Cyber Security Architect

GDH

St. Louis (MO)

Remote

USD 110,000 - 124,000

Full time

34 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

GDH is seeking a Cybersecurity Architect to design and implement Comply-to-Connect (C2C) policy frameworks across enterprise environments. This role provides technical leadership for C2C implementation, translating current security requirements into actionable designs and deployment strategies.

The position develops technical documentation, conducts gap analyses, and collaborates with stakeholders to support effective cybersecurity policy integration and enforcement.

Qualifications

  • 10+ years in cybersecurity or network security, incl. 5+ years NAC/Zero Trust/C2C design.
  • Active Secret clearance required.
  • Experience deploying NAC/C2C for large-scale environments.
  • Strong knowledge of 802.1X, EAP-TLS, MAB, CoA, RADIUS/TACACS+, PKI/CAC-based authentication.
  • Working knowledge of RMF, STIGs, and vulnerability assessment practices.
  • Experience with NAC platforms such as Forescout and/or Cisco ISE.
  • Strong communication skills to explain risks to non-technical stakeholders.
  • Willingness to travel up to 75% within the continental United States.

Responsibilities

  • Design device profiling, posture assessment, interrogation, automated remediation, and enforcement policies across the C2C framework.
  • Define enforcement strategies including monitoring, phased deployment, quarantine and rollback criteria.
  • Develop technical design docs, gap analyses, and change-management materials.
  • Create procedures for exception devices, including MAB and segmentation.
  • Design integrations with vulnerability assessment tools, EDR, AD/PKI, RADIUS, SIEM, and CMDB.

Skills

NAC design
Zero Trust
Policy design & communication
C2C frameworks
Stakeholder collaboration
Security architecture leadership

Education

Security+ certification
CISSP or CASP+ (preferred)

Tools

Forescout
Cisco ISE
RADIUS/TACACS+
PKI/CAC

Job description

Role Summary

The Cybersecurity Architect is responsible for designing and implementing Comply-to-Connect (C2C) policy frameworks and enforcement strategies across enterprise environments. This role provides technical leadership for C2C implementation, translating current security requirements into actionable designs and deployment strategies. The position develops technical documentation, conducts gap analyses, and collaborates with stakeholders to support effective cybersecurity policy integration and enforcement.

Responsibilities
  • Design device profiling, posture assessment, interrogation, automated remediation, and enforcement policies across the C2C security framework.
  • Define enforcement strategies, including monitoring, phased deployment, quarantine and remediation approaches, and rollback criteria.
  • Develop gap analyses, technical design documentation, and change management materials to support policy deployment.
  • Develop procedures for managing exception devices, including MAB and segmentation approaches, in collaboration with stakeholders.
  • Design integrations with vulnerability assessment tools, endpoint security solutions, Active Directory/PKI, RADIUS, SIEM, and CMDB systems.
  • Review and validate technical deliverables and help resolve technical challenges affecting implementation.
  • Capture lessons learned and develop reusable policy templates to support deployments across multiple environments.
  • Collaborate with cross-functional teams to support alignment with applicable cybersecurity standards and best practices.
  • Communicate technical risks, considerations, and tradeoffs to both technical and non-technical stakeholders.
  • Support continuous improvement through lessons learned and process refinement.
Qualifications
  • 10+ years of experience in cybersecurity or network security, including 5+ years designing Network Access Control (NAC), Zero Trust, or Comply-to-Connect solutions.
  • Active Secret security clearance required.
  • Experience designing and deploying NAC or C2C solutions supporting access control for large-scale production environments.
  • Strong knowledge of 802.1X, EAP-TLS, MAB, CoA, RADIUS/TACACS+, and PKI/CAC-based authentication.
  • Working knowledge of C2C frameworks, Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), and vulnerability assessment practices.
  • Experience with network access control platforms such as Forescout and/or Cisco ISE.
  • Strong communication skills with the ability to explain technical risks and tradeoffs to non-technical stakeholders.
  • Ability and willingness to travel up to 75% to locations within the continental United States.
Preferred Qualifications
  • Experience with C2C or Zero Trust implementations in regulated or security-focused environments.
  • Experience with enterprise integrations, including orchestration, APIs, and SIEM solutions.
  • Experience developing or supporting ATO/RMF documentation and security authorization packages.
  • Security+ certification required.
  • CISSP or CASP+ certification preferred.
  • Vendor-specific architect or professional certification related to Forescout, Cisco Security/ISE, or comparable technologies preferred.
Publishing Pay Range

$80.00 – $90.00 USD Hourly

This is a fully remote role and can be performed from an approved location.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

GDH • St. Louis (MO)

Remote
USD 103,000 - 117,000
Remote Cybersecurity Architect — Zero Trust & NAC Expert
Remote Cybersecurity Architect — Zero Trust & NAC Expert

GDH • St. Louis (MO)

Remote
USD 110,000 - 124,000
Cybersecurity Architect
Cybersecurity Architect

AITS Defence • Augusta (GA)

On-site
USD 120,000 - 150,000
Medical, Dental and Vision Insurance
Life Insurance
Paid Time Off (PTO)
+2
Cybersecurity Architect
Cybersecurity Architect

Finezi Inc. • Rosemead (CA)

On-site
USD 130,000 - 160,000
CYBERSECURITY ARCHITECT
CYBERSECURITY ARCHITECT

Zermount, Inc. • Arlington (VA)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Quantitix • Plano (TX)

On-site
USD 145,000 - 175,000
C2C Architect - 160333
C2C Architect - 160333

Zachary Piper Solutions • Alexandria (VA)

On-site
USD 170,000 - 185,000
Competitive salary $170,000–$185,000
Comprehensive benefits (Medical,Dental
Vision, 401(k), PTO, holidays, sick-le
Cybersecurity Architect
Cybersecurity Architect

Cybersecurity Jobs • San Diego (CA)

On-site
USD 98,000 - 171,000
Relocation assistance
Enterprise Cybersecurity Architect
Enterprise Cybersecurity Architect

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 140,000
Annual incentive
Medical coverage
Parental leave
+10
Enterprise Cybersecurity Architect-3
Enterprise Cybersecurity Architect-3

Cybersecurity Jobs • New York (NY)

On-site
USD 121,000 - 147,000