Enterprise Cybersecurity ArchitectPeraton is seeking an experienced Enterprise Cybersecurity Architect to define and lead the cybersecurity architecture strategy across the BNATCS program where cybersecurity is inseparable from safety. In this environment, a security failure is not merely a data breach - it can directly endanger human life, disrupt the national airspace, and compromise public safety. This role demands an architect who understands that every security design decision carries safety implications and who can embed that mindset across the entire integrated enterprise. In Peraton's role as a systems integrator, you will be responsible for securing the full spectrum of integrated systems - custom-developed, COTS, GOTS, and third-party vendor components - ensuring that cybersecurity controls are consistent, enforceable, and verifiable across organizational and technical boundaries. This role is based in Herndon, VA.ResponsibilitiesDefine and maintain the enterprise cybersecurity architecture vision, encompassing network security, application security, data protection, identity and access management, and endpoint security across all integrated systemsDevelop and govern cybersecurity reference architectures, standards, and design patterns that ensure consistent security posture across internal teams, subcontractors, and vendor-delivered componentsDrive the enterprise-wide adoption of Zero Trust Architecture (ZTA), defining segmentation strategies, identity verification models, and least-privilege access controls appropriate for safety-critical environmentsLead cybersecurity technology roadmap development, identifying strategic investments, capability gaps, and modernization priorities across the security portfolioArchitect cybersecurity controls that account for the safety-of-life implications inherent in aviation systems - ensuring that security mechanisms do not introduce latency, single points of failure, or operational disruptions that could compromise airspace safetyIntegrate cybersecurity requirements with safety engineering and system assurance processes, ensuring that security risk assessments are conducted alongside safety hazard analysesDesign resilience and continuity architectures - failover, graceful degradation, and recovery strategies - that maintain both security and safety posture during cyber incidentsDevelop security architectures for real-time, low-latency, and high-availability systems where traditional security controls must be adapted to meet stringent operational performance requirementsConduct security architecture assessments across the integrated system portfolio, identifying vulnerabilities, trust boundary gaps, and inconsistencies in security controls between vendor and custom componentsDefine and manage security interface requirements and security-relevant interface control documents (ICDs) for all system-to-system data exchanges across the integrated enterpriseConduct technical security reviews of vendor and subcontractor deliverables to ensure alignment with enterprise cybersecurity standards, secure coding practices, and compliance requirementsEstablish and chair security architecture review boards to evaluate proposed designs, adjudicate security trade-offs, and enforce architectural standards across all integrated systemsEnsure enterprise-wide compliance with FedRAMP, RMF, NIST 800-53, FISMA, FAA cybersecurity directives, and agency-specific security policiesLead threat modeling, risk assessments, and attack surface analyses across the integrated enterprise, with particular attention to safety-critical system boundariesCollaborate with cybersecurity operations, incident response, and security monitoring teams to ensure that architectural designs support effective detection, response, and recovery capabilitiesArchitect security solutions for hybrid and multi-cloud environments (AWS GovCloud, Azure Government) that meet federal compliance requirements while supporting mission performanceTranslate complex cybersecurity risks, architectural trade-offs, and safety-security interdependencies into clear, actionable guidance for executive stakeholders, program managers, and government customersMentor and guide security engineers, solution architects, and development teams to ensure cybersecurity and safety intent is preserved from design through implementation and integrationDrive cross-functional alignment across cybersecurity, software engineering, data architecture, infrastructure, and operations teamsQualifications Required Qualifications15+ years of experience in cybersecurity architecture, security engineering, or enterprise IT security within large-scale programsBachelor's degree in Computer Science, Cybersecurity, Information Systems, Computer Engineering, or a related field (or 4 additional years of relevant experience in lieu of degree)US CitizenshipPublic Trust Clearance - Ability to Obtain and MaintainDemonstrated experience serving as a cybersecurity architect within a systems integrator environment, securing multi-vendor, multi-technology solutions across complex trust boundariesDeep expertise in Zero Trust Architecture, network security design, identity and access management (IAM), and data protection strategies at enterprise scaleProven experience securing safety-critical or mission-critical systems where cybersecurity failures carry operational or life-safety consequencesMastery of FedRAMP, RMF, NIST 800-53, FISMA, and federal cybersecurity governance frameworksHands-on experience with security technologies including SIEM, SOAR, EDR, CSPM, IAM platforms, PKI, and network segmentation toolsStrong understanding of cloud security architecture on AWS and/or Azure, including cloud-native security services, landing zone security, and workload protectionExperience conducting threat modeling, risk assessments, and security architecture reviews across heterogeneous integrated environmentsFamiliarity with safety engineering principles (e.g., system safety, hazard analysis, fault tolerance) and their intersection with cybersecurityITIL certification and experience integrating cybersecurity governance with ITSM processesProven ability to lead cross-functional teams and drive security alignment across engineering, operations, and subcontractor organizationsPreferred QualificationsExperience securing FAA, aviation, or national airspace systems and familiarity with aviation-specific cybersecurity requirements and safety standardsBackground in securing real-time systems, low-latency architectures, and edge computing environments where traditional security controls require adaptationExperience with network security architecture (SD-WAN, secure transport, micro-segmentation) within large-scale integrated environmentsFamiliarity with AIOps, security observability platforms, automated threat detection, and security orchestration at enterprise scaleExperience with DevSecOps pipeline security - static/dynamic analysis, container security, software supply chain security, and secure CI/CD practicesHands-on experience with model-based systems engineering (MBSE) or architecture modeling tools for security architecture documentationRelevant certifications such as CISSP, CCSP, CISM, or GICSP (Global Industrial Cyber Security Professional)Experience with EO 14028 (Improving the Nation's Cybersecurity) complianceOMB M-22-09 Zero Trust implementation experienceHSPD-12 identity managementICS/OT security assessment experience of FAA safety case development experience#BNATCS Details Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law. Group ID: