Base Career helps you apply smarter for this job.
Key skills for this role
Join GDIT in modernizing the Department of Veterans Affairs’ network security posture under the NEDIIS program.
As the Cloud Network Security Architecture Manager , you will lead the design and implementation of TIC 3.0‑aligned, Zero‑Trust‑enabled, distributed security architectures across VA’s hybrid and multi‑cloud environments.
This role transforms legacy perimeter models into risk‑based trust zones, policy enforcement points (PEPs), cloud‑native security controls, and continuous monitoring‑integrated architectures , consistent with evolving federal cybersecurity guidance.
Clearance Level Must Currently Possess:
Clearance Level Must Be Able to Obtain:
Job Family:
Job Description:
Join GDIT in modernizing the Department of Veterans Affairs’ network security posture under the NEDIIS program. As the Cloud Network Security Architecture Manager , you will lead the design and implementation of TIC 3.0‑aligned, Zero‑Trust‑enabled, distributed security architectures across VA’s hybrid and multi‑cloud environments.
This role transforms legacy perimeter models into risk‑based trust zones, policy enforcement points (PEPs), cloud‑native security controls, and continuous monitoring‑integrated architectures , consistent with evolving federal cybersecurity guidance.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Albany, USA
Herndon, USA
, USA
Falls Church, USA
Herndon, USA
, USA
Martinsburg, USA
Herndon, USA
Lead TIC 3.0 modernization , shifting security from centralized gateways to distributed trust‑zone and PEP-based enforcement across AWS, Azure, and enterprise networks.
Architect Zero‑Trust‑aligned identity‑centric controls, segmentation, dynamic policy enforcement, and continuous validation.
Design and manage trust‑zone mappings , cloud boundary protections, secure interconnects, and mission‑aligned risk‑based traffic flows.
Guide implementation of policy enforcement points for cloud, on‑prem, remote, and mobile use cases.
Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
Partner with engineering, cyber, SOC, network, and operations groups to embed security across distributed systems.
Oversee gateway transformation , including redesign, scaling, load distribution, and modernization aligned with TIC 3.0.
Communicate architectural decisions, risks, and modernization strategies to VA leadership.
Evaluate emerging technologies, lead pilots/proofs of concept, and recommend mission‑aligned adoption strategies.
Support escalations and critical events involving cloud networks, identity systems, boundary controls, and PEP operations.
Produce architecture diagrams, trust‑zone definitions, PEP mappings, documentation, and compliance artifacts.
Mentor engineers and promote security best practices across cloud and network architecture teams.
Bachelor’s degree or equivalent experience.
Hands‑on experience designing or supporting federal‑grade, Zero‑Trust‑aligned architectures (identity‑centric access, micro‑segmentation, encrypted traffic inspection, cloud boundary protections).
Experience with TIC 3.0 concepts , trust zones, distributed enforcement, and cloud/mobility use cases.
Background in cloud, network, or security architecture (AWS, Azure, hybrid networking, segmentation).
Hands‑on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations .
Strong understanding of NIST Cybersecurity Framework, NIST SP 800‑207 (ZTA), NIST SP 800‑53 , and broader federal cybersecurity standards.
Experience with automation, scripting, or IaC (Terraform, Ansible, CloudFormation, ARM templates).
Effective communicator able to coordinate across multiple teams.
Ability to support emergency incidents, escalations, and critical events.
AWS Solutions Architect – Professional
Azure Solutions Architect Expert
Kubernetes / OpenShift (CKA / CKAD)
VMware certifications
Terraform Associate
This role will require you to obtain and maintain Public Trust Suitability and will require you to provide onsite fingerprinting at a designated facility. This investigation may review personal and criminal behavior, financial conduct, foreign influence, as well as other adjudications.
Work Location:
Additional Work Locations:
gdit.com/tc .
Provider of enterprise IT services and defense solutions.
Visit company websiteJobs and hiring trendsUSD 114750-155250 yearly / year
Full-time
Senior · 10+ years experience
Hybrid
Apply faster on company sites with our extension.