Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

ZERO TRUST (ZT) NETWORK ARCHITECTURE SME

Zermount, Inc.

ZERO TRUST (ZT) NETWORK ARCHITECTURE SME

POSITION OVERVIEW

The Zero Trust Network Architecture Technical SME exists to serve as the agency's primary technical advisor for the CISA ZTMM v2.0 Networks pillar. This role advances TSA's network segmentation posture, TIC 3.0 compliance, and ZTNA adoption by providing senior-level advisory on network architecture design, micro‑segmentation strategy, and software‑defined networking (SDN) capabilities. The expected outcome is a continuously advancing Networks pillar maturity posture with network macro‑ and micro‑segmentation maturing, ZTNA architecture advisory driving enforcement design, and lateral movement risk proactively identified and addressed. This is a senior technical advisory role requiring hands‑on network architecture and ZTNA design experience in a federal environment.

DUTIES & RESPONSIBILITIES

General Duties Serve as the primary technical advisor for the CISA ZTMM v2.0 Networks pillar across network security architecture, segmentation, and ZTNA domains. Continuously assess the agency's network architecture against CISA ZTMM v2.0 Networks pillar criteria and NIST SP 800‑207; proactively identify emerging network risk indicators, including lateral movement exposure, traffic encryption and visibility deficiencies, and TIC 3.0 compliance drift, and deliver real‑time advisory recommendations. Provide technical advisory guidance on ZTNA architecture design options, micro‑segmentation strategies, and SDN approaches, recommending solutions and implementation pathways for agency decision‑making. Evaluate ZTNA platform capabilities (e.g., Zscaler, Palo Alto Prisma) and develop configuration and deployment recommendations aligned to federal ZT requirements for agency adoption. Advise TIC 3.0 compliance strategies, cloud network access patterns, and secure remote access approaches in a hybrid federal environment; develop recommended solutions for agency review. Assess network access control mechanisms, lateral movement risk, and east‑west traffic enforcement against ZT principles; develop findings and recommended remediation approaches for agency concurrence. Provide advisory support for the development and maturation of Networks pillar entries in the Common Control Catalog (CCC), ensuring traceability to NIST SP 800‑53 Rev. 5 control families. Develop recommended Networks pillar inputs to the ZT Roadmap, IG FISMA maturity reporting, and enterprise performance reporting for agency review and approval. Collaborate with Identity, Device, Data, and Applications SMEs to ensure network enforcement approaches integrate coherently across all ZTMM pillars. Review network‑related policy documents and technical standards; identify gaps relative to ZT mandates and develop recommended updates for agency concurrence. Support all network‑related ZT data calls, audits, and compliance reporting by providing advisory analysis and recommended responses. Prepare and present network architecture findings, maturity assessments, and advisory recommendations to senior leadership and the CISO. Leverage AI‑assisted analysis tools, automation platforms, and prompt engineering techniques to enhance advisory productivity, accelerate gap analysis and documentation tasks, and enable focus on higher‑value technical advisory work; apply all AI capabilities in accordance with agency acceptable use policies and Zermount's ethical AI use guidelines.

SUBJECT MATTER EXPERTISE

SME Area #1 – Network Security Architecture, ZTNA & Micro‑Segmentation Advisory Expert‑level mastery of network security architecture including ZTNA design, micro‑segmentation strategy, and software‑defined networking demonstrated through production deployment or senior advisory engagement. Authoritative knowledge of CISA ZTMM v2.0 Networks pillar criteria, NIST SP 800‑207 network access tenets, TIC 3.0 use cases and security capabilities, and NIST SP 800‑53 Rev. 5 control families. Expert‑level proficiency with ZTNA platforms such as Zscaler and/or Palo Alto Prisma at architecture design, configuration, and deployment depth for federal environments. Expert‑level capability in network segmentation design including macro‑segmentation, micro‑segmentation, lateral movement risk assessment, and east‑west traffic enforcement strategy. Independent decision‑making authority on Networks pillar advisory scope, architecture assessment methodology, and recommended ZTNA and segmentation approach. Bring solutions for concurrence. Problem‑solving at the intersection of network enforcement and cross‑pillar ZT integration. Able to identify how network segmentation deficiencies create risk in Identity enforcement decisions and Applications access control. SME Area #2 – Enterprise Network Infrastructure & Cloud Networking Foundations Deep foundational expertise in enterprise network architecture including routing and switching (BGP, OSPF, VLAN design), firewall policy management, VPN technologies, and load balancing at architecture or senior engineering level. Hands‑on experience with enterprise network infrastructure platforms (Cisco, Palo Alto Networks, Fortinet, or equivalent) including firewall rule design, segmentation architecture, and traffic inspection configuration. Strong working knowledge of cloud networking constructs, including VPC/VNet design, cloud‑native security groups, transit gateways, and cloud‑based SD‑WAN, Infrastructure‑as‑Code (IaC), and hybrid connectivity patterns relevant to ZT network enforcement. Foundational understanding of database network access patterns, systems administration network dependencies, and application‑layer traffic flows as they relate to segmentation design and ZT enforcement policy. Supports Network pillar advisory by enabling technically credible engagement with agency network engineers, firewall administrators, and cloud infrastructure teams. Interacts directly with other Zero Trust SMEs.

