Capitol Careers is currently in search of a Zero Trust Security Architect for a large Federal Consulting Firm.
This is a Hybrid position, and requires working onsite in Washington, DC one day a week.
This position requires an Active Secret or Top-Secret Security Clearance.
About the Opportunity:
In this role, you will connect enterprise security strategy with technical delivery, helping client leadership develop and execute a multi-phase Zero Trust roadmap. You will assess existing capabilities, define priorities, guide engineering teams, and communicate the business value of proposed security investments.
The environment is anchored in the Microsoft security ecosystem. You will apply broad knowledge of Microsoft G5 security and compliance capabilities to maximize existing investments while guiding initiatives involving cloud application security, personal-device access, secure connectivity, and security automation.
This opportunity requires both architectural depth and executive communication skills. You should be able to explain a strategic roadmap to leadership and then work with engineers to ensure its capabilities are implemented and operationally sustainable.
Key Responsibilities:
Zero Trust Strategy and Roadmap
- Assess the current security environment and identify gaps in Zero Trust capabilities and maturity.
- Develop a phased roadmap with clear priorities, dependencies, milestones, and intended outcomes.
- Align proposed initiatives with business needs, operational constraints, and existing technology investments.
- Establish governance processes for reviewing architecture decisions, tracking progress, and addressing implementation risks.
- Update the roadmap as priorities, capabilities, and implementation findings evolve.
Executive Advisory and Business Cases
- Partner with client leadership to build agreement on Zero Trust objectives and implementation priorities.
- Translate technical concepts and security risks into clear executive briefings.
- Develop business cases explaining the benefits, tradeoffs, dependencies, and resource needs of proposed initiatives.
- Present recommendations that help stakeholders make informed investment and sequencing decisions.
- Communicate progress and unresolved issues across executive, business, and technical audiences.
Microsoft Security Architecture
- Apply broad working knowledge of Microsoft G5 security and compliance capabilities to solution planning.
- Identify opportunities to use native Microsoft functionality effectively and reduce unnecessary tool overlap.
- Coordinate architecture across identity, device, application, and data protection initiatives.
- Review engineering designs for consistency with the target architecture and approved security objectives.
- Help teams address integration dependencies and operational requirements before implementation.
Cloud Access, BYOD, and Secure Connectivity
- Guide Cloud Access Security Broker (CASB) policy design and enforcement.
- Provide architectural direction for a secure Bring Your Own Device (BYOD) program.
- Advise on Secure Access Service Edge (SASE) transition planning, including dependencies and phased adoption.
- Coordinate with identity, endpoint, network, and data security teams to establish consistent access controls.
- Evaluate proposed designs against user needs, security requirements, and operational support considerations.
Security Automation and Engineering Oversight
- Guide Security Orchestration, Automation, and Response (SOAR) workflow initiatives.
- Help identify automation opportunities and define the required integrations, decision points, and escalation paths.
- Provide engineering teams with architectural guidance and review implementation outcomes.
- Ensure target capabilities progress beyond design into tested, documented, and supportable operations.
- Establish measurable criteria for evaluating implementation progress and security maturity.
Framework Alignment and Documentation
- Align architecture and roadmap activities with NIST SP 800-207 and CISA Zero Trust maturity models.
- Document current-state and target-state architectures, implementation dependencies, and key decisions.
- Support consistent interpretation of Zero Trust principles across workstreams.
- Review exceptions and recommend approaches that balance security objectives with operational needs.
- Maintain clear traceability between strategic objectives, engineering initiatives, and delivered capabilities.
Required Qualifications:
- Demonstrated experience designing and guiding enterprise Zero Trust architecture and implementation roadmaps.
- Ability to combine technical architecture with executive advisory, stakeholder engagement, and business-case development.
- Broad working knowledge of Microsoft G5 security and compliance capabilities.
- Experience guiding initiatives involving CASB, BYOD, SASE, and SOAR.
- Understanding of NIST SP 800-207 and CISA Zero Trust maturity models.
- Experience providing architectural oversight to cross-functional engineering teams.
- Ability to assess technical dependencies, evaluate tradeoffs, and sequence implementation activities.
- Strong written communication, presentation, and architecture documentation skills.
- Ability to work onsite in Washington, DC once per week.
- An Active Secret or Top-Secret Security Clearance.
Ideal Background:
The strongest candidates will have helped organizations move from Zero Trust strategy into implementation. They should be able to demonstrate how they secured stakeholder alignment, prioritized investments, guided engineers, and measured progress.
Experience should include Microsoft-centered environments and the ability to explain how identity, devices, applications, data, and connectivity work together within the broader security architecture.