LEAD ZERO TRUST ARCHITECT

ADP, Inc.

Leesburg (VA)

On-site

USD 140,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Triple Point Security is seeking a Lead Zero Trust Architect to guide a national research organization’s enterprise Zero Trust program from Leesburg, VA. You will lead a small team, develop future state ZTA reference architectures for cloud, on-prem, and hybrid environments, and ensure alignment with enterprise architecture.

You will present recommendations to client leadership, facilitate sessions, and contribute to monthly office hours, impacting federal and scientific communities served by

Qualifications

  • Bachelor's degree in a related field.
  • 5+ years in cybersecurity architecture or security engineering.
  • Knowledge of NIST SP 800-207, ZTMM v2.0, and EO 14028.
  • Experience mapping controls to frameworks and creating traceability.
  • Cloud architecture experience across cloud, on-prem, and hybrid.

Responsibilities

  • Lead Architecture & Engineering workstream with a small team.
  • Develop future state ZTA aligned to EO 14028 and M-22-09.
  • Manage the ZTA process integration tracker and funding evidence.
  • Present architecture recommendations to senior leadership.

Skills

Zero Trust
Architecture design
Leadership
Client-facing
Communication
Cloud IAM
Risk-based thinking

Education

Bachelor's degree in Computer Science/Info Systems/Cybersecurity/Engineering
Master's degree (preferred)

Tools

AWS
Azure
GCP

Job description

Salary Range: $140,000.00 To $160,000.00 Annually

About the Role

Triple Point Security is looking for a Lead Zero Trust Architect to join our team supporting a national research organization's enterprise Zero Trust program. Over the past few years, our team has helped this client assess its Zero Trust maturity and build roadmaps toward Advanced and Optimal maturity levels. The next phase focuses on helping the organization's institutes and system owners understand, adopt, and receive credit for the Zero Trust capabilities already provided at the enterprise level.

In this role, you will lead a small architecture and engineering team, including a Cloud/Hybrid Architect and two ZTA Controls Analysts, responsible for the future state Zero Trust architecture, reference architectures for cloud, on-premises, and hybrid environments, and control inheritance documentation. You will also work directly on tracking how Zero Trust requirements are built into the client's authorization, funding, and investment processes, and on aligning the target architecture with the client's enterprise architecture.