QUALIFICATIONS

Minimum Requirements A minimum of 10 years of experience in network security architecture, ZTNA design, or enterprise network engineering with demonstrated Zero Trust scope. Demonstrated hands‑on experience designing or implementing ZTNA architectures in federal or large enterprise environments, reflecting operational design and deployment, not vendor evaluation or documentation. Hands‑on experience with ZTNA platforms (e.g., Zscaler, Palo Alto Prisma, Cisco) including architecture design, configuration, and deployment. Expert knowledge of NIST SP 800‑207, CISA ZTMM v2.0 Networks pillar criteria, and TIC 3.0 requirements. Experience with micro‑segmentation design, SDN, and lateral movement risk assessment in a ZT context. Ability to assess network security controls against NIST SP 800‑53 Rev. 5 control families. Demonstrated experience designing and implementing Zero Trust network architectures operationally, not limited to assessments or gap analyses. Experience supporting ZT‑related IG FISMA metrics reporting pertaining to network security and TIC 3.0. Strong written and oral communication skills; ability to translate complex network architecture concepts into CISO‑ready findings. Demonstrated familiarity with AI‑assisted analysis tools or prompt engineering; ability to apply AI capabilities ethically to accelerate advisory work and surface higher‑value technical insights. Preferred Qualifications Five years of IT cybersecurity experience, including direct support to the U.S. Government. This experience can be concurrent with the minimum 10 years of network architecture experience. Prior direct involvement in a ZT Networks pillar implementation or enterprise ZTNA deployment in a technical architecture or advisory capacity. ZTNA vendor certification: Zscaler Zero Trust Certified Associate (ZTCA) or Palo Alto Networks PCNSE. Experience with encrypted traffic management (SSL/TLS inspection) and east‑west traffic visibility in a ZT network environment. Experience with cloud‑native networking security (Azure Virtual WAN, AWS Transit Gateway, GCP Cloud Armor, or Infrastructure‑as‑Code) in a federal hybrid environment. Competencies Technical: CISA ZTMM v2.0 Networks pillar, NIST SP 800‑207, TIC 3.0, Zscaler, Palo Alto Prisma, Cisco, ZTNA architecture, micro‑segmentation, BGP/OSPF/VLAN, VPN, firewall policy design, cloud networking (VPC/VNet), NIST SP 800‑53, AI‑assisted analysis. Leadership: Technical advisory leadership for Networks pillar; cross‑pillar SME coordination with Identity, Devices, and Applications teams; CISO‑facing network architecture briefing; engagement with agency network engineers and cloud infrastructure teams. Behavioral: Proactive continuous network posture monitoring; precision in architecture assessment and segmentation advisory; continuous learning toward evolving ZTNA platform capabilities, TIC 3.0 updates, and federal network security guidance. Education & Certifications Minimum of a Bachelor of Science (or higher) in Information Technology, Computer Science, Network Engineering, Cybersecurity, or related field. Required: Certified Information Systems Security Professional (CISSP) or Cisco Certified Network Professional Security (CCNP Security), or equivalent certification. Strongly preferred: Certified Information Security Manager (CISM) or equivalent senior security management certification. Strongly preferred: ZTNA vendor certification. Zscaler ZTCA, Palo Alto Networks PCNSE, or equivalent. Clearance Level Active Secret Clearance required.

WORK LOCATION

Hybrid – Primarily Remote. Occasional onsite work required at the client location in Springfield, VA and Zermount HQ in Arlington, VA.

HOURS OF OPERATION

Business Hours: 8:00 AM EST – 4:30 PM EST Core Hours: 9:00 AM EST – 3:00 PM EST

REPORTING STRUCTURE

Reports To: ZT SME Team Leader Direct Reports: None #J-18808-Ljbffr Zermount, Inc.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the ZERO TRUST (ZT) NETWORK ARCHITECTURE SME in Arlington, VA vacancy
  •  ...ZERO TRUST (ZT) NETWORK ARCHITECTURE SME POSITION OVERVIEW The Zero Trust Network Architecture Technical SME exists to serve as the agency's primary technical advisor for the CISA ZTMM v2.0 Networks pillar. This role advances TSA's network segmentation posture,... 
    Network
    Casual work
    Remote work

    Zermount, Inc.

