ShorePoint Inc.

Principal System Architect / SME

ShorePoint Inc. • $150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in systems architecture with technical supervision of senior staff.
  • Active CISSP or CISM certification required.
  • Proven experience in designing and implementing enterprise cybersecurity architectures.
  • Experience in developing cybersecurity architecture requirements with stakeholders.
  • Familiarity with PKI, key management, and certificate lifecycle management.
  • Strong ability to communicate complex technical topics to diverse audiences.
  • U.S. citizenship required for federal compliance.

Responsibilities

  • Lead and mentor a team of senior systems architects and engineers.
  • Advise on workload distribution and staffing for the systems team.
  • Shape the agency's PQC migration strategy in line with NIST standards.
  • Conduct cryptographic inventory to assess quantum decryption risks.
  • Establish crypto-agility standards for seamless algorithm transitions.
  • Evaluate NIST-selected PQC algorithms for enterprise suitability.
  • Develop enterprise cybersecurity architecture requirements with federal stakeholders.

Benefits

  • Remote work opportunity based in Herndon, VA.
Full Job Description
Who we're looking for:

We are seeking a Principal System Architect / subject matter expert (SME) to lead an enterprise Post-Quantum Cryptography (PQC) program for a federal agency and help establish the technical direction for transitioning from classical to quantum-resistant cryptography. This hands-on team lead role provides day-to-day direction to senior architects and engineers, supports workload coordination and partners with government stakeholders to advance PQC migration, crypto-agility and enterprise cybersecurity architecture. The Principal System Architect / SME position requires enterprise security architecture expertise, technical leadership and the ability to communicate complex program status, progress and value to technical teams and leadership. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you'll be doing:

  • Lead and technically supervise a team of senior systems architects and engineers, providing daily direction and mentorship.
  • Advise the project manager on workload distribution and staffing across the systems team.
  • Shape and support the agency's PQC migration strategy in alignment with National Institute of Standards and Technology (NIST) post-quantum standards and Commercial National Security Algorithm (CNSA) 2.0 requirements.
  • Lead and conduct cryptographic inventory and discovery efforts to identify systems, protocols and data stores exposed to quantum decryption risk, including "harvest now, decrypt later" threats.
  • Establish crypto-agility standards to enable systems to transition between classical and post-quantum algorithms with minimal re-architecture.
  • Advise on hybrid classical/PQC implementation approaches to protect systems during the migration period.
  • Evaluate NIST-selected PQC algorithms, including ML-KEM, ML-DSA and SLH-DSA, for suitability across enterprise use cases, performance constraints and system requirements.
  • Gather and develop enterprise cybersecurity architecture requirements with federal stakeholders, building on analysis from information engineers.
  • Produce design architectures covering software, hardware and communications that meet current needs and anticipate future cross-functional requirements and interfaces.
  • Design, implement and baseline enterprise cybersecurity capability configurations.
  • Validate and verify capability implementations and ongoing configuration changes to confirm they meet intended security outcomes.
  • Develop policy aligned with Cybersecurity and Infrastructure Security Agency (CISA) maturity models, including the Zero Trust Maturity Model and NIST standards while ensuring architectures remain compatible and compliant with industry and federal standards.
  • Foster collaboration across government and contractor teams to identify clear paths forward across key task areas.
  • Develop briefings, presentations and written deliverables that communicate program status, risk reduction and value to technical teams and agency leadership.


What you need to know:

  • PQC standards, including NIST-selected ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) algorithms and the CNSA 2.0 suite and transition timelines.
  • Crypto-agility principles, hybrid cryptographic implementation strategies, public-key infrastructure (PKI), key management and certificate lifecycle management in the context of cryptographic modernization.
  • Enterprise cybersecurity architecture across software, hardware and network communications, including configuration baselining, validation and verification practices.
  • Federal cybersecurity frameworks and guidance, including NIST Special Publication (SP) 800-series publications, the NIST Cybersecurity Framework and CISA maturity models and how to translate federal policy and mandates into technical requirements and architecture decisions.
  • Enterprise network architecture and cryptography across segmentation, routing, secure transport protocols and supporting infrastructure components, including identity and access management systems, directory services, load balancers, firewalls and hardware security modules (HSMs).
  • Cloud, hybrid and multi-cloud security architecture, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), cloud key management, shared responsibility models, Federal Risk and Authorization Management Program (FedRAMP) requirements and cryptographic dependencies across applications, operating systems, firmware and third-party products.


Must have's:

  • 10+ years of experience in systems architecture, including providing technical supervision and direction to senior architects and staff.
  • Active Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification.
  • Experience designing and implementing enterprise cybersecurity architectures and capabilities.
  • Experience developing enterprise cybersecurity architecture requirements with customers and stakeholders.
  • Experience baselining enterprise cybersecurity capability configurations and validating and verifying implementations and ongoing configuration changes.
  • Experience creating policy that adheres to CISA maturity models and NIST standards.
  • Experience with PKI, key management and certificate lifecycle management.
  • Proven ability to lead teams, build collaboration across stakeholders and communicate complex technical topics to technical and executive audiences through briefings, presentations and written deliverables.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Applicants must currently be a U.S. citizen in compliance with federal contract requirements.


Beneficial to have:

  • Experience designing and implementing enterprise cybersecurity architectures that include PQC.
  • Hands-on experience with PQC standards, including ML-KEM, ML-DSA, SLH-DSA and CNSA 2.0 requirements.
  • Experience conducting cryptographic inventories and assessing "harvest now, decrypt later" risk exposure.
  • Hands-on experience piloting PQC or hybrid key exchange in TLS, VPN/IPsec, SSH or code-signing environments.
  • Experience with automated cryptographic and network discovery tools, including mapping cryptographic dependencies across large environments and building Cryptographic Bills of Materials (CBOMs).
  • Familiarity with FIPS 140-3 validation, HSMs and vendor PQC readiness roadmaps.
  • Familiarity with federal PQC policy drivers such as National Security Memorandum 10 (NSM-10), Office of Management and Budget (OMB) Memorandum M-23-02 and CISA PQC guidance.
  • Experience supporting cybersecurity work for federal government customers, including developing enterprise cybersecurity architecture requirements.
  • Experience implementing Zero Trust architecture in a federal environment.
  • Experience with major federal cloud platforms such as Amazon Web Services (AWS) GovCloud, Azure Government or Google Cloud for Government.
  • Project Management Professional (PMP) certification.
  • Cloud security certifications such as AWS Certified Security - Specialty, Azure Security Engineer or Certified Cloud Security Professional (CCSP).
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Mathematics, Engineering or a related field.


it's done:

  • Remote (Herndon, VA).

About ShorePoint Inc.

ShorePoint Inc. is a cybersecurity and IT consulting firm that provides services to the federal government and commercial clients. The company's services include cybersecurity, cloud computing, data analytics, and software development. ShorePoint was founded in 2015 and is headquartered in Reston, Virginia. The company has additional offices in Washington, D.C. and Colorado Springs, Colorado.
Learn more about ShorePoint Inc.
Size
300 employees
Industry
Founded
2015

Similar Jobs

More Jobs at ShorePoint Inc.

More Information Technology Jobs

Find similar Principal System Architect / SME jobs: