Cloud Network Security Architecture Manager (TIC 3.0)

General Dynamics Information Technology, Inc.

$114K — $155K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in IT or related fields
  • Hands-on experience with federal-grade, Zero-Trust-aligned architectures
  • Strong background in cloud, network, or security architecture (AWS, Azure)
  • Familiarity with NIST Cybersecurity Framework and federal cybersecurity standards
  • Experience with automation tools (Terraform, Ansible)
  • Effective communication skills for team coordination

Responsibilities

  • Lead modernization of TIC 3.0 security models
  • Architect Zero-Trust identity-centric controls and segmentations
  • Design trust-zone mappings and secure interconnections
  • Guide implementation of policy enforcement mechanisms
  • Integrate security solutions with existing monitoring platforms
  • Oversee gateway transformation in alignment with security standards
  • Communicate risks and strategies to leadership

Benefits

  • Medical and dental plan options, some including Health Savings Accounts
  • 401(k) plan with employer match
  • Flexible work weeks and generous paid time off
  • Short and long-term disability benefits
  • Life and critical illness insurance options
  • Regular review of benefits to ensure competitiveness
Full Job Description
Type of Requisition:
Regular

Clearance Level Must Currently Possess:
None

Clearance Level Must Be Able to Obtain:
None

Public Trust/Other Required:
MBI (T2)

Job Family:
IT Infrastructure and Operations

Job Qualifications:

Skills:
Cloud Platform, IT Service Management (ITSM), Network Architecture
Certifications:
None
Experience:
10 + years of related experience
US Citizenship Required:
No

Job Description:

Join GDIT in modernizing the Department of Veterans Affairs' network security posture under the NEDIIS program. As the Cloud Network Security Architecture Manager, you will lead the design and implementation of TIC 3.0-aligned, Zero-Trust-enabled, distributed security architectures across VA's hybrid and multi-cloud environments.

This role transforms legacy perimeter models into risk-based trust zones, policy enforcement points (PEPs), cloud-native security controls, and continuous monitoring-integrated architectures, consistent with evolving federal cybersecurity guidance.

How You Will Make an Impact
  • Lead TIC 3.0 modernization, shifting security from centralized gateways to distributed trust-zone and PEP-based enforcement across AWS, Azure, and enterprise networks.
  • Architect Zero-Trust-aligned identity-centric controls, segmentation, dynamic policy enforcement, and continuous validation.
  • Design and manage trust-zone mappings, cloud boundary protections, secure interconnects, and mission-aligned risk-based traffic flows.
  • Guide implementation of policy enforcement points for cloud, on-prem, remote, and mobile use cases.
  • Integrate solutions with CDM, EINSTEIN, SIEM platforms, and continuous monitoring pipelines.
  • Partner with engineering, cyber, SOC, network, and operations groups to embed security across distributed systems.
  • Oversee gateway transformation, including redesign, scaling, load distribution, and modernization aligned with TIC 3.0.
  • Communicate architectural decisions, risks, and modernization strategies to VA leadership.
  • Evaluate emerging technologies, lead pilots/proofs of concept, and recommend mission-aligned adoption strategies.
  • Support escalations and critical events involving cloud networks, identity systems, boundary controls, and PEP operations.
  • Produce architecture diagrams, trust-zone definitions, PEP mappings, documentation, and compliance artifacts.
  • Mentor engineers and promote security best practices across cloud and network architecture teams.


What You'll Need to Succeed
  • Bachelor's degree or equivalent experience.
  • Hands-on experience designing or supporting federal-grade, Zero-Trust-aligned architectures (identity-centric access, micro-segmentation, encrypted traffic inspection, cloud boundary protections).
  • Experience with TIC 3.0 concepts, trust zones, distributed enforcement, and cloud/mobility use cases.
  • Background in cloud, network, or security architecture (AWS, Azure, hybrid networking, segmentation).
  • Hands-on familiarity with firewalls, cloud gateways, DNS, IAM, API security, logging pipelines, and SIEM integrations.
  • Strong understanding of NIST Cybersecurity Framework, NIST SP 800-207 (ZTA), NIST SP 800-53, and broader federal cybersecurity standards.
  • Experience with automation, scripting, or IaC (Terraform, Ansible, CloudFormation, ARM templates).
  • Effective communicator able to coordinate across multiple teams.
  • Ability to support emergency incidents, escalations, and critical events.


Preferred (Not Required)
  • AWS Solutions Architect - Professional
  • Azure Solutions Architect Expert
  • Kubernetes / OpenShift (CKA / CKAD)
  • VMware certifications
  • Terraform Associate


Visa sponsorship will not be provided for this position.

This role will require you to obtain and maintain Public Trust Suitability and will require you to provide onsite fingerprinting at a designated facility. This investigation may review personal and criminal behavior, financial conduct, foreign influence, as well as other adjudications.

Security & Location
Public Trust clearance required.
Hybrid position in Martinsburg, WV or Austin, TX - must work a regular weekly schedule with 2 to 3 days onsite as needed.

Visa sponsorship will not be provided for this position.

The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
Less than 10%

Telecommuting Options:
Hybrid

Work Location:
USA WV Martinsburg

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Information Technology Jobs

Find similar Cloud Network Security Architecture Manager (TIC 3.0) jobs: