Data-Centric Security Architect

Il y a 4 heures

Arrondissement of BrusselsCapital, Brussels, Belgique Leidos LLC Temps plein
pLeidos is seeking a Data-Centric Security Architect (MBSE / Sparx EA) to develop robust security frameworks for a groundbreaking integrated air and missile defence command and control (C2) program for NATO partners and allied operations. You will bring your expertise in data-centric security to design, evolve, and validate a fit-for-purpose security architecture for a cloud-based solution supporting NATO missions. The role requires a thorough understanding of modern data-centric security, Zero Trust Architecture (ZTA), Identity and Access Management (IAM), and cloud security, fully aligned with the NATO Data Strategy for the Alliance (DaSA) and NATO Data-Centric Reference Architecture (DCRA). To help define and evolve security concepts and architecture underpinning a federated, multi-domain cloud environment, you will leverage security patterns supporting data classification, tagging, lineage, encryption, access controls (RBAC/ABAC/CBAC), access decision logic, and policy-based enforcement. /ppYou will also bring strong skills in architecting Identity, Credential, and Access Management (ICAM) Zero Trust solutions. You will create Zero Trust enforcement models across identity, endpoints, networks, workloads, and data. This is a strict MBSE position. To be successful, you must be an expert in data-centric security models and possess deep, practical experience utilizing SysML and Sparx EA (or equivalent) to define information flows, security constraints, and systems architecture. Traditional IT security professionals without MBSE modelling experience will not be considered. /ph3Primary Responsibilities /h3ulliUse MBSE tools (e.g. Sparx Enterprise Architect) to build data-centric security-first architecture models. /liliDevelop architecture views aligned with the NATO Architecture Framework (NAF v4), including security views, system views, technical standards/compliance views, service-based views, and data views. /liliModel security behaviours using sequences, activity flows, state machines, and dependency diagrams. /liliTrace security requirements from operational concepts to system functions to services to components and to controls. /liliAssist the programme and teammates in navigating and completing the NATO Security Accreditation process for systems on restricted and classified networks. /liliClearly identify compliance concerns and trade-offs and propose accreditation strategies. /liliCreate the System Security Architecture Document (SSAD), Security Target Risk Assessment, Secure Configuration Baselines, Security Operating Procedures (SecOPs), and Security Test Evaluation (STE) artifacts. /liliEngage directly with NATO Security Accreditation Authorities and comply with the NATO Security Directive Series, STANAGs, and FMN Baseline requirements. /li /ulh3Basic Qualifications /h3ulliNATO SECRET or national equivalent security clearance. /liliBachelors in Cybersecurity, Information Assurance, Computer Science, Systems Engineering, or related field. /liliStrong knowledge of the underpinnings of multi-domain security concepts, attribute-based security, and associated approaches, architectures, and technologies. /liliHands on experience with architecting for Data Centric Security and Zero Trust Architecture, preferably in a military and/or coalition environment. /lili5+ years in defense security architecture, cloud security, or classified system environments. /liliDeep knowledge of cloud security, data-centric protection, encryption, IAM/ICAM, Zero Trust, and secure system design. /liliExperience designing architectures for cross-domain, multi-level, multi-tenant systems. /liliKnowledge of MBSE tools and modelling languages (e.g., SysML, UML, NAF/DoDAF/UAF frameworks). /liliStrong understanding of modelling data flows, access policies, interfaces, and trust boundaries. /liliAbility to coordinate reviews, produce documentation, and close findings with Security Accreditation Authorities (SAAs). /liliProficient with standards including but not limited to: NIST 800-207 (ZTA), NIST 800-53, ISO 27001, CIS, and NATO cyber/INFOSEC frameworks (STANAG 4774, STANAG 4778, STANAG 5636, and ACP 240) Experience conducting risk analyses, vulnerability assessments, and defining mitigations. /liliExcellent communicator comfortable with multinational stakeholders. /liliAble to guide engineers and analysts through secure-by-design principles and model-based workflows. /li /ulh3Preferred Qualifications /h3ulliMaster’s degree. /liliExpertise in Zero Trust Data Format (ZTDF) Expertise in MBSE tools such as Cameo, MagicDraw, or Sparx Enterprise Architect and NAF v4 operational, system, service, and security viewpoints. /liliDemonstrated expertise in applying data-centric security principles. /liliDemonstrated experience completing NATO accreditation for classified systems. /liliStrong understanding of the NATO Data Strategy and NATO Data-Centric Reference Architecture (DCRA). /liliRelevant advanced certifications: CompTIA Security+