Job ID: 2614718
Location: Springfield, VA, US
Date Posted: 2026-07-20
Category: Cyber
Subcategory: Cyber Engineer
Schedule: Full-Time
Shift: Day Job
Travel: No
Minimum Clearance Required: Secret
Clearance Level Must Be Able to Obtain: Top Secret
Potential for Remote Work: ORA_HYBRID
Description
The Communication Security Lead Architect provides strategic direction, technical leadership, and operational execution for the department of State’s (DOS) high-assurance Communications Security (COMSEC) infrastructure. This position oversees a multidisciplinary team of professionals, such as network engineers, systems engineers, security analysts, COMSEC auditors, and logistics specialists, Data Engineers ensuring the delivery of robust, compliant, and innovative cryptographic solutions.
This position encompasses all stages of the high-assurance ecosystem lifecycle, including KMI and INE solutions, Over-the-Network Keying (OTNK) implementations, secure warehouse logistics, as well as overseeing the evaluation, selection, and phased introduction of emerging technologies.
The primary focus of this role is spearheading modernization efforts, including adoption automation, dashboarding, and Post-Quantum Cryptography (PQC), and transitioning to next-generation High-Assurance Inline Network Encryption (HAIPE) and modern fill devices.
Key Responsibilities:
Technical Leadership
- Direct Supervision: Manage, mentor, and evaluate a large team of KMI professional, Network & Systems engineers, security analysts, COMSEC auditors, and logistics personnel.
- Resource Integration: Align staffing and skill sets across distinct engineering, daily cryptographic operations, and compliance workstreams.
- Culture of Innovation: Foster continuous training on emerging cryptographic standards, Zero Trust Architecture (ZTA), and evolving threat vectors.
Emerging Technology Evaluation & Adoption
- Next-Gen HAIPE Deployment: Lead the technical evaluation, laboratory benchmarking, and phased rollout of next-generation HAIPE devices, ensuring multi-enclave throughput, backward compatibility, and adherence to national security validation standards.
- Modern Load Infrastructure & Crypto-Agility Engineering: Oversee the strategic transition from legacy fill devices to modern Next Generation Load Device (NGLD) platforms, integrating seamlessly with contemporary Key Management Infrastructure (KMI).
- Drive the adoption of crypto-agile frameworks capable of seamlessly ingesting new cryptographic algorithms without requiring extensive physical hardware replacement.
COMSEC Engineering & Lifecycle Operations
- Solutions Development: Architect, test, and deploy secure enterprise and tactical cryptographic solutions.
- Post-Quantum Cryptography (PQC) Transition: Drive strategic roadmaps, cryptographic asset discovery, and the implementation of PQC algorithms to safeguard data against quantum threats.
- Vulnerability & Patch Management: Direct rigorous testing, scheduling, and deployment of firmware modifications, software patches, and security configurations across all high-assurance assets.
Lifecycle Logistics & Secure Warehouse Operations
- Warehouse Accountability: Supervise secure warehouse environments managing Controlled Cryptographic Items (CCI), ensuring strict compliance regarding receipt, storage, distribution, and destruction.
- Key Management Automation: Oversee traditional and modern automated key generation, escrow, and distribution mechanisms, specializing in Over-the-Network Keying (OTNK) protocols.
Compliance, Governance, & Strategic Partnerships
- Audit Readiness: Direct comprehensive COMSEC account audits to maintain absolute compliance with federal, defense, or institutional security mandates.
- Governance Representation: Serve as the technical representative on executive steering committees and inter-agency governance working groups to influence cryptographic policy.
- Partner Collaboration: Partner with external security agencies, technical vendors, and institutional stakeholders to evaluate emerging tools and synchronize joint operational frameworks.
Qualifications
Required Education & Experience:
-
Bachelors in Computer Science, Cybersecurity, Electrical Engineering, or a related technical discipline and fourteen (14) years or more experience; Masters and twelve (12) years or more experience; may accept additional experience in lieu of degree.
Required Technical Competencies:
-
High-Assurance Cryptography: Deep understanding of traditional and modern COMSEC architecture, Key Management Infrastructure (KMI), and type-1 encryption devices (e.g., TACLANE, SKL, KGV platforms).
-
Modernization Frameworks: Experience aligning enterprise technology with National Security Agency (NSA) Commercial National Security Algorithm (CNSA 2.0) guidelines and NIST standards.
-
Testing & Prototyping: Proven ability to establish isolated testing enclaves, define Proof-of-Concept (PoC) performance criteria, and manage low-blast-radius deployment strategies.
Leadership & Strategic Skills
-
Scale Management: Demonstrated success leading large technical teams (25+ personnel) within high-stakes, mission-critical environments.
-
Stakeholder Diplomacy: Exceptional written and verbal communication skills, with a proven ability to present complex technical risks and engineering roadmaps to executive leadership and external governance boards.
-
Decisiveness: Strong command presence with a methodical, risk-based approach to incident response, vulnerability management, and infrastructure bottlenecks.
Preferred:
-
CISSP, CISM, or formal federal/defense COMSEC Manager certifications.
-
PKI Engineering expertise.
Required Clearance:
-
US Citizenship.
-
Active secret clearance with the ability to obtain a top secret clearance.
Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.