Secure Enclave Strategy & Enablement Lead
Lenexa, KS, US
Requisition ID: 181765
Job Level: Senior Level
Home District/Group: Kiewit Nuclear Solutions
Department: Risk Management
Market: Nuclear
Employment Type: Full Time
Position Overview
Kiewit is seeking a senior technology leader to enable secure execution for critical projects. This role will define and advance the secure-environment strategy needed to support CMMC Level 2 and related customer requirements—balancing compliance with practical business delivery.
This is a highly strategic role, the right candidate will bring firsthand experience establishing secure enclaves, know which questions to ask, understand where scope can be reduced, and guide the technical teams that implement the solution.
District Overview
Kiewit Nuclear Solutions is a full-service engineering, project management and construction provider operating across North America. Our experience spans all aspects of the nuclear market from carbon-free, small modular reactors to Department of Energy science, environmental and nuclear security mission capabilities. With these broad capabilities, we operate in the power utility, renewable energy, industrial and infrastructure markets.
Location
Location: Lenexa, KS (preferred). Will consider other locations and remote.
Responsibilities
- Lead the strategy, requirements definition, and roadmap for secure technology environments supporting Kiewit’s businesses.
- Assess and optimize Kiewit’s existing secure environment, including the gap between commercial and secure operating models.
- Define fit-for-purpose CMMC Level 2-aligned secure-enclave requirements for systems, data, users, vendors, and project workflows.
- Challenge assumptions and prevent unnecessary systems, data, or processes from entering the enclave while maintaining compliance and customer confidence.
- Partner with business, technology, cybersecurity, infrastructure, application, legal/compliance, and project stakeholders to translate contract and regulatory requirements into executable solutions.
- Establish scalable architecture, governance, controls, and operating processes that support the business for the next five to 10 years.
- Develop a practical model for different work types, including highly regulated government work and commercial work requiring heightened controls but not necessarily CMMC Level 2.
- Guide technical implementation teams on identity and access management, data protection, network segmentation, infrastructure, application verification, monitoring, incident response, evidence, and ongoing compliance.
- Support customer and government-facing discussions by clearly explaining Kiewit’s secure-environment approach and compliance posture.
- Build the business case, priorities, and future team structure needed to sustain and expand the capability.
What Success Looks like in the First-Year
- Rapidly understand the current secure environment, its certification posture, and its limitations.
- Complete or strengthen the gap analysis between existing commercial and secure environments.
- Define the appropriate enclave boundary and reduce unnecessary scope, cost, complexity, and “blast radius.”
- Deliver a prioritized roadmap to optimize the current environment and support near-term pursuits.
- Establish a longer-term architecture and operating model for both government-regulated and commercial work.
- Enable the business to pursue and execute work with a secure environment that customers trust.
Qualifications
- 10+ years of progressive experience in cybersecurity, secure-environment architecture, IT infrastructure, compliance, technology risk, or a closely related field.
- Demonstrated experience designing, standing up, governing, or materially improving a secure enclave or controlled environment for CUI, export-controlled information, classified information, government programs, or similarly regulated work.
- Strong working knowledge of CMMC Level 2 and the ability to translate its requirements into a practical operating environment.
- Experience with CUI scoping, system boundaries, data-flow decisions, control ownership, System Security Plans, POA&Ms, audit evidence, and assessment readiness.
- Broad understanding of infrastructure, cloud/hybrid environments, identity and access management, endpoint security, network segmentation, application verification, logging, vulnerability management, and incident response.
- Ability to lead through influence across technical teams, business leaders, and external customers.
- Sound judgment on when a control is required, when a requirement can be met another way, and how to avoid over-engineering a solution.
- Bachelor’s degree in information technology, cybersecurity, engineering, computer science, or a related field; equivalent relevant experience will be considered.
Preferred Qualifications
- Nuclear, DOE/NNSA, defense, critical-infrastructure, EPC, advanced-reactor, or regulated engineering-industry experience.
- Experience supporting CMMC Level 2 assessments or building a CMMC Level 2-ready environment.
- Familiarity with GCC High, GovCloud, or comparable controlled cloud environments.
- Experience supporting an organization through the transition from a commercial environment to segmented secure operating models.
- Relevant credentials such as CISSP, CISM, CCSP, PMP, CMMC CCP/CCA, or comparable certifications.
Other Requirements:
- Regular, reliable attendance
- Work productively and meet deadlines timely
- Communicate and interact effectively and professionally with supervisors, employees, and others individually or in a team environment.
- Perform work safely and effectively. Understand and follow oral and written instructions, including warning signs, equipment use, and other policies.
- Work during normal operating hours to organize and complete work within given deadlines. Work overtime and weekends as required.
- May work at various different locations and conditions may vary.
We offer our fulltime staff employees a comprehensive benefits package that’s among the best in our industry, including top-tier medical, dental and vision plans covering eligible employees and dependents, voluntary wellness and employee assistance programs, life insurance, disability, retirement plans with matching, and generous paid time off.
Equal Opportunity Employer, including disability and protected veteran status.
Job Segment:
Compliance, Nuclear Engineering, Cyber Security, Risk Management, Computer Science, Legal, Engineering, Security, Finance, Technology