    Arlington, VA
    1 day ago
  • Zermount, Inc. is seeking a Zero Trust Network Architecture SME in Arlington, VA. This senior advisory role focuses on enhancing the agency's network architecture and ZTNA implementation, requiring extensive experience in network security and compliance with federal standards... 
    Network
    Remote work

    Zermount, Inc.

    Arlington, VA
    4 days ago
  •  ...ZERO TRUST (ZT) IDENTITY & CREDENTIAL MAnagement SME POSITION OVERVIEW The Zero Trust Identity Management Technical...  ...policy into concrete identity architecture recommendations. The expected...  .... Collaborate with device, network, and application SMEs to ensure... 
    Network
    Casual work
    Remote work

    Zermount, Inc.

    Arlington, VA
    1 day ago
  • DecisionPoint Corporation is seeking a Zero Trust Security Engineer - SME to lead the implementation of Zero Trust Architecture (ZTA) across GPO enterprise systems. This role involves deploying Microsoft Defender for Endpoint, ensuring cybersecurity compliance, and optimizing... 
    Suggested
    Remote job

    DecisionPoint Corporation

    Washington DC
    4 days ago
  •  ...Zero Trust Architecture Senior Technical Expert (STE) Pueo is known for bringing the best talent and...  ...Provide expertise to the Government ZT Program Manager on Zero Trust adoption...  ...technical assessments across identity, device, network, application, and data layers to... 
    Network

    Pueo Business Solutions LLC

    McLean, VA
    4 days ago
  • $116.9k - $243.1k

    Job Description The Zero Trust Architect is responsible for ensuring the security and integrity...  ...measures to protect data, systems, and networks from threats. This role leads the design and deployment of Zero Trust Architecture (ZTA), ensuring verification of every access... 
    Network
    Work experience placement
    Local area

    Accenture Federal Services

    Arlington, VA
    4 days ago
  • A leading network solutions company in Washington is seeking a senior network designer to develop secure network architectures and enhance automation practices. The ideal candidate must have...  ...hardware, ensuring compliance with zero-trust principles, and supporting secure... 
    Network

    RPMGlobal

    Washington DC
    2 days ago
  • $116.9k - $243.1k

     ...government forward! Job Description: The Zero Trust Architect is responsible for ensuring the...  ...measures to protect data, systems, and networks from threats. This role leads the design and deployment of Zero Trust Architecture (ZTA), ensuring verification of every... 
    Network
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    20 hours ago
  • $99k - $225k

     ...Job Number: R0238654 Zero Trust Assessment Engineer, Senior The Opportunity...  ...approach to security architecture design, providing...  ...~ Experience architecting ZT solutions, roadmaps, and capabilities...  ...ecosystem ~ Knowledge of network technologies, including SD-WAN... 
    Network
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $180k - $200k

     ...Management is seeking a mission-driven Senior Zero Trust Cloud Security Architect to lead the...  ...of Zero Trust and cloud-security architectures across Department of War (DOW) classified...  ...cloud security controls, IAM, encryption, network segmentation, and secure DevSecOps... 
    Network
    For contractors
    Remote work

    Akima

    Alexandria, VA
    2 days ago
  •  ...Opportunity Overview  Northramp is seeking a Network Operations Lead — Zero Trust to join the team supporting the U.S. International Development...  ...— and driving the agency's transition to a Zero Trust architecture. The role pairs senior NOC leadership with the architectural... 
    Network
    Temporary work
    Local area
    Remote work
    Work from home
    Night shift

    Northramp

    Washington DC
    2 days ago
  • $162.8k - $303k

    Job Number: R0239408 Zero Trust Solutions Architect, Director Lead the strategic design,...  ...such as identity and access management, network segmentation, and advanced threat detection...  ...innovative approaches to Zero Trust architecture. Oversee vendor selection, contract... 
    Network
    Contract work
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Washington DC
    4 days ago
  • $103.2k - $172k

     ...communicate application and data architecture standards, policies, and...  ...security, operating at the edge, zero trust, enterprise/managed services,...  ...and 15 years' experience for SME-level ~ Active Security...  ...services for compute, store, network, security, and automation) ~... 
    Network
    Contract work
    Work experience placement
    H1b

    SMX Corporation

    Washington DC
    7 days ago
  •  ...Cybersecurity Architect & Engineer SME who can create government...  ...technical expertise, architectural recommendations, and engineering...  ...pipelines, and operationalizing zero trust and cATO capabilities. You...  ...years (preferred 10 years) of network, systems, applications... 
    Network
    Remote work

    Zermount, Inc.

