Security Architect

4 days ago

Austin TX, TX, United States Texas Comptroller of Public Accounts Full-time
Agency Information Serve Texas with private-sector urgency and public-sector purpose. Every dollar the State of Texas collects, holds, or spends runs through the Comptroller's Office. We are the state's chief tax collector, accountant, revenue estimator, treasurer, and purchasing manager. We write the checks and keep the books for the multi-billion-dollar business of state government, and we serve virtually every Texan while doing it. Texans trust us with their money. We earn that trust every day by safeguarding taxpayer dollars, cutting waste, and finding better, faster, more efficient ways to get the job done. This is not a place to coast. The work is demanding, the pace is fast, and the standards are high. We want people who take ownership, question the status quo, and think creatively seeing beyond the obvious to solve the problems facing Texans. We measure ourselves by results. If you're driven by the idea that government can work better, and willing to work hard to prove it, you'll fit in here. What you'll get in return: real responsibility, meaningful work, and the chance to build your career alongside sharp, mission-focused professionals. We invest in people who invest in the job, with on-the-job training, professional development, and room to grow as fast as your performance allows. Public service is a calling. If you're ready to make every taxpayer dollar count, we want to hear from you. To stay current on your application, log in to the CAPPS portal to check for status updates. We update it as promptly as possible. Work Hours Monday through Friday, 40 hours a week with occasional evening, weekend hours and holidays. Hours may change based on business need. General Description Join Information Security Division (ISD) as a Security Architect. This role performs advanced cybersecurity analysis and security architecture support work for the ISD. Serves as the agency's principal security architect responsible for defining the enterprise security architecture, supporting security standards, and common control baselines that govern how security is designed into agency platforms, systems, and services. Serves as the ISD counterpart to the Enterprise Architect in Enterprise IT: the Security Architect will support the defining of security standards, control baselines, and security reference architectures; the Enterprise Architect embeds them into enterprise platforms as inheritable common controls. Aligns security architecture with TAC 477, the Texas Cybersecurity Framework, NIST SP 800-53, and TX-RAMP requirements. This is an individual contributor position with no supervisory responsibilities. Minimum Qualifications
- Graduation from an accredited college or university with major coursework in cybersecurity, computer science, management information systems, computer engineering, or a related field.
- Seven (7) years of progressively responsible experience in information security, security engineering, or systems security analysis, including at least three (3) years performing security architecture or security design work. Preferred Qualifications
- Experience in a Texas state agency or other public-sector environment, including TAC 477, Texas Cybersecurity Framework, TXCC security programs, and TX-RAMP.
- Experience defining common control frameworks or control inheritance models (e.g., NIST SP 800-53 common/hybrid controls) and authoring control implementation statements.
- Experience rationalizing or consolidating security tooling portfolios with measurable cost or operational savings.
- CISSP (ISSAP concentration preferred), CCSP, SABSA, GIAC security architecture credential (e.g., GDSA), or TOGAF certification.
- Experience supporting security assessment and authorization (A&A) or audit activities using inherited control documentation. Substitutions
- One (1) additional year of minimum experience as stated above may substitute for thirty (30) semester hours of the required education with a maximum substitution of 120 semester hours (four years). Licenses and Certifications
- Preferred: CISSP (ISSAP concentration preferred), CCSP, SABSA, GIAC security architecture credential (e.g., GDSA), or TOGAF certification. Essential Job Duties Security Architecture Strategy Support & Standards
- Support with developing and maintaining the agency¿s enterprise security architecture, security reference architectures, and target-state security patterns aligned with the enterprise architecture roadmap, agency risk posture, and TXCC statewide security direction.
- Assist in defining agency security standards, secure design patterns, and platform security requirements derived from TAC 477, the Texas Cybersecurity Framework, NIST SP 800-53, and the agency information security policies and control standards.
- Serve as the Information Security Division's voting member of the architecture review process; evaluate proposed solutions, platforms, and exceptions for conformance with security standards and risk tolerance. Common Control Baseline Analysis & Inheritance
- Define and document common and hybrid control baselines for enterprise platforms (identity, logging, encryption, configuration management, vulnerability management), including implementation statements and inheritance models consumable by system owners.
- Partner with the Enterprise Architect to ensure enterprise platforms operationalize defined control baselines so that consuming systems inherit controls consistently, reducing per-system control implementation and assessment burden.
- Validate that implemented platform controls satisfy the defined baselines; maintains traceability between platform capabilities, control statements, and compliance requirements to support assessment and audit activities. Security Tooling Rationalization
- Define the security tooling reference architecture and leads rationalization of the security tooling portfolio to eliminate duplicative agents, overlapping capabilities, and administrative overhead across platforms.
- Establish standard, enterprise-wide implementations for core security services
- identity and access management, logging and SIEM, endpoint protection, and encryption
- consumed uniformly by all platforms.
- Coordinate with Enterprise IT on platform-level deployment of consolidated security tooling and measure resulting cost and operational savings. Compliance & Risk Alignment
- Assess cloud services and platforms against TX-RAMP requirements and advise on certification pathways, continuous monitoring obligations, and inherited control documentation.
- Support security risk assessments of proposed architectures, major platform changes, and consolidation initiatives; document residual risk and recommend compensating controls.
- Review security exception requests against defined standards and advise the CISO on risk impact decisions. Advisory & Expertise Development
- Advise the CISO and ISD leadership on emerging threats, security technologies, and architectural implications of agency modernization initiatives.
- Mentor ISD and Enterprise IT staff on secure design practices; develop and maintain security architecture documentation, patterns, and standards to institutionalize knowledge.
- Represent the agency in interagency, TXCC, and security community workgroups.
- Perform related work as assigned. May also perform work listed in previous levels of the Cybersecurity Analyst series. Maximize Your Earnings At the Comptroller's office, we know potential employees are looking for more than just a paycheck. The agency offers a strong benefits package for you and your family. Insurance, retirement plans, and a flexible work schedule are just the start. See our benefits offering Please Note An applicant must be eligible to work in the United States to be hired at the Comptroller's office and must remain eligible, without sponsorship or any assurance of financial or other assistance from this agency, during the term of their employment. Applicants must ensure that all required supplemental questions are fully answered, complete job histories, and description of duties performed. Applications submitted through Work in Texas: Work In Texas (WIT) applicants must complete supplemental questions to be considered for the position. To complete the supplemental questions please go to CAPPS TAM to register or login and access

your profile
. Military Preference: To receive military preference, you are required to provide proof by attaching the necessary documentation to this job application. To explore how military experience may align with this role, applicants may review Military Occupational Specialty (MOS) codes within the State's Position Classification Plan. Please refer to the Military Crosswalk and select the occupational category that most closely corresponds with the classification listed in this job posting. The Comptroller's Office is proud to be an equal opportunity workplace. Due to the high volume of applications, we do not accept telephone calls. Only candidates selected to interview will be contacted. Notifications to applicants are sent electronically to the email address you provide.