Bloomberg

Security Architect - Cloud & DevSecOps

Bloomberg$150K — $180K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience as a trusted technical advisor to CISOs or CIOs in public or complex enterprise environments.
  • Expertise in operationalizing security controls with a focus on tiering models and compensating validation.
  • Proven mentoring experience, emphasizing hands-on training and technical skill transfer to infrastructure and security teams.
  • Advanced proficiency in enterprise cybersecurity stack including Google Threat Intel, Mandiant ASM, and Azure Arc.
  • Deep understanding of cloud architecture and DevSecOps engineering principles, specifically in deployment automation.

Responsibilities

  • Serve as a strategic advisor to the CISO, translating security mandates into actionable directives.
  • Conduct hands-on knowledge transfer, co-engineering security automation and data pipelines with client staff.
  • Develop and deliver real-time training and create automation playbooks for security operations.
  • Architect automated tracking and logging mechanisms for vulnerability compliance.
  • Integrate AI tools into workflows, demonstrating their use for automated log parsing and threat analysis.
  • Build low-code automated workflows for managing security exception lifecycles.
  • Establish automated alert systems for significant business risks, ensuring rapid escalation procedures.

Benefits

  • Remote work flexibility with only occasional onsite visits required.
  • Opportunity to influence statewide security initiatives and enhance organizational capabilities.
  • Hands-on collaboration with internal teams for knowledge transfer and skill development.
  • Access to cutting-edge AI tools and technologies in a real work environment.
Full Job Description
The client is looking for one (1) Certified Cloud Architect

Purpose and Objective
The client requires an expert senior technical leader and engineer to serve as a strategic advisor to the CISO and drive the statewide implementation of the Accelerated Exposure Reduction Plan.
This role balances high-level strategic advisory with hands on engineering, operating on a "teach-by-doing" knowledge transfer model. The primary objective is to build long-term internal capabilities while operationalizing and enforcing the client's newly updated Flaw Remediation (SI-2) Standard. This initiative transitions the client from reactive, manual vulnerability management to an AI-accelerated, continuous authorization, and automated DevSecOps posture.

Scope
The consultant shall perform hands-on engineering, deliver strategic CISO advisory, and provide direct mentoring across the following core operational pillars:

CISO Strategic Advisory and Engineering
Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives.
Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal client staff to institutionalize elite technical skills.
Deliver real time training and co-develop automation playbooks within the security operations (SecOps) using live demonstration approach.

Flaw Remediation (SI-2) Standard Operationalization
Tier Optimization & Enforcement: Architect automated tracking, logging, and validation mechanisms to implement compliance with the client's updated SI-2 timeframes:
Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities, CISA KEV listings, active exploits, and identity/privileged system flaws implement approved mitigations or compensating controls within 24 hours, with full remediation closed inside 7 calendar days.
Tier 2 (High-Risk/Internal): Configure alerting and metric reporting to validate mitigation within 48 hours and full remediation within 15 calendar days.
Tier 3 (Moderate/Low): Establish repeatable monthly scheduling to ensure remediation within 30 calendar days.
Clean Deployment Architectures: Partner with client development teams to pivot away from manual, in-place patching. Author and implement automated templates for clean deployments using virtualized system images, containers, and cloud-native configurations.
DevSecOps Integration: Embed secure builds, automated software testing, code scanning, and dependency updates natively into client deployment pipelines.

AI Capability Deployment & Toolchain Integration
Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, showing security analysts and application developers how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation.
Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass.
Ensure all AI-assisted capabilities comply strictly with client privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments.

Governance Safeguards & Escalation Automation
Build automated low-code workflows to manage the SI-2 time-bound exception lifecycle, ensuring every granted exception maps back to a named owner, specific compensating controls, and an explicit financial tiedown capturing technical debt.
Configure automated alert thresholds and workflow routing for significant business risks that exceed normal management tolerance, ensuring rapid escalation in line with the SI-2 update.

Minimum Qualifications and Core Competencies

The designated expert must demonstrate a unique blend of strategic advisory presence and deep, practical engineering capability:
Executive Advisory: Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
Teach-by-Doing Expertise: Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
Security Control Mastery (SI-2): Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
Advanced Tooling Fluency: enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
Performance Monitoring & Safeguards
Knowledge Transfer Auditing: Progress will be measured not only by technical deployment velocity but also by the documented proficiency gains of internal client staff who assume ownership of the deployed tools.
Data Isolation Guardrails: The consultant is strictly forbidden from utilizing public or unvetted commercial AI models for analyzing client code, logs, or asset data. All engineering must occur exclusively within authorized, client-managed enterprise security instances.

Top Required Skills & Years of Experience:
Must be able to demonstrate prior experience doing the following in a large/complex environment:
Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
Cloud Architecture & DevSecOps Engineering

Nice to have Skills:
Federated/Government environment
Tech Stack to include: Google, Microsoft, AWS, Splunk

Notes:
This position can work 100% remote with occasional onsite visits 1-2 times required

About Bloomberg

Bloomberg L.P. is a privately held financial, software, data, and media company headquartered in Midtown Manhattan, New York City. It was founded by Michael Bloomberg in 1981, with the help of Thomas Secunda, Duncan MacMillan, Charles Zegar, and a 12% ownership investment by Merrill Lynch. Bloomberg L.P. provides financial software tools and enterprise applications such as analytics and equity trading platform, data services, and news to financial companies and organizations through the Bloomberg Terminal (via its Bloomberg Professional Service), its core revenue-generating product. Bloomberg L.P. also includes a wire service (Bloomberg News), a global television network (Bloomberg Television), digital websites, a radio station (WBBR), subscription-only newsletters, and three magazines: Bloomberg Businessweek, Bloomberg Markets, and Bloomberg Pursuits.
Learn more about Bloomberg
Size
20,000 employees
Industry
Founded
1981

Similar Jobs

More Jobs at Bloomberg

More Information Technology Jobs

Find similar Security Architect - Cloud & DevSecOps jobs: