Sr. Security Architect

Feuji

Orange (CA)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

OCSD seeks an experienced cybersecurity leader to oversee enterprise security architecture and cyber services for the organization. You will direct design, implementation, and operation of security controls across endpoints, network, VPN, wireless, DNS and SIEM systems.

You will act as a senior technical SME, coordinating incident response, ensuring CJIS compliance, and driving security maturity. Strong communication and project management skills are essential in this role.

Qualifications

  • BS in Cybersecurity or related technical field with 7+ years of experience, or MS with 5+ years, or PhD with 4+ years of experience.
  • Certifications: CISSP or GIAC GREM (or similar).
  • Experience leading SOC/security operations teams and enterprise security architectures.

Responsibilities

  • Design, implement, and maintain Palo Alto firewalls, Panorama management, and security services.
  • Lead secure remote access design with MFA and least privilege.
  • Develop and enforce secure wireless and DNS architectures.
  • Lead enterprise SIEM design, correlation rules, dashboards and reporting.
  • Guide incident response lifecycle and post-incident reviews.
  • Ensure CJIS compliance across architecture, policies, and procedures.

Skills

SOC leadership
Security operations
Communication skills
Project management
Team collaboration
Ability to perform under pressure
Independent work

Education

BS in Cybersecurity or related field
MS in Cybersecurity or related field
PhD in Cybersecurity or related field

Tools

Palo Alto Networks
PAN-OS
Intrusion Prevention Systems

Job description

Summary

This position entails providing expert technical leadership and oversight for the OCSD cybersecurity team, with a responsibility to protect OCSD assets, systems, and data against cyber threats. Primary responsibilities will be for the design, development, and implementation of robust and compliant enterprise-wide security architecture. Technical cyber services and expertise provided are associated with (but not limited to) endpoint and email security, firewall management, wireless security, virtual private technologies, and Incident Response with adherence to regulatory frameworks like CJIS. The following details specific duties and responsibilities for this position.

Duties and Responsibilities
Palo Alto Networks Platform Management:
  • Design, Implement and maintain Palo Alto Network firewalls (NGFW), Panorama Central Management and related security services (Wildfire, Threat Prevention, URL Filtering, Anti-Virus, etc.)
  • Develop and enforce high-level security policies, rule sets and zone segmentation to align with Zero Trust principles across the entire network.
  • Serve as the top-tier subject matter expert for all Palo-Alto related security engineering, configuration and troubleshooting.
Virtual Private Network Technologies
  • Architect and optimize secure remote access solutions leveraging solutions such as Palo Alto GlobalProtect or other enterprise VPN technologies ensuring least privilege and MFA requirements are enforced and properly implemented.
Wireless Infrastructure Security
  • Develop and enforce security policies for corporate and guest wireless networks, ensuring segmentation, use of secure authentication protocols and encryption methodology.
DNS Security
  • Design and implement secure DNS architecture utilizing DNSSEC or private DNS Services.
Security Information And Event Management
  • Lead the design and tuning of the enterprise SIEM.
  • Lead the design and tuning of device log integration into enterprise SIEM.
  • Develop advanced correlation rules, alerts, dashboards and reporting to identify, prioritize and track security threats and anomalies.
Incident Response
  • Develop, maintain, and test the OCSD Incident Response Plan and playbooks.
  • Act as a lead resource during critical security incidents, providing technical expertise to guide the incident response lifecycle (Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned)
  • Conduct post-incident reviews to identify architectural gaps and define immediate and long-term security enhancements.
Regulatory Compliance - Criminal Justice Information Services (CJIS)
  • Ensure all security architectures, policies and operational procedures strictly comply with local, state and federal mandates, specifically the CJIS requirements.
  • Create and maintain enterprise-wide security standards, security control baselines, and reference architecture to dictate how technology is securely implemented across the organization.
  • Conduct regular security assessments to identify control deficiencies and define remediation strategies.
Required Qualifications

BS in Cybersecurity or related technical field, 7+ years relevant industry experience, or MS in Cybersecurity or related technical field, 5+ years relevant industry experience, or PhD in Cybersecurity or related technical field with 4+ years industry experience.

Required Certifications: Certified Information Systems Security Professional (CISSP) or GIAC Reverse Engineering Malware (GREM) or similar.

Additional Qualifications
  • Professional experience providing expert technical leadership in support of a Security Operations Center (SOC) or similar organization that provides cyber security services.
  • Strong understanding of Palo Alto Networks architecture and technologies. Expertise with Palo Alto Networks firewalls, intrusion prevention systems and other security products.
  • Experience with network security design, deployment, and maintenance.
  • Experience with troubleshooting security issues.
  • Experience with providing support to users.
  • Excellent communication and interpersonal skills.
  • Strong Project Management
  • Ability to work independently and as part of a team.
  • Ability to work under pressure and meet deadlines.
  • Ability to work overtime as requested.
  • Ability to work flexible hours including weekends and overnight
  • Ability to manage multiple projects simultaneously
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Tech Support Engineer
Sr Tech Support Engineer

RippleMatch Inc. • Plano (TX)

On-site
USD 100,000 - 165,000
Palo Alto SME
Palo Alto SME

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 190,000
Palo Alto SME
Palo Alto SME

Si Tec Consulting • Springfield (VA)

On-site
USD 150,000 - 190,000
Sr Cybersecurity Technologist
Sr Cybersecurity Technologist

Complete Logistical Services • Houston (TX)

On-site
USD 96,000 - 165,000
Palo Alto Integration Engineer, Senior
Palo Alto Integration Engineer, Senior

Digital-Global-Connectors • McLean (VA)

On-site
USD 135,000 - 160,000
Palo Alto Integration Engineer, Senior
Palo Alto Integration Engineer, Senior

Digital Global Connectors • McLean (VA)

On-site
USD 135,000 - 160,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 154,000 - 250,000
Palo Alto SME
Palo Alto SME

SITEC Consulting, LLC. • Springfield (VA)

On-site
USD 150,000 - 210,000
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
Principal Consultant, Offensive Security, Proactive Services (Unit 42)
Principal Consultant, Offensive Security, Proactive Services (Unit 42)

Palo Alto Networks • Burbank (CA)

On-site
USD 151,000 - 208,000