This is a client-facing position. You will work regularly with client leadership, architecture and security offices, and system owners, and you can expect to present architecture recommendations, facilitate working sessions and review meetings, and help lead the monthly office hours we host for the client's institutes. Your work will have a meaningful impact on the medical and scientific communities our client serves.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field from an accredited university
  • 5+ years of experience in cybersecurity architecture, enterprise security architecture, or security engineering, including demonstrated experience designing, assessing, or implementing Zero Trust Architecture in a Federal or large enterprise environment
  • Working knowledge of NIST SP 800-207, the CISA Zero Trust Maturity Model (ZTMM) v2.0 (five pillars and three cross-cutting capabilities), OMB Memorandum M-22-09, and Executive Order 14028
  • Strong knowledge of NIST SP 800-53 Rev. 5 and the NIST Risk Management Framework (SP 800-37), including common, hybrid, and system-specific controls and how control inheritance is claimed and evidenced
  • Experience developing target-state architectures, reference architectures, or reusable design patterns spanning cloud, on-premises, and hybrid environments
  • Hands-on architecture experience in at least one major cloud service provider (AWS, Azure, or GCP), including identity and access management, network segmentation, and logging and monitoring
  • Experience mapping security controls to capability frameworks or maturity models and producing traceability matrices, gap analyses, and remediation roadmaps
  • Experience leading technical staff, including assigning and sequencing work, reviewing deliverables for technical accuracy, and holding a team to fixed deliverable dates
  • Strong written communication skills, including the ability to produce clear, well-organized architecture deliverables for both technical and non-technical readers
  • Experience in client-facing roles, including presenting recommendations to senior leadership and governance bodies, facilitating meetings and working sessions, and building agreement among stakeholders with different priorities
  • Proven problem solving, critical analysis, and risk-based thinking skills to prioritize architecture recommendations against available time, budget, and staffing
Preferred Qualifications
  • 8+ years of experience in cybersecurity or IT architecture, including 3+ years in a lead or senior architect role
  • Master's degree in Cybersecurity, Information Systems, Computer Science, or a related field
  • Experience supporting Federal civilian agencies, particularly HHS or other research and health organizations with federated IT operating models
  • Experience with enterprise architecture frameworks (TOGAF, FEAF) and with mapping a target architecture to Business, Data, Application, Technology/Infrastructure, and Security Architecture domains
  • Experience embedding security requirements into IT governance and funding processes such as Capital Planning and Investment Control (CPIC), Enterprise Performance Life Cycle (EPLC) stage gates, ATO/A&A reviews, O&M project justifications, acquisition reviews, or architecture review boards
  • Experience recording control inheritance in GRC tools such as CSAM/JCAM, RSA Archer, or ServiceNow IRM
  • Familiarity with FedRAMP, Trusted Internet Connections (TIC) 3.0, CISA Continuous Diagnostics and Mitigation (CDM), and NIST SP 1800-35 (Implementing a Zero Trust Architecture)
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Bicep) and policy-as-code, including using automation to produce continuous monitoring evidence
  • Hands-on experience with ZT enabling technologies such as ICAM and PIV/PKI, Entra ID or Okta, ZTNA/SASE, micro-segmentation, and EDR/device posture solutions
  • Experience developing and delivering training, briefings, or recurring stakeholder forums such as office hours or communities of practice
  • Prior experience in a consulting or professional services environment, including contributing to technical proposals and capability briefings
Certifications
  • Required:at least one active senior cybersecurity certification: CISSP (Certified Information Systems Security Professional), CISSP-ISSAP (Information Systems Security Architecture Professional), CCSP (Certified Cloud Security Professional), or equivalent
  • Preferred:Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT)
  • Preferred:AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or equivalent cloud security certification
  • Preferred:CGRC (Certified in Governance, Risk and Compliance, formerly CAP) or CISM
Clearance and Suitability
  • Must be a U.S. citizen (client requirement).
  • Must be able to obtain and maintain a client suitability determination (Public Trust) and a client-issued Personal Identity Verification (PIV) credential, and complete required security and privacy training prior to access.
Responsibilities
  • Lead the Architecture & Engineering workstream: set the technical approach, assign and sequence work across the Cloud/Hybrid Architect and ZTA Controls Analysts, and review every team deliverable for technical accuracy before it enters independent quality review
  • Develop the Future State ZTA, integrating identity, device, network, application/workload, and data security controls supported by automation, orchestration, and continuous monitoring, aligned with Executive Order 14028, OMB M-22-09, the HHS ZTA, and CISA ZTMM v2.0, targeting Advanced maturity enterprise-wide and Optimal maturity for selected critical systems
  • Own the ZTA process integration tracker: identify, document, and maintain the processes and funding mechanisms that should require ZT evidence, including ATO/A&A reviews, cybersecurity funding requests, O&M project justifications, CPIC submissions, and procurement/acquisition reviews; for each, record the process owner, decision point, required evidence, insertion mechanism, approving governance body, and cycle date
  • Sequence ZT requirement insertions against the funding and planning calendars that govern them, and publish provisional criteria for the following cycle wherever the current cycle has closed
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Zero Trust (ZT) Technical Lead
Zero Trust (ZT) Technical Lead

Zermount, Inc. • Arlington (VA)

On-site
USD 120,000 - 160,000
Zero Trust (ZT) Technical Lead
Zero Trust (ZT) Technical Lead

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Zero Trust / Enterprise Security Architect
Senior Zero Trust / Enterprise Security Architect

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 165,000 - 175,000
Senior Zero Trust Identity and ICAM Engineer
Senior Zero Trust Identity and ICAM Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 135,000 - 180,000
401(k)
Competitive salary
Dental insurance
+4
Senior Zero Trust / Enterprise Security Architect
Senior Zero Trust / Enterprise Security Architect

eTelligent Group • Bethesda (MD)

Hybrid
USD 165,000 - 175,000
Zero Trust Identity and ICAM Engineer Mid Level
Zero Trust Identity and ICAM Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 120,000 - 180,000
401(k)
Competitive salary
Dental insurance
+5
ZERO TRUST (ZT) NETWORK ARCHITECTURE SME
ZERO TRUST (ZT) NETWORK ARCHITECTURE SME

Zermount, Inc. • Arlington (VA)

On-site
USD 120,000 - 160,000
Zero Trust Engineer
Zero Trust Engineer

Insight Global • Illinois

On-site
USD 120,000 - 130,000
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph, Immediate Hire
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph, Immediate Hire

Synertex LLC • Bethesda (MD)

On-site
USD 180,000 - 260,000
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph

Synertex LLC • Bethesda (MD)

On-site
USD 140,000 - 180,000