Zero Trust Architect
Openkyber
Security Architect - Zero Trust Architecture Charlotte, NC Hybrid role (3 days onsite, 2 days remote) Pay: $65-$75 per hour 12-month contract with strong potential for extension or full-time conversion Objective: Lead the design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy. Define and operationalize a "never trust, always verify" model across identity, devices, networks, applications, and data. Drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least privilege and continuous verification across all enterprise resources.
Key Responsibilities:Architecture & Strategy Define and maintain the enterprise Zero Trust Architecture (ZTA) reference model, aligned to industry frameworks (NIST SP 800-207, CISA ZTMM) and business priorities. Establish target-state architectures and transition roadmaps for Zero Trust adoption across hybrid cloud, SaaS, and on-prem environments. Define policy-driven access models leveraging identity, device posture, behavior, and environmental risk signals. Align Zero Trust architecture with enterprise security strategy, cloud adoption, and digital transformation initiatives.
Architecture & Governance Lead end-to-end architecture reviews ensuring solutions align with Zero Trust principles, including least privilege, continuous verification, and explicit trust evaluation. Define and enforce architectural guardrails and secure patterns across identity, network, endpoint, application, and data layers. Establish policy decision and enforcement models (PDP/PEP) across enterprise control points (identity providers, gateways, endpoints, network controls). Provide governance and oversight for Zero Trust capabilities across business units, platforms, and shared services.
Cross-Domain Integration Design integration patterns that unify IAM, endpoint security, network controls, application access, and data protection into a cohesive Zero Trust model. Define how identity, device posture, and risk signals drive dynamic access decisions across APIs, applications, and infrastructure. Collaborate with domain architects (IAM, Network, Cloud, Endpoint, Data) to ensure consistent enforcement of Zero Trust controls and patterns. Enable secure service-to-service and user-to-resource access patterns across distributed architectures (microservices, APIs, SaaS).
Policy, Access & Control Enforcement Define enterprise access control strategies including adaptive authentication, conditional access, and fine-grained authorization. Establish policy models for user, service, and machine identity access, incorporating RBAC, ABAC, and policy-based access control. Define enforcement patterns across gateways, proxies, API layers, and endpoint controls to ensure consistent access decisions. Integrate continuous monitoring and feedback loops to adjust access decisions based on real-time risk and context.
Threat Modeling, Risk & Assurance Lead threat modeling initiatives focused on lateral movement, identity compromise, session hijacking, and trust boundary violations. Define security controls to mitigate Zero Trust-specific attack vectors (credential abuse, privilege escalation, bypass of enforcement points). Ensure Zero Trust architecture aligns with regulatory requirements and supports continuous risk reduction and measurable security outcomes. Establish metrics and maturity indicators for Zero Trust adoption and effectiveness across the enterprise.
Engineering Enablement & Adoption Drive adoption of Zero Trust patterns through reusable architectures, reference implementations, and engineering guidance. Partner with engineering, platform, and security teams to embed Zero Trust controls into SDLC, CI/CD, and platform engineering workflows. Evaluate and recommend technologies supporting Zero Trust capabilities (identity platforms, ZTNA, microsegmentation, API gateways, endpoint posture). Communicate architecture strategy, tradeoffs, and risk posture clearly to engineering, product, and executive stakeholders.
Core Security Domains:Identity & Access Management Authentication, federation, adaptive MFA, conditional access, service-to-service identity, least privilege, and identity governance.
Device & Endpoint Security Device posture, endpoint detection and response (EDR), mobile/device trust, health validation, and enforcement of device-based access conditions.
Network Security & Segmentation Microsegmentation, software-defined perimeters, ingress/egress controls, secure connectivity, and enforcement of network-level policy decisions.
Application & API Security Application access control, API authentication/authorization, secure service communication, token-based access, and policy enforcement at application layers.
Data Security Data classification, encryption, data minimization, access controls aligned to sensitivity, and protection of data across states (in transit, at rest, in use).
Visibility, Analytics & Automation Centralized telemetry, continuous monitoring, behavioral analytics, policy decision support, and automated response and enforcement.
GenAI Security Define secure GenAI patterns (LLM access controls, prompt/response handling, RAG security, agent/tooling boundaries). Threat model GenAI use cases (prompt injection, data leakage, model extraction/poisoning, unsafe output handling) and define mitigations/testing. Set GenAI data governance requirements (sensitive data use, retention, auditability) and vendor/model assurance expectations.
MINIMUM QUALIFICATIONS:7+ years of relevant experience Bachelor's Degree in Computer Science, Information Security, or related field of study or equivalent
PREFERRED QUALIFICATIONS:Master's in Computer Science, Information Security, or related field. 5+ years designing or implementing Zero Trust Architecture or similar enterprise security transformation initiatives Deep understanding of Zero Trust principles and frameworks (NIST SP 800-207, CISA Zero Trust Maturity Model) Strong experience in IAM, authentication/authorization, and policy-based access control models Experience with network security, segmentation, ZTNA, and modern connectivity architectures Experience with endpoint/device security and integration of device posture into access decisions Experience designing secure architectures across hybrid cloud (AWS/Azure), SaaS, and on-prem environments Proven experience integrating multiple security domains into cohesive architecture patterns Hands-on or architectural experience with technologies such as identity platforms, ZTNA solutions, API gateways, and microsegmentation tools Strong experience with threat modeling, architecture reviews, and security risk assessments Familiarity with regulatory frameworks (FFIEC, PCI DSS, SOX) and security frameworks (NIST, CIS) Demonstrated ability to influence cross-functional teams and drive enterprise adoption of security patterns Strong communication and executive presentation skills
For applications and inquiries, contact:View email address on us.fitly.work
$113.15k - $135.64k
...innovation meets mission-critical impact. As a Senior Enterprise Architect , you’ll lead the design and delivery of cutting-edge IT... ...(HCI). Advanced knowledge in IT security mechanics (e.g., Zero-trust, authentication protocols: MFA/hardware tokens, AD/ADFS, certificates...SuggestedFull timeWork at officeNight shift- ...The consultant must have 15+ of core Hands-on configuration experience in SAP SD. Must be hands-on SAP SD Functional Lead/Architect Level Experience leading blueprint/requirements gathering Must have participated in Multiple Full Life Cycle Implementations. Must have experience...Suggested
$81.2 - $86.2 per hour
We are looking for Business Intelligence Analyst - Remote / Telecommute for our client in San Francisco, CA Job Title: Business Intelligence Analyst - Remote / Telecommute Job Location: San Francisco, CA Job Type: Contract Job Overview: Pay ...SuggestedContract workTemporary workLocal areaRemote work- Job Title Senior Epic BI Developer / Epic Cogito Developer Location: Remote Contract: C2H or FTE Design, develop, and maintain Epic reporting and analytics solutions utilizing the Epic Cogito suite Develop complex SQL queries, stored procedures, ETL processes, and enterprise...SuggestedPermanent employmentContract workRemote work
$214.51k
...Job Description CDM Smith is seeking a Senior Enterprise Architect to join our Corporate Business Technology team. This role is responsible... .... Partner with delivery teams and stakeholders as a trusted architecture advisor, helping identify risks, dependencies, and...SuggestedWork experience placementH1bRemote work- ...Public Trust: None Requisition Type: Regular Your Impact Own your opportunity to support our nation's defense. Make an impact... ...Seize your opportunity to make a personal impact as a Cloud Architect supporting USPACOM J6 enterprise IT, mission partner...Work from homeFlexible hours
- ...Security Lab foundation Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup... ...optimization AWS Budgets: Cost alerts, anomaly detection AWS Trusted Advisor: Security and cost optimization recommendations...
- PRINCIPAL DUTIES: Has a beginning understanding about the contract, bid assumptions (how the contract was bid), plans, specifications, DBE's, subcontracts and purchase orders.Participates in planning and scheduling process and assists with establishing project schedule...Contract work
- Affinity Mastermind is seeking a Luxury Travel Advisor to create bespoke travel itineraries for clients eager for extraordinary experiences. You can work remotely from anywhere in the US or Latin America, crafting journeys that highlight hidden gems and five-star accommodations...Remote workFlexible hours
- Job Description Job Description PRINCIPAL DUTIES: Has a beginning understanding about the contract, bid assumptions (how the contract was bid), plans, specifications, DBE's, subcontracts and purchase orders.Participates in planning and scheduling process and assists...Contract workTemporary workWork experience placementLocal area
- Category Skill Description from the JD: Customer Priority Identity & Access Management Microsoft Entra ID Administer and harden Microsoft Entra ID: app registrations and Enterprise Application permissions, consent governance, service principals and managed identities...
- ABOUT YOUR ROLE The Plate Designer utilizes current graphic design technology and computer software packages to produce a variety of different products and/or media. The individual originates design, art and copy layouts, determines style, size and arrangement of type and...Full timeWork at officeWorldwide
$180k - $220k
Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including...Local areaImmediate startFlexible hoursShift work3 days per week- ...There are 2 locations: Austin, TX or Sunnyvale, CA (Hybrid) Job Summary We are seeking an experienced Data Platform Engineer to architect, build, and operate our cloud-based data lakehouse platform. The role is responsible for developing scalable data infrastructure...
