Zero Trust Security Architect

Brooksource

United States

Hybrid

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Brooksource is seeking an Enterprise Architect to lead design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy. Responsibilities include defining and operationalizing a “never trust, always verify” model across identity, devices, networks, applications, and data.

The successful candidate will drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least

Qualifications

  • 7+ years of relevant experience.
  • Bachelor’s Degree in Computer Science, Information Security, or related field or equivalent.
  • Master’s degree preferred.
  • 5+ years designing or implementing Zero Trust Architecture or related initiatives.
  • Strong understanding of Zero Trust principles and frameworks.
  • Experience with IAM, authentication/authorization, and policy-based access control.
  • Experience with network security, segmentation, ZTNA, and modern connectivity.
  • Endpoint security experience and device posture integration.
  • Secure architectures across hybrid cloud, SaaS, and on‑prem environments.
  • Proven ability to integrate multiple security domains into cohesive architectures.

Responsibilities

  • Define and maintain the enterprise Zero Trust Architecture reference model aligned to frameworks and business priorities.
  • Establish target‑state architectures and roadmaps for Zero Trust across hybrid cloud, SaaS, and on‑prem environments.
  • Define policy‑driven access models leveraging identity, device posture, behavior, and risk signals.
  • Lead architecture reviews to ensure alignment with least privilege and continuous verification.
  • Provide governance for Zero Trust capabilities across business units and shared services.
  • Collaborate with IAM, Network, Cloud, Endpoint, and Data teams to enforce consistent Zero Trust controls.

Skills

Zero Trust Architecture
IAM
ZTNA
Policy-based Access Control
NIST SP 800-207
Security Architecture
Threat Modeling
Architecture Reviews
Regulatory Compliance
Executive Communication

Education

Bachelor's degree in CS/Information Security
Master’s degree

Tools

Identity Platforms
ZTNA Solutions
API Gateways
Microsegmentation Tools

Job description

  • 12-month contract with strong potential for extension or full-time conversion
  • Standard business hours (Monday–Friday)
  • Business casual environment
  • Charlotte, NC – Hybrid schedule (3 days onsite, 2 days remote)
  • W-2 only (not compatible with C2C or 1099); must be authorized to work in the U.S. without sponsorship

Brooksource is searching for an Enterprise Architect to lead the design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy.

Responsibilities include defining and operationalizing a “never trust, always verify” model across identity, devices, networks, applications, and data. The successful candidate will drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least privilege and continuous verification across all enterprise resources.

