Zero Trust Architect
Openkyber
Security Architect - Zero Trust Architecture Charlotte, NC Hybrid role (3 days onsite, 2 days remote) Pay: $65-$75 per hour 12-month contract with strong potential for extension or full-time conversion Objective: Lead the design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy. Define and operationalize a "never trust, always verify" model across identity, devices, networks, applications, and data. Drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least privilege and continuous verification across all enterprise resources.
Key Responsibilities:Architecture & Strategy Define and maintain the enterprise Zero Trust Architecture (ZTA) reference model, aligned to industry frameworks (NIST SP 800-207, CISA ZTMM) and business priorities. Establish target-state architectures and transition roadmaps for Zero Trust adoption across hybrid cloud, SaaS, and on-prem environments. Define policy-driven access models leveraging identity, device posture, behavior, and environmental risk signals. Align Zero Trust architecture with enterprise security strategy, cloud adoption, and digital transformation initiatives.
Architecture & Governance Lead end-to-end architecture reviews ensuring solutions align with Zero Trust principles, including least privilege, continuous verification, and explicit trust evaluation. Define and enforce architectural guardrails and secure patterns across identity, network, endpoint, application, and data layers. Establish policy decision and enforcement models (PDP/PEP) across enterprise control points (identity providers, gateways, endpoints, network controls). Provide governance and oversight for Zero Trust capabilities across business units, platforms, and shared services.
Cross-Domain Integration Design integration patterns that unify IAM, endpoint security, network controls, application access, and data protection into a cohesive Zero Trust model. Define how identity, device posture, and risk signals drive dynamic access decisions across APIs, applications, and infrastructure. Collaborate with domain architects (IAM, Network, Cloud, Endpoint, Data) to ensure consistent enforcement of Zero Trust controls and patterns. Enable secure service-to-service and user-to-resource access patterns across distributed architectures (microservices, APIs, SaaS).
Policy, Access & Control Enforcement Define enterprise access control strategies including adaptive authentication, conditional access, and fine-grained authorization. Establish policy models for user, service, and machine identity access, incorporating RBAC, ABAC, and policy-based access control. Define enforcement patterns across gateways, proxies, API layers, and endpoint controls to ensure consistent access decisions. Integrate continuous monitoring and feedback loops to adjust access decisions based on real-time risk and context.
Threat Modeling, Risk & Assurance Lead threat modeling initiatives focused on lateral movement, identity compromise, session hijacking, and trust boundary violations. Define security controls to mitigate Zero Trust-specific attack vectors (credential abuse, privilege escalation, bypass of enforcement points). Ensure Zero Trust architecture aligns with regulatory requirements and supports continuous risk reduction and measurable security outcomes. Establish metrics and maturity indicators for Zero Trust adoption and effectiveness across the enterprise.
Engineering Enablement & Adoption Drive adoption of Zero Trust patterns through reusable architectures, reference implementations, and engineering guidance. Partner with engineering, platform, and security teams to embed Zero Trust controls into SDLC, CI/CD, and platform engineering workflows. Evaluate and recommend technologies supporting Zero Trust capabilities (identity platforms, ZTNA, microsegmentation, API gateways, endpoint posture). Communicate architecture strategy, tradeoffs, and risk posture clearly to engineering, product, and executive stakeholders.
Core Security Domains:Identity & Access Management Authentication, federation, adaptive MFA, conditional access, service-to-service identity, least privilege, and identity governance.
Device & Endpoint Security Device posture, endpoint detection and response (EDR), mobile/device trust, health validation, and enforcement of device-based access conditions.
Network Security & Segmentation Microsegmentation, software-defined perimeters, ingress/egress controls, secure connectivity, and enforcement of network-level policy decisions.
Application & API Security Application access control, API authentication/authorization, secure service communication, token-based access, and policy enforcement at application layers.
Data Security Data classification, encryption, data minimization, access controls aligned to sensitivity, and protection of data across states (in transit, at rest, in use).
Visibility, Analytics & Automation Centralized telemetry, continuous monitoring, behavioral analytics, policy decision support, and automated response and enforcement.
GenAI Security Define secure GenAI patterns (LLM access controls, prompt/response handling, RAG security, agent/tooling boundaries). Threat model GenAI use cases (prompt injection, data leakage, model extraction/poisoning, unsafe output handling) and define mitigations/testing. Set GenAI data governance requirements (sensitive data use, retention, auditability) and vendor/model assurance expectations.
