Logo
NFF

Cybersecurity Architect Job at NFF in Washington

NFF, Washington, DC, United States, 20022


About NFF

Since 1996, NFF has designed, architected, and delivered IT network and security solutions to many state, and local government agencies, K-20 educational institutions, federal agencies, and large enterprise businesses across the mid-Atlantic. NFF is a technology services and solutions provider, specializing in next-generation IT infrastructure including networks, data centers, cloud migrations, IT security, collaboration and mobility, and full/part-time staff augmentation services. Our solutions, professional services and IT staffing portfolio are centered around building more resilient, secure, adaptive, and intelligent IT infrastructure and include comprehensive assessment, architecture, design, integration and installation services, and ongoing performance management services though our Network Operations Center (NOC).

NFF is a Cisco Gold Partner with a Customer Experience Specialization and was a "Cisco Top-5 Mid-Atlantic SLED Partner" in 2019, 2020 and 2022. NFF has maintained Cisco Gold Partnership since 2008, is the only Cisco Gold Partner headquartered in the District of Columbia. In addition to Cisco, NFF has key partnerships with many manufacturers and IT solution providers including, Rapid7, Arctic Wolf, VMware, NetApp and Splunk.
NFF is a District of Columbia (DC) Certified Business Enterprise (CBE) and a SBA Certified Small Business with headquarters in downtown Washington, DC. Our dedication to quality is reflected in our accomplishment of being awarded multiple ISO 9001:2015 certifications.

About this Position / Responsibilities

NFF, Inc. is seeking a highly experienced Cybersecurity Architect / Strategic Consultant to lead and guide the development, implementation, and evolution of customer cybersecurity strategies for our customer. This role demands a deep understanding of cybersecurity frameworks, risk management, emerging technologies, and technical security controls and architecture. The ideal candidate will be a trusted advisor to senior leadership, aligning cybersecurity initiatives with business objectives to safeguard organizational assets and reputation.

Duties and Responsibilities

Strategic Planning and Advisory:
  • Develop and refine the organization's cybersecurity strategy, ensuring alignment with overall business goals.
  • Provide expert guidance on implementing industry-standard security program frameworks such as NIST CSF, ISO 27001, and CIS Controls.
  • Identify emerging threats and recommend proactive technical measures to mitigate risks.
  • Design and enablement of cyber controls functions and processes based on CMMC / NIST 800-171, NIST 800-53
Risk Management:
  • Familiarity with risk management frameworks like NIST RMF, ISO 27005, and FAIR.
  • Conduct comprehensive cybersecurity risk assessments, identifying vulnerabilities and recommending remediation strategies.
  • Develop and maintain a robust risk management program to address both IT and operational risks.
  • Implement technical solutions to manage and monitor risk effectively, including vulnerability management tools.
Technical Oversight:
  • Design and validate secure network architectures, focusing on principles such as Zero Trust and least privilege.
  • Evaluate and implement advanced security technologies, including EDR, SIEM, DLP, and intrusion detection/prevention systems.
  • Provide hands-on technical assessments of infrastructure, applications, and cloud environments to ensure security compliance.
  • Oversee penetration testing activities and ensure identified vulnerabilities are remediated.
Policy and Governance:
  • Lead the development and enforcement of cybersecurity policies, standards, and procedures.
  • Establish metrics and reporting mechanisms to measure the effectiveness of cybersecurity initiatives.
  • Support incident response planning and governance, ensuring technical readiness for potential breaches.
Cloud and Emerging Technologies:
  • Provide technical guidance on securing multi-cloud environments, including AWS, Azure, and Google Cloud.
  • Evaluate and implement cloud-native security tools, such as CSPM, CIEM, and workload protection platforms.
  • Advise on emerging technologies like AI and ML, focusing on their application in threat detection and response.
Incident Response and Threat Intelligence:
  • Develop and oversee technical aspects of the incident response plan, ensuring readiness for real-world threats.
  • Leverage threat intelligence platforms to proactively identify and address potential vulnerabilities.
  • Coordinate with SOC teams to fine-tune detection rules and improve response times.
Qualifications

Required Qualifications:
  • Required 15+ years' experience in Information Security
  • Required 15+ years' proven experience with NIST CSF, NIST 800-53, and NIST 800-171 frameworks.
  • Required 15+ years' experience with a proven track record of developing and executing cybersecurity strategies for organizations of varying sizes and industries.
  • Required 15+ years' hands-on experience with risk assessments, compliance audits, and incident response planning.
  • Required 15+ years' proficiency with technical tools such as vulnerability scanners, SIEM platforms, and EDR solutions
  • Required 15+ years' expertise in cloud security, Zero Trust architecture, and emerging technologies.
Relevant certifications (e.g., CISSP, CISM, CISA, CRISC, OSCP, CEH, or GSEC).

Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.

NFF Disclosures

NFF offers a competitive salary, comprehensive benefits and flexible paid time off options, for eligible employees:
  • Medical, Dental and Vision, Health Savings Account, Flexible Spending Account
  • STD, LTD, Supplemental life insurance and ADD&D
  • Comprehensive 401k plan
  • Paid Time Off

NFF is an Equal Opportunity Employer.

Important Notice: All NFF communications come from @nffinc.com Emails from other domains claiming to be NFF are likely scams. Be cautious, verify senders, and report suspicious messages immediately.