MINIMUM QUALIFICATIONS:
  • 7+ years of relevant experience
  • Bachelor’s Degree in Computer Science, Information Security, or related field of study or equivalent
PREFERRED QUALIFICATIONS:
  • Master’s in Computer Science, Information Security, or related field.
  • 5+ years designing or implementing Zero Trust Architecture or similar enterprise security transformation initiatives
  • Deep understanding of Zero Trust principles and frameworks (NIST SP 800-207, CISA Zero Trust Maturity Model)
  • Strong experience in IAM, authentication/authorization, and policy-based access control models
  • Experience with network security, segmentation, ZTNA, and modern connectivity architectures
  • Experience with endpoint/device security and integration of device posture into access decisions
  • Experience designing secure architectures across hybrid cloud (AWS/Azure), SaaS, and on-prem environments
  • Proven experience integrating multiple security domains into cohesive architecture patterns
  • Hands‑on or architectural experience with technologies such as identity platforms, ZTNA solutions, API gateways, and microsegmentation tools
  • Strong experience with threat modeling, architecture reviews, and security risk assessments
  • Familiarity with regulatory frameworks (FFIEC, PCI DSS, SOX) and security frameworks (NIST, CIS)
  • Demonstrated ability to influence cross-functional teams and drive enterprise adoption of security patterns
  • Strong communication and executive presentation skills
KEY RESPONSIBILITIES:
Architecture & Strategy:
  • Define and maintain the enterprise Zero Trust Architecture (ZTA) reference model, aligned to industry frameworks (NIST SP 800-207, CISA ZTMM) and business priorities.
  • Establish target‑state architectures and transition roadmaps for Zero Trust adoption across hybrid cloud, SaaS, and on‑prem environments.
  • Define policy‑driven access models leveraging identity, device posture, behavior, and environmental risk signals.
  • Align Zero Trust architecture with enterprise security strategy, cloud adoption, and digital transformation initiatives.
  • Lead end‑to‑end architecture reviews ensuring solutions align with Zero Trust principles, including least privilege, continuous verification, and explicit trust evaluation.
  • Define and enforce architectural guardrails and secure patterns across identity, network, endpoint, application, and data layers.
  • Establish policy decision and enforcement models (PDP/PEP) across enterprise control points (identity providers, gateways, endpoints, network controls).
  • Provide governance and oversight for Zero Trust capabilities across business units, platforms, and shared services.
Cross-Domain Integration:
  • Design integration patterns that unify IAM, endpoint security, network controls, application access, and data protection into a cohesive Zero Trust model.
  • Define how identity, device posture, and risk signals drive dynamic access decisions across APIs, applications, and infrastructure.
  • Collaborate with domain architects (IAM, Network, Cloud, Endpoint, Data) to ensure consistent enforcement of Zero Trust controls and patterns.
  • Enable secure service‑to‑service and user‑to‑resource access patterns across distributed architectures (microservices, APIs, SaaS).
Policy, Access & Control Enforcement
  • Define enterprise access control strategies including adaptive authentication, conditional access, and fine‑grained authorization.
  • Establish policy models for user, service, and machine identity access, incorporating RBAC, ABAC, and policy‑based access control.
  • Define enforcement patterns across gateways, proxies, API layers, and endpoint controls to ensure consistent access decisions.
  • Integrate continuous monitoring and feedback loops to adjust access decisions based on real‑time risk and context.
  • Lead threat modeling initiatives focused on lateral movement, identity compromise, session hijacking, and trust boundary violations.
  • Define security controls to mitigate Zero Trust‑specific attack vectors (credential abuse, privilege escalation, bypass of enforcement points).
  • Ensure Zero Trust architecture aligns with regulatory requirements and supports continuous risk reduction and measurable security outcomes.
  • Establish metrics and maturity indicators for Zero Trust adoption and effectiveness across the enterprise.
  • Drive adoption of Zero Trust patterns through reusable architectures, reference implementations, and engineering guidance.
  • Partner with engineering, platform, and security teams to embed Zero Trust controls into SDLC, CI/CD, and platform engineering workflows.
  • Evaluate and recommend technologies supporting Zero Trust capabilities (identity platforms, ZTNA, microsegmentation, API gateways, endpoint posture).
  • Communicate architecture strategy, tradeoffs, and risk posture clearly to engineering, product, and executive stakeholders.
CORE SECURITY DOMAINS:
Identity & Access Management:
  • Authentication, federation, adaptive MFA, conditional access, service‑to‑service identity, least privilege, and identity governance.
  • Device posture, endpoint detection and response (EDR), mobile/device trust, health validation, and enforcement of device‑based access conditions.
Network Security & Segmentation
  • Microsegmentation, software‑defined perimeters, ingress/egress controls, secure connectivity, and enforcement of network‑level policy decisions.
Application & API Security
  • Application access control, API authentication/authorization, secure service communication, token‑based access, and policy enforcement at application layers.
Data Security
  • Data classification, encryption, data minimization, access controls aligned to sensitivity, and protection of data across states (in transit, at rest, in use).
Visibility, Analytics & Automation
  • Centralized telemetry, continuous monitoring, behavioral analytics, policy decision support, and automated response and enforcement.
GenAI Security
  • Define secure GenAI patterns (LLM access controls, prompt/response handling, RAG security, agent/tooling boundaries).
  • Threat model GenAI use cases (prompt injection, data leakage, model extraction/poisoning, unsafe output handling) and define mitigations/testing.
  • Set GenAI data governance requirements (sensitive data use, retention, auditability) and vendor/model assurance expectations.

Eight Eleven Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, national origin, age, sex, citizenship, disability, genetic information, gender, sexual orientation, gender identity, marital status, amnesty or status as a covered veteran in accordance with applicable federal, state, and local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise Architect – Zero Trust
Enterprise Architect – Zero Trust

Eightelevengroup • Charlotte (NC), Northern (KY)

Hybrid
USD 90,000 - 103,000
Enterprise Architect - Zero Trust
Enterprise Architect - Zero Trust

Brooksource • Charlotte (NC)

Hybrid
USD 90,000 - 103,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Wilmington (DE)

On-site
USD 150,000 - 210,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Irving (TX)

On-site
USD 170,000 - 230,000
Zero Trust Architect
Zero Trust Architect

Digital Global Connectors • McLean (VA)

Hybrid
USD 140,000 - 230,000
Zero Trust Architect
Zero Trust Architect

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 140,000 - 190,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Manassas (VA)

On-site
USD 127,000 - 236,000
Health benefits
401(k) and Profit Sharing
Paid time off
+1
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Urbandale (IA)

On-site
USD 127,000 - 236,000
Health insurance
Dental insurance
Vision insurance
+5
Zero Trust Engineer Mid Level
Zero Trust Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Dental insurance
Health insurance
+3
Zero Trust Architect - Security
Zero Trust Architect - Security

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 150,000 - 200,000