What are the responsibilities and job description for the Enterprise Cloud Security Architect position at Rose International?
Date Posted: 07/28/2026
Hiring Organization: Rose International
Position Number: 504807
Industry: Government/Staffing
Job Title: Enterprise Cloud Security Architect
Job Location: Madison, WI, USA, 53703
Work Model: Hybrid
Work Model Details: Primarily remote with some onsite work possibility
Shift: 8:00 AM - 5:00 PM
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 13
Min Hourly Rate($): 130.00
Max Hourly Rate($): 155.00
Must Have Skills/Attributes: Azure, Engineering, GitHub, Infrastructure, Validation
Experience Desired: Proven experience serving as a trusted technical advisor to CISOs, CIOs (1 yrs); Documented success as a technical mentor, trainer (1 yrs); Comprehensive expertise operationalizing security controls, including tiering models (1 yrs); Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io (1 yrs); Cloud Architecture & DevSecOps Engineering (1 yrs); Tech Stack to include: Google, Microsoft, AWS, Splunk (1 yrs); Federated/Government environment (1 yrs)
**C2C is not available**
Job Description
Candidate must be a Wisconsin resident or willing to relocate to Wisconsin prior to starting the role at their own expense. This position can work 100% remote with occasional onsite visits 1-2 times required throughout the duration of the contract.
Required Skills And Experience
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.
California Pay Equity
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.
Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.
If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.
Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).
Hiring Organization: Rose International
Position Number: 504807
Industry: Government/Staffing
Job Title: Enterprise Cloud Security Architect
Job Location: Madison, WI, USA, 53703
Work Model: Hybrid
Work Model Details: Primarily remote with some onsite work possibility
Shift: 8:00 AM - 5:00 PM
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 13
Min Hourly Rate($): 130.00
Max Hourly Rate($): 155.00
Must Have Skills/Attributes: Azure, Engineering, GitHub, Infrastructure, Validation
Experience Desired: Proven experience serving as a trusted technical advisor to CISOs, CIOs (1 yrs); Documented success as a technical mentor, trainer (1 yrs); Comprehensive expertise operationalizing security controls, including tiering models (1 yrs); Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io (1 yrs); Cloud Architecture & DevSecOps Engineering (1 yrs); Tech Stack to include: Google, Microsoft, AWS, Splunk (1 yrs); Federated/Government environment (1 yrs)
**C2C is not available**
Job Description
Candidate must be a Wisconsin resident or willing to relocate to Wisconsin prior to starting the role at their own expense. This position can work 100% remote with occasional onsite visits 1-2 times required throughout the duration of the contract.
Required Skills And Experience
- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments
- Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff
- Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures
- Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks
- Cloud Architecture & DevSecOps Engineering
- Federated/Government environment
- Tech Stack to include: Google, Microsoft, AWS, Splunk
- Progress will be measured not only by technical deployment velocity but also by the documented proficiency gains of internal DET staff who assume ownership of the deployed tools
- The consultant is strictly forbidden from utilizing public or unvetted commercial AI models for analyzing State code, logs, or asset data. All engineering must occur exclusively within authorized, state-managed enterprise security instances
- The consultant shall perform hands-on engineering, deliver strategic CISO advisory, and provide direct mentoring across the following core operational pillars
- Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives
- Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal DET staff to institutionalize elite technical skills
- Deliver real time training and co-develop automation playbooks within the security operations (SecOps) using live demonstration approach
- Architect automated tracking, logging, and validation mechanisms to implement compliance with the State’s updated SI-2 timeframes
- Ensure all public-facing vulnerabilities, CISA KEV listings, active exploits, and identity/privileged system flaws implement approved mitigations or compensating controls within 24 hours, with full remediation closed inside 7 calendar days
- Configure alerting and metric reporting to validate mitigation within 48 hours and full remediation within 15 calendar days
- Establish repeatable monthly scheduling to ensure remediation within 30 calendar days
- Partner with agency development teams to pivot away from manual, in-place patching
- Author and implement automated templates for clean deployments using virtualized system images, containers, and cloud-native configurations
- Embed secure builds, automated software testing, code scanning, and dependency updates natively into agency deployment pipelines
- Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, showing security analysts and application developers how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation
- Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass
- Ensure all AI-assisted capabilities comply strictly with State privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments
- Build automated low-code workflows to manage the SI-2 time-bound exception lifecycle, ensuring every granted exception maps back to a named owner, specific compensating controls, and an explicit financial tiedown capturing technical debt
- Configure automated alert thresholds and workflow routing for significant business risks that exceed normal management tolerance, ensuring rapid escalation in line with the SI-2 update
- **Only those lawfully authorized to work in the designated country associated with the position will be considered.**
- **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.
California Pay Equity
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.
Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.
If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.
Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).