Solutions Architect - FDIC Enterprise DevSecOps
Skills
About the role
Description
The Solutions Architect is a Key Personnel role on the FDIC Enterprise DevSecOps program, supporting the client's CIO organization (CIOO). The architect owns the target-state design of the FDIC DevSecOps platform - a hybrid estate spanning Azure/AKS, AWS, mainframe z/OS/Endevor, and enterprise middleware (WebLogic/WebSphere, Oracle, PeopleSoft, SAP, MuleSoft, Appian, Salesforce, Power Platform) across a large, complex enterprise DevSecOps environment at DevSecOps maturity Level 2 of 5. The architect translates FDIC Enterprise Architecture (EA) directives and enterprise architecture governance requirements into actionable, repeatable platform blueprints that enable development teams to ship securely with minimal client intervention. This role demands recent, hands-on design authority over the exact FDIC self-managed toolchain - GitHub Enterprise Server, GitHub Cloud/Actions, GitHub Advanced Security (GHAS), JFrog Artifactory/Xray, SonarQube, and Subject7 on Azure/AKS - and a demonstrated ability to harden that platform to FISMA-moderate, NIST 800-53/800-207, OMB M-22-09, and CISA Zero Trust Maturity Model 2.0 (target: Optimal) standards.
PRIMARY RESPONSIBILITIES
Platform Architecture and Target-State Design
Own the DevSecOps platform architecture across the FDIC hybrid estate (Azure primary - AKS, ACR, App Gateway, Key Vault; plus AWS, mainframe z/OS/Endevor, WebLogic/WebSphere, Oracle, PeopleSoft, SAP Data Services, MuleSoft, Appian, Salesforce, Power Platform); produce and maintain Architecture Decision Records (ADRs) aligned to FDIC target-state EA.
Design self-managed platform deployments for JFrog Artifactory/Xray, SonarQube, GitHub Enterprise Server (GHES), GitHub Advanced Security (GHAS)/CodeQL, and Subject7 on AKS; define upgrade paths under the n/n-1 version strategy.
Establish immutable-infrastructure and GitOps patterns (Flux, Helm) for the AKS platform; author Terraform IaC modules and Bicep templates for repeatable, policy-compliant provisioning across Azure and AWS landing zones.
Design pipeline architecture for a large CI/CD pipeline estate (GitHub Actions; on-prem, cloud, hybrid, multicloud patterns), integrating blocking security gates: SAST/SCA on Critical/High, IaC scan on Critical, DAST on Critical, container scan on Critical/High, SonarQube quality gate on fail.
Define architecture for GitHub Copilot (SaaS) integration and AI-assisted development workflows within FDIC compliance constraints.
Security Architecture and Zero Trust
Architect Zero Trust controls aligned to OMB M-22-09 and CISA ZTMM 2.0 at Optimal maturity; map identity (Entra/CyberArk), device, network, application, and data pillars to the DevSecOps toolchain.
Design policy-as-code enforcement (OPA/Gatekeeper, Azure Policy) for Kubernetes admission control and IaC guardrails; ensure CyberArk and Azure Key Vault secrets management patterns meet FIPS 140-2/3 and PQC (FIPS 203/204/205) requirements.
Define cATO (continuous ATO) architecture: continuous compliance monitoring via Splunk and DynaTrace, automated evidence collection, and alignment to NIST 800-37/800-53/800-88/800-207 control families for FISMA-moderate boundary.
Establish container security architecture integrating Aqua, Trivy, Trufflehog, and GHAS/CodeQL scanning into build and release pipelines; ensure secrets + peer-review gates at Develop stage are architecturally enforced.
Lead architecture reviews through enterprise architecture and change governance boards (EA fitness gate), CCB, ISSM/ISSO, and OCISO coordination bodies; produce fitness-gate artifacts that prevent rework.
Hybrid and Mainframe Integration Architecture
Architect API and event-driven integration patterns for MuleSoft, Appian, Salesforce, and Power Platform workloads; define DevSecOps onboarding playbooks for each platform tier.
Produce reference architectures for WebLogic/WebSphere, Oracle, PeopleSoft, and SAP Data Services application pipelines, covering build, scan, test (Selenium/Playwright/JMeter/Subject7), and release stages.
SLA, Observability, and Reliability Architecture
Architect the observability stack (Splunk, DynaTrace, Azure Monitor) to enforce >99.5% availability SLAs for the 83 Mission Essential/Critical applications and Critical/High security-finding remediation within Original Posting:
June 17, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $131,300.00 - $237,350.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
#Remote
Compensation
This Solutions Architect role pays $131k-$237k/yr. Within typical range for solutions architect roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.