base