Principal Cyber Security Engineer and Architect

ITSMF

Ashburn (VA)

Hybrid

USD 133,000 - 231,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid holidays
Tuition assistance

Job summary

Verizon seeks a System Architecture Engineer for the National Security Program Office to define core cybersecurity guardrails and technical standards across sensitive programs. You will lead hands‑on implementation and enforcement of security controls across enterprise infrastructures.

In a hybrid role based at Ashburn, VA, you will ensure environments align with CISA, CIS, NIST, and SANS guides while partnering with security teams and program leadership to sustain secure architectures.

Qualifications

  • Bachelor’s degree or four or more years of work experience.
  • Six or more years of relevant experience required, demonstrated through professional or military experience or specialized training in system security engineering or network security architecture.
  • Must be able to have or obtain Top Secret Security Clearance.
  • Experience with Windows server operating environments and UNIX/Linux systems engineering.
  • Hands‑on experience with virtualization and cloud infrastructure security (Kubernetes/OpenShift/OpenStack, AWS/Azure Gov).
  • Familiarity with cybersecurity frameworks (NIST/CIS/SANS) and translating them into enforceable controls.

Responsibilities

  • Guardrail and baseline creation based on CISA, CIS, NIST, and SANS guidance.
  • Translation of guidelines into concrete engineering controls and secure configurations.
  • Conduct security assessments against baselines and drive remediation to enforce compliance.
  • Collaborate with corporate security, cybersecurity, NSOC, and infrastructure teams to embed controls into pipelines and deployments.

Skills

Security engineering
Network security
OpenStack
Kubernetes
SOAR playbooks
Cloud security
IAM / NAC
Vulnerability remediation
Data protection

Education

Bachelor’s degree or 4+ years experience

Tools

OpenShift
Kubernetes

Job description

When you join Verizon

You want more out of a career. A place to share your ideas freely — even if they’re daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love — driving innovation, creativity, and impact in the world. Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together — lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.

What you’ll be doing...

The Corporate Security team is seeking an experienced, self-motivated System Architecture Engineer to join the National Security Program Office (NSPO). In this high-impact strategic role, you will be responsible for assessing, defining, and establishing core cybersecurity guidelines, guardrails, and technical standards across all sensitive and mission-critical programs.

Working as a core member of the NSPO, you will bridge organizational security requirements with technical execution. Beyond policy creation, you will directly lead the hands‑on implementation and enforcement of these guardrails across critical enterprise infrastructures to ensure all program environments operate strictly according to guidelines published by CISA, CIS, NIST, and SANS.

Key Responsibilities

  • Guardrail & Baseline Creation: Assess program requirements and author technical security guidelines, policy baselines, and architectural guardrails for all sensitive and mission‑critical program environments based on CISA, CIS Benchmarks, NIST (e.g., CSF, 800‑53, 800‑171), and SANS guidance.
  • Architecture & Hands‑On Implementation: Translate abstract security guidelines into concrete engineering controls. Lead the technical implementation of hardened network architectures, microsegmentation, zero‑trust patterns, and secure configurations across classified infrastructures.
  • Security Assessments & Compliance: Evaluate existing program systems against published CISA/CIS/NIST baselines to identify architectural gaps, drift, or vulnerabilities, driving remediation plans to enforce compliance.
  • Cross‑Functional & Security Partnership: Partner directly with Corporate Security, Cybersecurity teams, the Network and Security Operations Center (NSOC), infrastructure groups, and program leadership to align program guardrails with enterprise security strategy, report on compliance posture, mitigate architectural risks, and embed mandatory controls into build patterns, deployment pipelines, and operational workflows.

Where you'll be working...

In this worksite‑based role, you'll work onsite at a defined location which is Ashburn, VA.

What we’re looking for...

You’ll need to have:

  • Bachelor’s degree or four or more years of work experience.
  • Six or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training in system security engineering or network security architecture.
  • Must be able to have or obtain Top Secret Security Clearance

Even better if you have one or more of the following:

  • Experience with Windows server operating environments and UNIX/Linux systems engineering (variety of variants).
  • Expertise in TCP/IP networking, 4G/5G call flows (SBI, Diameter, SIP), and virtualization technologies like OpenStack and OpenShift / Kubernetes.
  • Strong foundational knowledge of incident response lifecycles (NIST or SANS) with experience designing, testing, and maintaining automation playbooks using SOAR platforms.
  • Hands‑on experience translating cybersecurity frameworks, such as NIST (800‑53, 800‑171, CSF), CIS Benchmarks, CISA directives, and SANS baselines, into enforceable engineering controls and technical guardrails.
  • Proven experience conducting security assessments against baseline standards to identify architectural gaps, drift, or vulnerabilities, driving remediation plans to enforce compliance.
  • Hands‑on experience with virtualization, containerization, and cloud infrastructure security (e.g., Kubernetes, OpenShift, OpenStack, AWS/Azure government environments).
  • Expertise in cryptographic controls and data‑in‑transit / data‑at‑rest encryption standards (e.g., IPsec, TLS 1.3, MACsec, PKI).
  • Advanced architecture and security certifications such as CISSP, CISSP‑ISSAP (Architecture), CCSP, CISM, or vendor networking/security certifications (e.g., CCNP Security, PCNSE).
  • Solid understanding of Identity and Access Management (IAM), Least Privilege access frameworks, and Network Access Control (NAC) integration.
  • Strong analytical skills and attention to detail with a proven track record of managing and delivering results.
  • Ability to work independently, keeping project teams aware of strategic technical challenges .Experience working within or supporting sensitive/restricted program environments.

If Verizon and this role sound like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.

Where you’ll be working

In this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.

Scheduled Weekly Hours

40

Equal Employment Opportunity

Verizon is an equal opportunity employer. We evaluate qualified applicants without regard to veteran status, disability or other legally protected characteristics.

Benefits and Compensation

Our benefits are designed to help you move forward in your career, and in areas of your life outside of Verizon. From health and wellness benefit options including: medical, dental, vision, short and long term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance and group home & auto insurance. We also offer a matched 401(k) savings plan, up to 8 company paid holidays per year and up to 6 personal days per year, paid parental leave, adoption assistance and tuition assistance, plus other incentives, we’ve got you covered with our award‑winning total rewards package. Depending on the role, employees have the opportunity to receive compensation in the form of premium pay such as overtime, shift differential, holiday pay, allowances, etc. Newly hired employees receive up to 15 days of vacation per year, which grows with additional service. For part‑timers, your coverage will vary as you may be eligible for some of these benefits depending on your individual circumstances.

The salary will vary depending on your location and confirmed job‑related skills and experience. This is an incentive based position with the potential to earn more. For part‑time roles, your compensation will be adjusted to reflect your hours.

The annual salary range for the location(s) listed on this job requisition based on a full‑time schedule is: $132,500.00 - $231,000.00.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Distinguished Engineer - Security Architecture
Distinguished Engineer - Security Architecture

Verizon Communications • Irving (TX)

On-site
USD 137,000 - 263,000
Hybrid work model
Principal Engineer - Security Architecture
Principal Engineer - Security Architecture

Verizon Communications • Irving (TX)

On-site
USD 121,000 - 231,000
Principal Engineer - Security Architecture
Principal Engineer - Security Architecture

Verizon • Basking Ridge (NJ)

Hybrid
USD 121,000 - 231,000
Hybrid work arrangement
Tuition assistance
Parental leave
+1
Principal Engineer - Security Architecture
Principal Engineer - Security Architecture

Verizon • Irving (TX)

On-site
USD 121,000 - 231,000
Health/dental/vision benefits
401(k) with company match
Paid holidays and personal days
+1
Principal Engineer - Security Architecture
Principal Engineer - Security Architecture

Verizon • San Jose (CA)

Hybrid
USD 121,000 - 231,000
Distinguished Engineer - Security Architecture
Distinguished Engineer - Security Architecture

Verizon • Basking Ridge (NJ)

Hybrid
USD 137,000 - 263,000
Hybrid work model
Total rewards package
Distinguished Engineer - Security Architecture
Distinguished Engineer - Security Architecture

Verizon • San Jose (CA)

On-site
USD 137,000 - 263,000
Hybrid work model
Total rewards package
Distinguished Engineer - Security Architecture
Distinguished Engineer - Security Architecture

Verizon • Irving (TX)

On-site
USD 137,000 - 263,000
Hybrid work model
Competitive compensation
Lead Network Security Engineer Firewalls & Policy
Lead Network Security Engineer Firewalls & Policy

Verizon • Irving (TX)

Hybrid
USD 121,000 - 231,000
Hybrid work model
Healthcare benefits
401(k) savings plan
Lead Network Security Engineer Firewalls & Policy
Lead Network Security Engineer Firewalls & Policy

Verizon • Cary (NC)

Hybrid
USD 121,000 - 231,000