MINIMUM QUALIFICATIONS:7+ years of relevant experience Bachelor's Degree in Computer Science, Information Security, or related field of study or equivalent
PREFERRED QUALIFICATIONS:Master's in Computer Science, Information Security, or related field. 5+ years designing or implementing Zero Trust Architecture or similar enterprise security transformation initiatives Deep understanding of Zero Trust principles and frameworks (NIST SP 800-207, CISA Zero Trust Maturity Model) Strong experience in IAM, authentication/authorization, and policy-based access control models Experience with network security, segmentation, ZTNA, and modern connectivity architectures Experience with endpoint/device security and integration of device posture into access decisions Experience designing secure architectures across hybrid cloud (AWS/Azure), SaaS, and on-prem environments Proven experience integrating multiple security domains into cohesive architecture patterns Hands-on or architectural experience with technologies such as identity platforms, ZTNA solutions, API gateways, and microsegmentation tools Strong experience with threat modeling, architecture reviews, and security risk assessments Familiarity with regulatory frameworks (FFIEC, PCI DSS, SOX) and security frameworks (NIST, CIS) Demonstrated ability to influence cross-functional teams and drive enterprise adoption of security patterns Strong communication and executive presentation skills
For applications and inquiries, contact:View email address on us.fitly.work
- ...Cisco SD-Access and micro segmentation strategies to ensure zero unplanned downtime across manufacturing environments.... ...lifecycle management of OT network infrastructure Zero-Trust Network Design: Architect secure industrial networks incorporating IDMZ, macro-segmentation...SuggestedContract workLocal area
- ...DatamanUSA has an exciting opportunity for a Enterprise Architect to work with one of our direct clients in Olympia, WA. Job Title... ...data manipulation capabilities. ~ Experience applying Zero Trust principles, encryption standards, authentication/authorization...SuggestedPart timeRemote work
- ...Cisco SD-Access and micro segmentation strategies to ensure zero unplanned downtime across manufacturing environments.... ...lifecycle management of OT network infrastructure Zero-Trust Network Design: Architect secure industrial networks incorporating IDMZ, macro-segmentation...SuggestedHourly payContract workLocal area
- ...Job Description IT Security Architect Role Summary: Conduent is building an architecture function responsible for defining enterprise... ..., and tenant consolidation initiatives, ensuring hardened trust models, secure hybrid identity boundaries, and resilient authentication...SuggestedRemote workWork from homeFlexible hours
$90k - $105k
General information Press space or enter keys to toggle section visibility Job Title IAM Engineer City Remote Work Location Type Remote State Remote Employment Type Full-time (30+ hrs/week)/FULLTIME Description & Requirements ...SuggestedFull timeWork experience placementLocal areaRemote workFlexible hours$186k - $255k
...You will be part of a culture that values trust, accountability, and shared success where... ....Job SummaryJob SummaryAs a Principal Architect, you will serve as a trusted executive advisor... ...with network security, SASE/Zero Trust, cloud security, and identity management...Full timeRemote workVisa sponsorshipWork visa- ...organization. Work you'll do We are seeking a Senior Manager-level IAM Architect to partner with Senior IAM leadership team to define and drive... ..., SABSA, TOGAF, vendor-specific IAM certs).Experience with zero-trust identity models, identity governance, privileged access...Visa sponsorship
- ...Principal Platform Architect Location: Toronto, Ontario , Canada - Remote Long Term Contract Department: Cloud Infrastructure & Platform... ...& Identity Governance: Design robust identity management, Zero Trust frameworks, and end-to-end security architectures to secure...Long term contractRemote work
- ...Job Title : IAM Architect Location : Alpharetta, GA - Need to work from office 3 Days a week and need to come office for Face2Face Round... ...(RBAC, ABAC) Federation (SAML, OAuth, OIDC) Develop zero trust security models for identity 2. Implementation & Integration...Contract workWork at office3 days per week
- ...Claude/GPT), and automated triage workflows. Experience with Zero Trust architecture principles, NIST 800-207, and regulatory... ...dashboards, and correlation rules inside CrowdStrike Falcon. Architect automated SOAR playbooks in Torq, connecting CrowdStrike, identity...
- ...directory services (LDAP, AD, SAML, OAuth, OIDC) Strong scripting and automation skills (PowerShell, Python, etc.) Knowledge of Zero Trust architecture Experience with regulatory compliance frameworks and audit processes Excellent communication,...
- ...and secure network solutions supporting statewide operations. Collaborate with cybersecurity teams to develop and implement Zero Trust, network segmentation, and security architecture strategies. Develop hybrid cloud networking architectures supporting Azure...
- ...Job Title: (IAM) Saviynt Administrator/Architect Location: Spring, TX - Hybrid (3-Days a week Onsite) Duration: 12+ Months... ...other IAM/PAM platforms. Experience with microservices, Zero Trust, and modern identity patterns. Tools & Technologies:...Contract work3 days per week
- ...Cybersecurity IGA & SSO Architect :: Jersey City, NJ :: 5 Days Onsite :: W2 Role : Cybersecurity IGA & SSO Architect Location :- Jersey... ...on automation, compliance, identity lifecycle management, and Zero Trust principles. Provide architectural governance, solution reviews...Remote work
- ...Identity Governance. Design secure identity solutions following Zero Trust and least-privilege principles. Support modern identity... ...Conditional Access Passwordless Authentication Identity Federation Architect solutions for: Entra ID Azure AWS Microsoft 365 Okta PingFederate...
- ...We are seeking an experienced Security Architect Agentic Identity & Access Management to design... ...-to-tool, agent-to-agent), implement Zero Standing Privilege (ZSP) and dynamic policy... ...workload identity federation. Zero Trust & Policy Enforcement: Design context-aware...Work experience placement
- ...privacy, and security controls. Apply appropriate data-handling safeguards when using AI tools in regulated environments. Support Zero Trust security architecture initiatives based on NIST SP 800-207 principles. Develop, review, and update security policies, procedures,...Remote workRelocation
- ...Terraform, AWS CDK, or CloudFormation for identity infrastructure automation. ~ Strong understanding of least-privilege access, Zero Trust principles, secure session management, secrets management, and API security. ~ Strong troubleshooting, documentation,...Long term contractImmediate start
- ...Job Description: Security Architect Agentic Identity & Access Management Location-Remote Role Overview We are looking for a Security... ...and access-control models for autonomous agents. Establish Zero Trust principles for agent-to-agent, agent-to-application, and agent...Remote work
- ...capabilities for administrative and elevated-access scenarios Support Active Directory hardening, identity governance, least privilege, and Zero Trust principles Configure and maintain AD organizational units, GPOs, security groups, and delegated-administration models...Remote work
- ...IAM engineer/architect. Houston, Texas- HYBRID Identity as a Perimeter and Modernization Program Microsoft Entra ID, Windows Hello... ...security keys where appropriate. The project will further strengthen Zero Trust identity controls through Conditional Access optimization,...Temporary workFor contractors
- ...information about OpenKyber, visit us at . This is a contract to perm role. Position Title: Principal Cybersecurity Architect Identity, IAM & Zero Trust Location Information Remote Position Responsibilities: As the Principal Cybersecurity Architect specializing in Identity...Permanent employmentContract workRemote work
$65.28 per hour
...65.28 Security Clearance: Ability to obtain and maintain Public Trust (or higher if required) Overview This role is for a senior IAM... ...RBAC, privileged access, and access governance while supporting zero-trust and compliance requirements. They'll also handle complex...Contract workRemote work$112.9k - $257k
...Job Number: R0245812 Cybersecurity Architect The Opportunity: Everyone knows security needs to be "baked in" to system architecture... ...network architecture and design ~ Experience architecting Zero Trust solutions, roadmaps, and capabilities in alignment with...Full timeContract workPart timeWork at officeLocal areaRemote work$132.8k - $250.8k
...In this position... Ford Credit is seeking a Principal AI Architect to shape its enterprise AI strategy and turn it into secure, cloud... ...AI, Gemini, GKE, Cloud Run, BigQuery, and Pub/Sub. Embed Zero-Trust principles, identity and access controls, data protection,...Local areaImmediate startRemote workFlexible hours$145.6k - $209.3k
...is seeking an experienced Identity & Access Management (IAM) Architect to help define, design, and evolve the identity security architecture... ...of: SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, SCIM, Zero Trust principles, RBAC and ABAC models, Cloud identity architecture,...$190k
...platforms, at scale.What You'll DoLead AI Tech Architects - AI Platforms at BCG Platinion are:... ...while guiding broader solution design.Trusted partners. They work closely with senior client... ...their eligible family members.* That’s zero dollars in premiums taken from employee...Work at officeLocal area$190k
...platforms, at scale.What You'll DoLead AI Tech Architects at BCG Platinion are:Collaborative. They... ...presentation skills, ability to act as a trusted advisor and influence clients and BCG... ...their eligible family members.* That’s zero dollars in premiums taken from employee paychecks...Work at officeLocal area- ...Computacenter (UK) Ltd in the United States seeks a Security Chief Enterprise Architect to lead enterprise security strategy across data center and network environments, guiding architecture decisions and governance to enable business outcomes. You will collaborate...
- Job DescriptionJob Summary:The Wealth Management & Trust Domain Enterprise Architect serves as the strategic technology and architecture advisor for Pinnacle's Wealth Management and Trust business. This role is accountable for translating business strategy into technology...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Zero Trust Architect. Be the first to apply!



