ZERO TRUST (ZT) IDENTITY & CREDENTIAL MANAGEMENT SME
Zermount, Inc.
ZERO TRUST (ZT) IDENTITY & CREDENTIAL MAnagement SME POSITION OVERVIEW The Zero Trust Identity Management Technical SME exists to serve as the agency's primary technical advisor for the CISA ZTMM v2.0 identity pillar. This role directly advances TSA's compliance with OMB M-22-09 phishing-resistant MFA requirements and EO 14028 identity modernization mandates by providing senior-level ICAM advisory that translates federal policy into concrete identity architecture recommendations. The expected outcome is a continuously advancing identity pillar maturity posture, with phishing-resistant authentication enforced, privileged access controlled, and identity posture signals integrated into cross-pillar ZT enforcement decisions. This is a senior technical advisory role requiring hands-on ICAM implementation experience, not policy familiarity alone. DUTIES & RESPONSIBILITIES General duties
- Serve as the primary technical advisor for the CISA ZTMM v2.0 identity pillar across identity architecture, authentication, and access management domains.
- Continuously assess the agency's IAM posture against CISA ZTMM v2.0 identity pillar criteria, OMB M-22-09, and NIST SP 800-63. Proactively surface emerging identity risk indicators and deliver real-time advisory recommendations.
- Provide technical advisory guidance on phishing-resistant MFA strategies, PIV/CAC enforcement, FIDO2 deployment, and enterprise IdP integration - recommending solutions and implementation pathways for agency decision-making.
- Evaluate enterprise IAM/IdP platforms (e.g., Entra ID, Okta, Ping Identity) and provide configuration and enhancement recommendations aligned to ZT principles for agency adoption.
- Advise PAM strategies, RBAC/ABAC models, and least-privilege enforcement aligned to NIST SP 800-207; develop recommended solutions for agency review.
- Provide advisory support for the development and maturation of identity-related entries in the Common Control Catalog (CCC), ensuring traceability to NIST SP 800-53 rev. 5 control families.
- Develop recommended identity pillar inputs to the ZT roadmap, IG FISMA maturity reporting, and enterprise performance reporting for agency review and approval.
- Collaborate with device, network, and application SMEs to ensure identity-based enforcement integrates coherently across all ZTMM pillars.
- Review identity-related policy documents and SOPs; identify gaps relative to ZT mandates and develop recommended updates for agency concurrence.
- Support all identity-related ZT data calls, audits, and compliance reporting by providing advisory analysis and recommended responses.
- Prepare and present technical findings, maturity assessments, and advisory recommendations to senior leadership and the CISO.
- Leverage AI-assisted analysis tools, automation platforms, and prompt engineering techniques to enhance advisory productivity, accelerate gap analysis and documentation tasks, and enable focus on higher-value technical advisory work; apply all AI capabilities in accordance with agency acceptable use policies and Zermount's ethical AI use guidelines.
- Expert-level mastery of ICAM architecture and authentication engineering including enterprise IAM/PAM/IdP design, phishing-resistant MFA implementation (PIV/CAC enforcement, FIDO2) deployment, and federated identity frameworks demonstrated through operational implementation experience, not framework study.
- Authoritative knowledge of NIST SP 800-63, NIST SP 800-207 identity tenets, CISA ZTMM v2.0 identity pillar criteria, OMB M-22-09, and federal ICAM policy requirements; ability to independently interpret and apply evolving guidance.
- Expert-level proficiency in enterprise IAM platforms including Entra ID (Azure AD), Okta, or equivalent architecture and configuration design depth, not administrative use.
- Expert-level knowledge of RBAC, ABAC, and PAM architectures to support Just Enough, Just In Time (JEJIT) access principles in federal environments; demonstrated ability to advise on least-privilege policy design and privileged account governance.
- Independent decision-making authority on identity pillar advisory scope, maturity assessment methodology, and recommended advancement approach.
- Problem-solving at the intersection of identity enforcement and cross-pillar ZT integration. Able to identify how identity posture deficiencies create downstream risk in devices, networks, data, and application pillar enforcement.
- Strong foundational knowledge of directory services (Active Directory, LDAP, Entra ID), cloud identity platforms, and enterprise authentication infrastructure at an architecture or engineering level.
- Hands-on experience with cloud platforms, particularly Azure/Entra ID, AWS IAM, or GCP identity, including conditional access policy design, cross-tenant federation, and hybrid identity architecture.
- Working knowledge of core identity and network access protocols including OAUTH 2.0, SAML, OIDC, RADIUS, and TACACS+, and their role in enforcing ZT identity-based access decisions.
- Foundational understanding of network architecture, database access controls, and systems administration concepts sufficient to assess identity enforcement implications across the enterprise stack.
- Supports identity pillar advisory by enabling technically credible engagement with agency engineers, platform administrators, and cross-pillar SMEs on authentication architecture, access control design, and protocol-level enforcement.
- Interact directly with other ZT SMEs to support access requirements across pillars.
- A minimum of 10 years of experience supporting identity management, governance, or security, with demonstrated Zero Trust scope.
- Hands-on experience implementing phishing-resistant MFA solutions including PIV/CAC enforcement and FIDO2/WEBAUTHN deployment in a federal or large enterprise environment.
- Hands-on experience with federal IAM platforms including Entra ID (Azure AD) or Okta; must extend beyond administration to include ZT-aligned architecture and configuration design.
- Expert knowledge of NIST SP 800-63, NIST SP 800-207, CISA ZTMM v2.0 identity pillar criteria, and OMB M-22-09.
- Experience with RBAC, ABAC, and PAM architectures in a federal environment.
- Demonstrated experience developing and implementing Zero Trust Identity solutions operationally, to include JEJIT access principles.
- Experience integrating identity posture signals into ZT access enforcement policy decisions.
- Experience supporting ZT-related IG FISMA metrics reporting pertaining to identity and access management.
- Strong written and oral communication skills; ability to translate complex technical findings into CISO-ready recommendations.
- Demonstrated familiarity with ai-assisted analysis tools or prompt engineering; ability to apply AI capabilities ethically to accelerate advisory work and surface higher-value technical insights.
- Five years of IT cybersecurity experience, including direct support to the U.S. Government. This experience can be concurrent with the minimum 10 years of identity management, governance, or security
- Prior direct involvement in implementing access and authorization automations.
- Prior direct involvement in a ZT Identity Pillar implementation or enterprise ZT deployment in a technical design or advisory capacity.
- Experience architecting or evaluating ZT-aligned IAM solutions including enterprise IdP integration, federation, and phishing-resistant authentication enforcement.
- Cloud vendor IAM certification (e.g., Microsoft certified: Identity and Access Administrator SC-300, AWS security specialty).
- Experience with ICAM roadmap implementation or federal ICAM architecture design.
- Technical: CISA ZTMM v2.0 identity pillar, NIST SP 800-63, NIST SP 800-207, OMB M-22-09, Entra ID/Azure AD, Okta, PIV/CAC, FIDO2, PAM, RBAC/ABAC, OAUTH 2.0, SAML, OIDC, NIST SP 800-53 control families, AI-assisted analysis.
- Leadership: Technical advisory leadership for Identity Pillar; cross-pillar SME collaboration and integration; CISO-facing technical briefing and recommendations; advisory engagement with federal engineers and platform administrators.
- Behavioral: Proactive continuous assessment of posture rather than point-in-time reporting; rigorous technical precision in architecture recommendations; continuous learning orientation toward evolving federal identity standards and platform capabilities.
- Minimum of a Bachelor of Science (or higher) in Information Technology, Computer Science, Cybersecurity, or related field.
- Required: Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) or equivalent certification.
- Strongly preferred: Certified Identity and Access Manager (CIAM) or Microsoft certified: Identity and Access Administrator (SC-300).
- Strongly preferred: cloud vendor IAM certification (e.g., Microsoft Azure Security Engineer Associate AZ-500, AWS security specialty).
- Active Secret clearance is required.
- Hybrid - primarily remote. Occasional onsite work required at the client location in Springfield, VA and Zermount HQ in Arlington, VA.
- Business hours: 8:00 AM EST - 4:30 PM EST
- Core hours: 9:00 AM EST - 3:00 PM EST
- Reports to: ZT SME Team Lead
- Direct reports: None
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the ZERO TRUST (ZT) IDENTITY & CREDENTIAL MANAGEMENT SME in Arlington, VA vacancy
- ZERO TRUST (ZT) ENDPOINT & CONNECTED SYSTEMS SME POSITION OVERVIEW The Zero Trust Systems Engineering Technical SME... ...level advisory on device posture management, CDM integration, EDR compliance,... ...and approval. Collaborate with Identity, Network, Data, and Applications...SuggestedCasual workRemote work
- ZERO TRUST (ZT) PROCESS RE-ENGINEERING SME POSITION OVERVIEW The Zero Trust Process Re-Engineering SME exists to... ...all five CISA ZTMM v2.0 pillars: Identity, Devices, Networks, Applications &... ...Familiarity with enterprise IT service management frameworks (e.g., ITIL) and their...SuggestedCasual workRemote work
- Identity, Credential and Access Management Systems Engineer Be among the first 25 applicants (4 weeks ago) Tetrad Digital Integrity (TDI) is a leading... ...Experience with federation protocols (SAML, OAUTH, OpenID) and zero trust principles. Experience with the ForgeRock platform....SuggestedFull timeWork at officeNight shift
- Guidehouse is seeking an experienced Cyber Engineer - Identity Management Lead in Washington, DC. This role involves designing, assessing,... ...and implementing identity management solutions integrating Zero Trust principles for federal clients. The ideal candidate will have...Suggested
$86.9k - $198k
...Overview We are seeking an ICAM Engineer to support enterprise identity and access management initiatives within a secure, large‑scale environment.... ...focuses on strengthening identity security, supporting zero trust architectures, and ensuring proper access controls across...SuggestedImmediate start- ...Everforth ECS is seeking a Product Manager SME to work in the National... ...the authoritative voice on Zero Trust compliance, Risk Management... ...one of the following active credentials: CompTIA Security+ CE, ISC²... ...Access Management, Identity and Access Management federation...Contract work
$150k - $170k
Job Openings >> 1802 - Identity & Access Management Engineer - Onsite - Active Secret Required... ...Information System Identity Credential and Access Management (ICAM) Provide... ...systems Subject Matter Expert (SME) in Cloud Key vaulting, Zero Trust Architecture, and modern...Temporary workLocal area$99k - $225k
...Job Number: R0238654 Zero Trust Assessment Engineer, Senior The Opportunity:... ...Automation and Orchestration (A&O), identity and access management, conditional-based access, attribute-... ...organizations ~ Experience architecting ZT solutions, roadmaps, and capabilities...Full timeContract workPart timeWork at officeLocal areaRemote work- ...looking for an Entra ID Engineer to design, implement, and maintain identity solutions within Microsoft Entra ID. The position is hybrid,... ...with Azure cloud solutions and a deep understanding of Zero Trust security principles. Responsibilities include automation with...
- ..., Virginia is seeking a highly experienced SME Systems Engineer to support critical Identity, Credential, and Access Management (ICAM) activities for the U.S. Coast Guard... ...background in federated identity concepts, Zero Trust principles, and hold DoD certifications. A...
- A cybersecurity firm is seeking an Identity Provider Engineer in Virginia, specializing in identity and access management. Responsibilities include supporting IAM projects and managing user privileges. The ideal candidate will have experience with IAM tools and possess...
- As an Identity and Access Management(IAM) specialist, you have the skills and experience to keep hackers... ...role in the world of IAM and zero trust. You’ll interface with stakeholders... ...appropriate user privileges and manage credentials for accessing our clients’ most valuable...Temporary workRelocation package
- LaunchCode is seeking an ICAM Engineer to support enterprise identity and access management initiatives within a large-scale cybersecurity... ...This hybrid role focuses on enhancing identity security and zero-trust architectures. Applicants must have at least 3 years of experience...
$86.8k - $198k
A leading consulting firm is seeking a Ping Identity Engineer to shape the future of Identity and Access Management (IAM) and Zero Trust. In this role, you will analyze identity lifecycles, design and support IAM solutions, and ensure compliance with security protocols...Remote job- ...join our talented Team. Job Title: Senior Identity, Credential, and Access Management (ICAM) Security Engineer Location: Washington, DC... ...ICAM architectures for the federal government that meet zero-trust mandates. Experience planning, designing, and...Work at office
- ...is seeking a Network Operations Lead — Zero Trust to join the team supporting the U.S. International... ...IT environment, providing service management, network operations, IT asset... ...incident bridge, design segmentation and identity-based access policies, and lead a team...Temporary workLocal areaRemote workWork from homeNight shift
- Overview Zero Trust Engineer (Senior) - Falls Church, Virginia • Full-time IMPORTANT NOTICE... ...Zero Trust architectures including identity management, micro-segmentation, and continuous verification... ...of Zero Trust principles, DoD ZT Reference Architecture, IAM/PAM, network...Full timeContract workWork at officeRemote work
- ...Identity Access Management Integration Architect AEEC is currently seeking an Identity Access Management Integration Architect to support our... ...prior to beginning work and must be able to obtain a public trust clearance. Required Qualifications: Experienced in...Full timeContract workTemporary work
$77 - $87 per hour
...Client is seeking an ICAM Operations - IAM Manager to work in our Washington, DC office to oversee and guide the Identity Governance & Administration (IGA) program ,... ...compliance frameworks (FISMA, NIST 800-53, Zero Trust). ~ Familiarity with Oracle Identity Manager...Full timeTemporary workInterim roleWork at office$86.8k - $198k
Job Number: R0237452 Ping Identity Engineer The Opportunity You know... .... As an Identity and Access Management (IAM) specialist, you have... ...in the world of IAM and Zero Trust. You'll interface with stakeholders... ...user privileges and manage credentials for accessing our client's...Full timeContract workPart timeWork at officeLocal areaRemote work- RedMatter Solutions is searching for a PAM Engineer to lead the implementation and management of enterprise Privileged Access Management solutions in support of federal cybersecurity and Zero Trust initiatives. This hybrid position requires expertise in administering PAM...
$86.8k - $198k
Identity Provider Engineer The Opportunity: You know that the user... .... As an Identity and Access Management (IAM) specialist, you have... ...identity and access management and zero trust. In this role, you’ll... ...user privileges and manage credentials for accessing our clients’ most...Full timeContract workPart timeLocal areaRemote work- Overview We are seeking an an Identity and Access Management Systems Engineer to be responsible for the upkeep, configuration, and reliable operation... ...Manager or other IDM platform, Federation protocols (SAML, OAUTH, OpenID) and zero trust principles. #J-18808-Ljbffr NSSFull timeWork at officeNight shift
$131.3k - $237.35k
...informed decisions using trusted data at scale. Leidos... ...seeking an experienced SME Cybersecurity Systems... ...Engineering Plan (SEP) for managing all systems... ...implementing enterprise-scale Zero Trust Architecture.... ...sexual orientation, gender identity or expression, veteran...Local areaImmediate start$154.05k - $278.48k
...informed decisions using trusted data at scale. Leidos... ...seeking an experienced SME Solution Architect Lead... ...pipelines, release management processes, and enterprise... ...00-53, RMF, STIGs, and Zero Trust architecture principles... ...orientation, gender identity or expression, veteran...Local areaImmediate start$118.45k - $260.59k
...something bigger - helping to simplify health care one person, one family and one community at a time. Position Summary The Senior Manager - Zero Trust is a senior management position charged with directing and overseeing the strategy, engineering, operations, and execution...Hourly payFull timeTemporary workWork experience placementLocal areaRemote work$131.3k - $237.35k
...informed decisions using trusted data at scale. Leidos... ...seeking an experienced SME Systems Engineer Lead to... ...planning. Identify and manage human-systems... ...Experience implementing Zero Trust architecture patterns... ...sexual orientation, gender identity or expression, veteran...- Overview We are seeking an experienced Project Manager to lead a large-scale Identity and Access Management (IAM) modernization program for a civilian... ...legacy identity infrastructure to modern cloud and Zero Trust platforms. The Project Manager will serve as the primary...Contract workFor subcontractor
$162.8k - $303k
Booz Allen Hamilton seeks a Zero Trust Solutions Architect, Director to lead strategic design and implementation of security frameworks... ...0 years in cybersecurity and experience in cloud security, identity management, and network architecture. This role includes overseeing...Remote work- Zermount, Inc. is seeking a Zero Trust (ZT) Process Re-Engineering SME in Arlington, VA to provide senior-level advisory expertise for IT and cybersecurity processes. The role focuses on compliance with federal mandates and requires at least 10 years of relevant experience...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ZERO TRUST (ZT) IDENTITY & CREDENTIAL MANAGEMENT SME. Be the first to apply!
Related searches
- health information management work from home Arlington, VA
- lecturer management Arlington, VA
- management services technician Arlington, VA
- senior director product management Arlington, VA
- asset management Arlington, VA
- product management intern Arlington, VA
- management information systems director Arlington, VA
- events management graduate Arlington, VA
- change management project manager Arlington, VA
- management development specialist Arlington, VA