- ...consuming existing ones Designs Terraform modules from ground up,not just using what''''''''''''''''''''''''''''''''s already there Architect and build ETL/ELT pipelines using Dataflow(Apache Beam)as the primary tool Dotoform for SOL based transformations on BigQuery...
- OpenKyber is hiring! OpenKyber is looking for CDN Platform Engineer , Dearborn, MI For quick apply, please reach out to OpenKyber at / The Content Delivery Network (CDN) Platform Engineer is responsible for the design, implementation, optimization, and operational reliability...Shift work
- Role: Platform Engineer Duration: 1 month Location: St. Louis, MO Role Overview Highly skilled AI Infrastructure Engineer to design, build, and operate scalable GPU-enabled Kubernetes platforms for AI/ML workloads. Must have skills: Kubernetes, ...
- Title: Cloud Security Engineer Location: Fort Worth, TX NEED local Resource Duration: 12+ months Contract Work mode: 3 days hybrid onsite (Tue/Wed/Thu) Interview: In person Interview and glider has to be taken and LinkedIn and resume should...Contract workLocal area
$19.5 per hour
Job Description Kitchen Designers at The Home Depot help customers turn their kitchen and bath dreams into reality. Kitchen Designers greet and engage customers, listen to their needs, and guide them through the design process—offering “good, better, best” options, ...Local area- Overview: If you're looking for the stability of a profitable, growing company with the entrepreneurial spirit of a startup, we're hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Software Engineer to join our Policy Onboarding...For contractorsLive inRemote work
$150k - $226k
Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including...Local areaImmediate startFlexible hoursShift work- Synergisticit Job OpportunitiesSince 2010 SynergisticIT has helped jobseekers get employed in the tech job market by providing candidates the requisite skills, experience and technical competence to outperform at interviews and at clients. The tech job market has been ...Full time
- Since 2010 SynergisticIT has helped Jobseekers get employed in the tech Job market by providing candidates the requisite skills, experience and technical competence to outperform at interviews and at clients. The Tech Job market has been affected by massive layoffs and...Full time
- OpenKyber client For interviews they will be asked to conduct a scripting challenge 7-8 years ServiceNow ITSM Senior Developer Technical Competency Experience as a ServiceNow ITSM Developer and Implementing Incident Management, Problem Management, Change Management, Knowledge...Flexible hours
- Only for W2 (Note: H1B Candidates Please) Position: Power Platform Developer Location: Columbus, OH Hybrid Duration: 6+ Months Client: OpenKyber / OpenKyber Job Summary We are seeking an experienced Power Platform Developer with strong hands-on experience in Microsoft ...H1b
- Job Title : ServiceNow Developer Location : Chicago, IL (flexible for Remote) Client: OpenKyber Rate: $80/hr on W2 Positions: 2 JD: Job Title: ServiceNow Developer ROLE_DESCRIPTION "Responsibilities: ServiceNow Configuration: Perform hands-on configuration and customization...Second jobRemote workFlexible hours
$99k - $128k
Job Description Job Description Mid- System Engineer (w/ active Secret)Location: Pearl Harbor, HI (Alternate Locations: Whidbey Island or Norfolk, VA) Clearance: Secret Type: Full-time, On-site Schedule: Wednesday - Sunday Salary Range: Pearl Harbor $99,000 - $128,...Full timeFlexible hours$125k - $145k
MINDBANK JOB OPENING Job Title: ServiceNow Support Role for Customer Service Management Job Type: W2 Contractor for OpenKyber only; this is not a Corp-to-Corp job; it is not a 1099 job- no third parties; only applicants that can work directly for OpenKyber. ...Contract workFor contractorsWork experience placementWork at officeRemote work- Interview mode - In person/Virtual - Virtual How many rounds of interview -2-3 rounds Job Details: Minimum years of experience needed in the required skills: 5 yrs experience Minimum over all work experience required: 5-7 yrs Domain - Cloud & DevOps Engineering Any certification...For contractorsWork experience placementSecond job
$113.33k - $188.9k
Our Deloitte AI & Engineering team to transform technology platforms, drive innovation, and help make a significant impact on our clients' success. You'll work alongside talented professionals reimagining and reengineering operations and processes that are critical to businesses...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Zero Trust Architect. Be the first to apply!


