Salary Range: $140,000.00 To $160,000.00 Annually
About the Role
Triple Point Security is looking for a Lead Zero Trust Architect to join our team supporting a national research organization's enterprise Zero Trust program. Over the past few years, our team has helped this client assess its Zero Trust maturity and build roadmaps toward Advanced and Optimal maturity levels. The next phase focuses on helping the organization's institutes and system owners understand, adopt, and receive credit for the Zero Trust capabilities already provided at the enterprise level.
In this role, you will lead a small architecture and engineering team, including a Cloud/Hybrid Architect and two ZTA Controls Analysts, responsible for the future state Zero Trust architecture, reference architectures for cloud, on-premises, and hybrid environments, and control inheritance documentation. You will also work directly on tracking how Zero Trust requirements are built into the client's authorization, funding, and investment processes, and on aligning the target architecture with the client's enterprise architecture.
This is a client-facing position. You will work regularly with client leadership, architecture and security offices, and system owners, and you can expect to present architecture recommendations, facilitate working sessions and review meetings, and help lead the monthly office hours we host for the client's institutes. Your work will have a meaningful impact on the medical and scientific communities our client serves.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field from an accredited university
- 5+ years of experience in cybersecurity architecture, enterprise security architecture, or security engineering, including demonstrated experience designing, assessing, or implementing Zero Trust Architecture in a Federal or large enterprise environment
- Working knowledge of NIST SP 800-207, the CISA Zero Trust Maturity Model (ZTMM) v2.0 (five pillars and three cross-cutting capabilities), OMB Memorandum M-22-09, and Executive Order 14028
- Strong knowledge of NIST SP 800-53 Rev. 5 and the NIST Risk Management Framework (SP 800-37), including common, hybrid, and system-specific controls and how control inheritance is claimed and evidenced
- Experience developing target-state architectures, reference architectures, or reusable design patterns spanning cloud, on-premises, and hybrid environments
- Hands-on architecture experience in at least one major cloud service provider (AWS, Azure, or GCP), including identity and access management, network segmentation, and logging and monitoring
- Experience mapping security controls to capability frameworks or maturity models and producing traceability matrices, gap analyses, and remediation roadmaps
- Experience leading technical staff, including assigning and sequencing work, reviewing deliverables for technical accuracy, and holding a team to fixed deliverable dates
- Strong written communication skills, including the ability to produce clear, well-organized architecture deliverables for both technical and non-technical readers
- Experience in client-facing roles, including presenting recommendations to senior leadership and governance bodies, facilitating meetings and working sessions, and building agreement among stakeholders with different priorities
- Proven problem solving, critical analysis, and risk-based thinking skills to prioritize architecture recommendations against available time, budget, and staffing
Preferred Qualifications
- 8+ years of experience in cybersecurity or IT architecture, including 3+ years in a lead or senior architect role
- Master's degree in Cybersecurity, Information Systems, Computer Science, or a related field
- Experience supporting Federal civilian agencies, particularly HHS or other research and health organizations with federated IT operating models
- Experience with enterprise architecture frameworks (TOGAF, FEAF) and with mapping a target architecture to Business, Data, Application, Technology/Infrastructure, and Security Architecture domains
- Experience embedding security requirements into IT governance and funding processes such as Capital Planning and Investment Control (CPIC), Enterprise Performance Life Cycle (EPLC) stage gates, ATO/A&A reviews, O&M project justifications, acquisition reviews, or architecture review boards
- Experience recording control inheritance in GRC tools such as CSAM/JCAM, RSA Archer, or ServiceNow IRM
- Familiarity with FedRAMP, Trusted Internet Connections (TIC) 3.0, CISA Continuous Diagnostics and Mitigation (CDM), and NIST SP 1800-35 (Implementing a Zero Trust Architecture)
- Experience with infrastructure-as-code (Terraform, CloudFormation, Bicep) and policy-as-code, including using automation to produce continuous monitoring evidence
- Hands-on experience with ZT enabling technologies such as ICAM and PIV/PKI, Entra ID or Okta, ZTNA/SASE, micro-segmentation, and EDR/device posture solutions
- Experience developing and delivering training, briefings, or recurring stakeholder forums such as office hours or communities of practice
- Prior experience in a consulting or professional services environment, including contributing to technical proposals and capability briefings
Certifications
- Required:at least one active senior cybersecurity certification: CISSP (Certified Information Systems Security Professional), CISSP-ISSAP (Information Systems Security Architecture Professional), CCSP (Certified Cloud Security Professional), or equivalent
- Preferred:Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT)
- Preferred:AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or equivalent cloud security certification
- Preferred:CGRC (Certified in Governance, Risk and Compliance, formerly CAP) or CISM
Clearance and Suitability
- Must be a U.S. citizen (client requirement).
- Must be able to obtain and maintain a client suitability determination (Public Trust) and a client-issued Personal Identity Verification (PIV) credential, and complete required security and privacy training prior to access.
Responsibilities
- Lead the Architecture & Engineering workstream: set the technical approach, assign and sequence work across the Cloud/Hybrid Architect and ZTA Controls Analysts, and review every team deliverable for technical accuracy before it enters independent quality review
- Develop the Future State ZTA, integrating identity, device, network, application/workload, and data security controls supported by automation, orchestration, and continuous monitoring, aligned with Executive Order 14028, OMB M-22-09, the HHS ZTA, and CISA ZTMM v2.0, targeting Advanced maturity enterprise-wide and Optimal maturity for selected critical systems
- Own the ZTA process integration tracker: identify, document, and maintain the processes and funding mechanisms that should require ZT evidence, including ATO/A&A reviews, cybersecurity funding requests, O&M project justifications, CPIC submissions, and procurement/acquisition reviews; for each, record the process owner, decision point, required evidence, insertion mechanism, approving governance body, and cycle date
- Sequence ZT requirement insertions against the funding and planning calendars that govern them, and publish provisional criteria for the following cycle wherever the current cycle has closed