Hiring.Camp

Senior Azure Government Security & Compliance Architect

Chameleon Integrated Services

·

Today

Location
Tallahassee, FL
Workplace
Remote
Type
Contract
Department
Engineering
Seniority
Senior
Education
Master
Closing date
Today
Source
ApplyToJob

Description


We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward thinking candidates that have strong experience in operational support and can help take to the next level in a pro-active stance.
 
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity.  We secure some of the most sensitive data for the Department of Defense and for other U. S. federal government agencies.  We are known for the great care we take with clients and employees, and we believe in promoting from within.

Senior Azure Government Security & Compliance Architect
Position Overview
  • Position Type: Part-Time Consultant / Technical Vetting & Compliance Authority
  • Target Allocation: 8–10 hours/week average (Note: Workload rises substantially during security engineering phases, technical readiness reviews, and the structural execution of Deliverables 10, 11, and 12).
  • Technical Reality: This is an elite compliance role. The security architecture, authorization documentation, and continuous monitoring controls are too complex to distribute casually among traditional software developers. You will hold complete technical ownership over the platform's defensive validation strategy.
  • Compensation Type: Milestone / Deliverable-Based Fixed-Price Engagement.
Chameleon is seeking a Senior Azure Government Security & Compliance Architect to serve as the absolute authority for the security baseline of a high-visibility contract with the Florida Office of the Chief Inspector General (OCIG). In this role, you will take complete engineering and administrative ownership over defining, documenting, and validating the security controls transforming a data analytics Proof of Concept (POC) into a secure, multi-agency, enterprise-ready Decision Intelligence Platform.
This platform will unify statewide oversight, tracking abnormal spending patterns, contract vulnerabilities, and fraud/waste/abuse risks across up to 35 state agencies. Because this is a high-visibility, firm-fixed-price (FFP) state government contract, you will maintain absolute technical accountability for establishing an infrastructure that aligns perfectly with state and federal statutory requirements, preparing the system for full production authorization and independent validation.
Principal Responsibilities
  • Compliance Gap Analysis: Develop a comprehensive security compliance control crosswalk to identify, map, and remediate technical gaps against strict federal and state high-control baselines.
  • Identity & Access Architecture: Define and enforce a granular, role-based access control (RBAC) framework and end-to-end user lifecycle management model aligned strictly to least-privilege principles and multi-factor authentication (MFA) enforcement.
  • Audit Logging & Monitoring: Architect comprehensive audit logging, monitoring, and retention specifications for user actions, administrative events, system configurations, and raw data access layers to ensure absolute traceability.
  • Configuration Assessment: Conduct exhaustive, formal reviews of cloud, network, storage, and application configuration baselines to actively identify, catalog, and fix misconfigurations.
  • Vulnerability & Pentest Coordination: Manage internal and external vulnerability scanning protocols, orchestrate formal penetration testing events, and document the rigorous technical evidence confirming the resolution of high or critical findings.
  • Supply Chain Vetting: Perform comprehensive third-party risk assessments, map vendor/sub-vendor code dependencies, and produce a verified Software Bill of Materials (SBOM) alongside a critical service provider register.
  • Privilege Access Governance: Develop and execute structured privilege-access reviews to monitor elevated account allocations, analyze account activities, and mitigate credential risk exposure.
  • Incident Response Integration: Design and integrate actionable incident response workflows, contact escalation paths, security event reporting routines, and vulnerability patch management lifecycles that conform to state policies.
  • Authorization Package Compilation: Compile and validate all technical security artifacts, data-flow diagrams, system security plans (SSP-style), and readiness review dossiers required to clear independent state testing and ensure a seamless handover to the State.
Required Qualifications
  • Experience Baseline: 10+ years of comprehensive information security engineering experience.
  • Cloud Depth: 5+ years of dedicated, hands-on cloud security architecture, data environment hardening, or security automation work.
  • Government Control Mastery: Documented history implementing and mapping controls against NIST SP 800-53 and NIST SP 800-171 within federal or state government systems.
  • High-Control Baselines: Direct experience preparing systems for or operating within FedRAMP High or comparable high-control, highly regulated environments.
  • Infrastructure Toolkit: Proven hands-on mastery of Azure and Entra ID security parameters, managed identities, automated secrets/key management, and Azure Key Vault configuration.
  • Threat Management: Strong background executing vulnerability management lifecycles, structured incident response mapping, and formal configuration assessments.
  • Supply Chain Architecture: Practical understanding of third-party risk assessment methodologies and familiarization with Software Bill of Materials (SBOM) compilation frameworks.
  • Testing & Assessment: Verifiable history acting as a security control assessor or leading technical control validation assessments.
  • Vetting & Location: Must be a U.S.-based citizen or resident. Must be able to successfully clear an FDLE Level II background screening (including fingerprinting) within 5 business days of contract award.
Strong Preferences
  • Prior experience navigating Florida state government compliance frameworks, specifically referencing Florida Administrative Code Rule 60GG-2 and Section 282.318, Florida Statutes.
  • Practical security engineering context handling CJIS or HIPAA regulated government data streams.
  • Hands-on security containment and control configuration for Azure Databricks workspaces, Azure Data Lake Storage Gen2 (ADLS Gen2), and Power BI workspaces inside Azure Government environments.
  • Proven experience compiling, submitting, or auditing formal FedRAMP authority to operate (ATO) authorization packages.
  • Active premium industry credentials such as CISSP, CISM, or CCSP.
MANDATORY RESUME FORMATTING INSTRUCTIONS
The State of Florida strictly evaluates and verifies all named staff experience for this contract. Generic resumes that only list generalized cybersecurity buzzwords or generic compliance tool lists without specific government framework context will be automatically rejected.
To be considered for this role, your resume must explicitly detail the following metadata for your past contract positions:
  1. The Government Customer: Explicitly name the agency and the high-control environment context (e.g., Federal Agency, Military Branch, State Department).
  2. The Specific Compliance Baseline: Detail exactly how you applied security standards, naming the specific NIST families, FedRAMP control layers, or state statutory rules you personally mapped.
  3. Architecture Scale & Complexity: Specify the exact size of the cloud network architecture, the number of distinct user roles or environments secure-mapped, and the precise project duration.
  4. Personal Engineering Contribution: Detail exactly what you personally built, assessed, or documented (e.g., "Authored the System Security Plan for a FedRAMP High environment," "Configured least-privilege Entra ID access policies for database storage").
  5. Deployment & Vetting Status: Explicitly state the true production, operational, or steady-state authorization status achieved by platforms under your security oversight.
  6. Quantifiable Results: Include the precise metrics achieved under your guidance, such as percentage of vulnerabilities remediated, independent audit pass rates, or system availability uptime markers.

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status”

Texting Privacy Policy

  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting "Stop".

Skills

AzureDatabricksPower BICybersecurityPenetration TestingComplianceHIPAACISSP