Job#: 3025371 Job Description: Cybersecurity Architect (Enterprise SOC)
Location: Onsite - Southern California (100% onsite, no remote)
Engagement Type: 12-Month Contract-to-Hire
Compensation: Conversion rate of 170-180k/annually
Start: Ready to interview and onboard ASAP
Overview
We are seeking a
Cybersecurity Architect to support a large, mission-critical enterprise environment operating a mature
Security Operations Center (SOC). This role will provide
technical leadership, architecture ownership, and hands-on execution across core cybersecurity domains, including network security, firewall platforms, SIEM, incident response, and regulatory compliance.
This position is ideal for a senior security professional who enjoys
designing security architecture while remaining hands-on, and who is comfortable operating in
highly regulated, high-availability environments.
Note: This role requires full-time onsite presence.
Key Responsibilities
Security Architecture & Engineering
- Design, implement, and maintain a robust enterprise-wide cybersecurity architecture.
- Develop security policies, standards, and reference architectures aligned to Zero Trust principles.
- Lead architectural decisions for network security, segmentation, and access control.
- Ensure security controls are scalable, resilient, and aligned with regulatory requirements.
Firewall & Network Security Platforms
- Serve as the primary technical authority for next-generation firewall platforms and centralized management tools.
- Design and maintain firewall rule sets, security zones, threat prevention policies, and segmentation strategies.
- Lead firewall migrations, redesigns, and optimization initiatives.
- Provide advanced troubleshooting and Tier-4 escalation support.
VPN & Remote Access Security
- Architect and manage secure remote access solutions, ensuring MFA and least-privilege access models.
- Design and support site-to-site, remote access, and third-party VPN integrations.
Wireless & DNS Security
- Define and enforce secure wireless architectures for corporate and guest environments.
- Implement secure DNS architectures and protective controls.
SIEM & Security Monitoring
- Lead the design, integration, and tuning of enterprise SIEM solutions.
- Architect log ingestion pipelines from security and infrastructure devices.
- Develop correlation rules, alerts, dashboards, and reports to detect and prioritize threats.
Incident Response & Threat Handling
- Develop, maintain, and test Incident Response plans and playbooks.
- Act as a lead responder during major security incidents.
- Drive post-incident reviews and define architectural remediation strategies.
Compliance & Governance
- Ensure security architecture and operations comply with applicable regulatory and compliance frameworks.
- Develop enterprise security standards, control baselines, and documentation.
- Conduct security assessments and guide remediation efforts.
Required Qualifications
Education & Experience
- Bachelor's degree in Cybersecurity or related technical field with 7+ years of relevant experience
- OR
- Master's degree with 5+ years of relevant experience
- OR
- Doctorate with 4+ years of relevant experience
Technical Experience
- Extensive experience supporting or leading security initiatives within a SOC or enterprise security organization.
- Strong expertise in:
- Network security architecture and design
- Firewall platforms and security services
- SIEM architecture and log analytics
- Incident response lifecycle
- Experience securing large, complex enterprise networks.
- Strong troubleshooting, documentation, and communication skills.
- Ability to manage multiple initiatives simultaneously in high-pressure environments.
Certifications (One or More Preferred)
- CISSP
- GIAC (GCIH, GREM, or similar)
- CEH or equivalent security certifications
Preferred Experience
- Experience working in government, public sector, or highly regulated environments.
- Familiarity with compliance frameworks such as CJIS-aligned, NIST, or similar standards.
- Experience mentoring or providing technical leadership to security teams.
Engagement Details
- Work Schedule: Full-time, 40 hours/week
- Overtime: Not anticipated
- Work Environment: Onsite enterprise SOC
- Employment Type: Contract-to-hire with long-term potential
- Security Screening: Must successfully complete an enhanced background screening process
EEO Employer
Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or .
Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Apex uses a virtual recruiter as part of the application process. Click for more details.
Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.