Role: Certified Cloud Architect
Start Date: 08/24/2026
Duration: 12 Months
Location: Madison, WI
Work Model: 100% Remote (Wisconsin Residents Only)
Location RequirementCandidates
must be current Wisconsin residents or
willing to relocate to Wisconsin at their own expense before the start date.
This position is
100% remote, with
1-2 onsite visits required during the contract period.
Required Skills & Experience- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leadership within public sector or highly federated enterprise environments.
- Demonstrated success as a technical mentor, trainer, or engineering lead, providing pair-engineering, knowledge transfer, and technical upskilling for infrastructure and security operations teams.
- Extensive experience implementing and operationalizing enterprise security controls, including:
- Security tiering models
- Compensating control validation
- Time-bound risk governance frameworks
- Strong expertise with enterprise cybersecurity technologies, including:
- Google Threat Intelligence / VirusTotal
- Google SecOps
- Google Mandiant Attack Surface Management (ASM)
- Tenable.io
- Microsoft Azure Arc
- GitHub & GitHub Advanced Security
- Ansible Tower
- Gemini and Anthropic AI Security Frameworks
- Deep expertise in Cloud Architecture and DevSecOps Engineering.
Preferred Skills & Experience- Experience working within Government or Federated Enterprise environments.
- Hands-on experience with technologies including:
- Google Cloud
- Microsoft Azure
- AWS
- Splunk
- Experience measuring project success through both:
- Technical implementation and deployment milestones.
- Documented knowledge transfer and technical proficiency improvements of internal staff.
- Understanding of secure AI governance, including adherence to policies prohibiting the use of public or unapproved commercial AI models for analyzing State code, logs, or infrastructure data. All engineering activities must be performed exclusively within authorized, state-managed enterprise environments.
Key Responsibilities- Perform hands-on cloud and security engineering while serving as a strategic advisor to the CISO.
- Provide executive-level guidance by translating federal mandates, emerging AI security threats, and architectural risks into actionable enterprise security strategies.
- Deliver hands-on mentoring through pair-engineering and knowledge transfer with internal DET staff.
- Conduct live demonstrations and real-time training while developing SecOps automation playbooks.
- Design and implement automated tracking, logging, and validation mechanisms to ensure compliance with the State's updated SI-2 security requirements.
- Ensure all public-facing vulnerabilities, CISA KEV vulnerabilities, active exploits, and privileged identity risks receive approved mitigations or compensating controls within 24 hours, with complete remediation within 7 calendar days.
- Configure automated alerting and reporting to validate:
- Mitigation within 48 hours
- Full remediation within 15 calendar days
- Establish automated monthly remediation schedules to ensure issues are resolved within 30 calendar days.
- Partner with agency development teams to replace manual, in-place patching with modern automated deployment practices.
- Develop standardized deployment templates utilizing:
- Virtual machine images
- Containers
- Cloud-native infrastructure
- Integrate secure software development practices into deployment pipelines, including:
- Secure build processes
- Automated testing
- Code scanning
- Dependency management and updates
- Operationalize Gemini Government, Google Codemender, or equivalent AI-assisted technologies within security operations to automate:
- Log analysis
- Threat hunting
- Source code remediation
- Build automated enterprise data pipelines integrating telemetry from:
- Tenable.io
- Google Mandiant ASM
- Microsoft Azure Arc
- Splunk
- Google SecOps
- Maintain a centralized enterprise security platform providing a single authoritative view of security operations.
- Ensure all AI-assisted capabilities comply with State privacy policies, data classification standards, and logging requirements, preventing sensitive information from being exposed to unauthorized environments.
- Develop low-code automated workflows to manage the SI-2 exception lifecycle, ensuring every approved exception includes:
- Assigned owner
- Documented compensating controls
- Financial accountability for technical debt
- Configure automated alert thresholds and workflow routing for critical business risks requiring executive-level escalation in accordance with updated SI-2 governance requirements.
Must-Have Skills- Cloud Architecture
- DevSecOps
- Google SecOps
- Google Threat Intelligence / VirusTotal
- Google Mandiant ASM
- Tenable.io
- Microsoft Azure Arc
- GitHub & GitHub Advanced Security
- Ansible Tower
- Gemini / Anthropic AI Security Frameworks
- Enterprise Security Architecture
- CISO Advisory
- Security Governance
- Security Automation
- SI-2 Compliance
- Vulnerability Management
- Infrastructure Security
- Knowledge Transfer & Technical Mentoring
- Public Sector / Government Experience