Job Summary
Job Description
Key Accountabilities:
- Design and govern secure architectures across cloud, identity, applications, and data platforms.
- Lead application security initiatives including assessments, threat modeling, secure SDLC practices, and vulnerability remediation.
- Support CMMC 2.0 Level 2+ readiness, including NIST 800 171/172 control implementation, SSP/POA&M management, and audit support.
- Architect and operate security capabilities within Microsoft GCC High and Azure Government, including Defender, Sentinel, Purview, and Entra ID.
- Provide senior level guidance during security incidents, investigations, and post incident remediation.
- Translate regulatory and business requirements into scalable security roadmaps and standards.
- Serve as a trusted advisor to engineering, IT, and leadership teams, mentor security professionals.
- Meets TKMNA Employee Attributes / Competencies
The above is intended to describe the general content of and requirement for the performance of this job. It is not to be construed as an exhaustive statement of duties, responsibilities or requirements.
Qualifications:
Minimum Requirements:
- Bachelor’s degree or equivalent professional experience required, Master’s degree preferred.
- 7+ years of experience in information security, including hands‑on security architecture or application security experience.
- Strong experience securing Microsoft 365 GCC‑High and Azure Government environments.
- Demonstrated expertise with cloud security, identity and access management, application security, and incident response.
- Experience supporting regulated environments (CMMC, ITAR, DFARS, or similar).
Certifications
- All relevant security and cloud certifications preferred, including CISSP, CCSP, CISM, GIAC, and Microsoft security certifications.
Skills
- Cloud & Identity: Azure Gov, M365 GCC‑High, Entra ID, Zero Trust, Conditional Access, MFA, PIM
- Application Security: Threat modeling, SAST/DAST/SCA, API and container security
- Monitoring & Response: Microsoft Sentinel, Defender XDR, automation and incident response
- Compliance: CMMC 2.0, NIST 800‑171/172, ITAR, risk management
Disclaimer
This is to notify the general public that some individuals/entities are using the thyssenkrupp (“TK”) name, trademark, domain name, and logo without authorization. They are posing as employees, representatives, or agents of TK and its associated/group companies. These individuals/entities are fraudulently offering jobs online through texts, websites, telephone calls, emails, or by issuing fake offer letters. They are also soliciting jobseekers to deposit money in certain bank accounts or providing jobseekers with fraudulent checks to obtain banking information.