    Arlington, VA
    4 days ago
  •  ...Senior Zero Trust Compliance Officer Everforth ECS is seeking a Senior Zero Trust Compliance...  ...with the DoW Zero Trust Reference Architecture, DoW Zero Trust Strategy, and NIST...  ...operating on unclassified and classified networks. Translates Zero Trust technical implementations... 
    Network
    Contract work

    ECS

    Fairfax, VA
    3 hours ago
  • $150k - $190k

     ...Zero Trust Engineer (Senior) Falls Church, Virginia • Full-time...  ...implementation of Zero Trust security architectures aligned with DoD Zero Trust...  ...-less security. Design network micro-segmentation strategies...  ...of Zero Trust principles, DoD ZT Reference Architecture, IAM/... 
    Network
    Full time
    Contract work
    Work at office
    Remote work

    ZTI Solutions, LLC

    Falls Church, VA
    more than 2 months ago
  • $131.3k - $237.35k

     ...currently has an opening for a Cloud SME/Architect at Beale Air Force...  .../ Architect will lead the architecture, modernization, integration,...  ..., cloud landing zones, VPC/network architecture, IAM, storage,...  ...Demonstrated ability to serve as a trusted technical advisor to senior... 
    Network
    Relocation package

    Via Logic LLC

    Alexandria, VA
    3 days ago
  •  ...Virginia. This role involves providing advanced cybersecurity support for mission systems, implementing Zero Trust principles, and overseeing operations for classified networks. Candidates must have extensive experience in information assurance, a relevant degree, and an... 
    Network
    Remote work

    Aretum

    McLean, VA
    1 day ago
  •  ...management initiatives within a large-scale cybersecurity environment. This hybrid role focuses on enhancing identity security and zero-trust architectures. Applicants must have at least 3 years of experience in ICAM or IAM programs, strong understanding of directory services,... 

    LaunchCode

    Washington DC
    3 days ago
  • $146k - $234k

     ...lead for Kubernetes platform architecture, automation, infrastructure...  ...cluster foundations including networking, storage integrations,...  ...Kubernetes Subject Matter Expert (SME) providing architectural...  ...stacks Familiarity with Zero Trust Architecture and federal cloud... 
    Network
    Contract work
    Shift work

    Peraton

    Washington DC
    1 day ago
  • $180k - $200k

     ...hiring for a Cybersecurity Subject Matter Expert (SME) to support the design and implementation of a Zero Trust Architecture for Headquarters Air Force/A2 Intelligence...  ...deep subject matter expertise in areas such as network security, cloud security, identity and access... 
    Network
    Currently hiring

    Govcio LLC

    Washington DC
    3 days ago
  •  ...We are searching for a Sr. SME to support an AWS GovCloud platform in the Cloud Architecture and Administration team. The candidate...  ...policies. Cross-Account Networking - Transit Gateway, VPC peering...  ...automated remediation. Zero Trust Architecture - Implementing... 
    Network
    For contractors

    Ampcus

    Washington DC
    3 days ago
  • Sev1Tech LLC is seeking a Trusted Internet Connections (TIC) System Engineer in Arlington, Virginia. This role focuses on designing and maintaining secure network perimeter defenses while emphasizing TIC 3.0 and Zero Trust principles. Responsibilities include implementing... 
    Network

    Sev1Tech LLC

    Arlington, VA
    4 days ago
  • $131.3k - $237.35k

     ...Description The System Architect SME provides senior technical leadership for enterprise infrastructure architecture and modernization in support of the SEC ISS contract...  ...ensures architecture decisions align with Zero Trust, FISMA, and SEC governance expectations.... 
    Contract work
    Local area
    Immediate start
    Remote work

    Leidos

    Washington DC
    4 days ago
  •  ...solutions provider is seeking a Senior Zero Trust Engineer in Falls Church, Virginia. This...  ...designing and implementing Zero Trust architectures and leading major security projects. Applicants...  ...have over 10 years of experience in network security, relevant degrees, and CISSP... 
    Network
    Full time

    ZTI Solutions LLC

    Falls Church, VA
    2 days ago
  • $128.89k - $184.12k

    A leading defense contractor is seeking a Senior Zero Trust Compliance Officer in Fairfax, VA. This role involves designing and validating Zero Trust compliance across Department of Defense systems while ensuring security authorization alignment. The ideal candidate has... 
    For contractors

    Huntington Ingalls Industries

    Fairfax, VA
    4 days ago
  •  ...Engineering and Cloud Integration Engineer SME / Cross-Disciplinary leader with deep...  ...Engineering and proven capabilities in Cloud Architecture and Cybersecurity. This position...  ...secure practices, frameworks (e.g., FedRAMP, Zero Trust), and system resiliency principles.... 

    Modern Technology Solutions Inc

    Arlington, VA
    1 day ago
  •  ...Everforth ECS is seeking a Cloud Engineer SME to work in the National Capital Region...  ...Cloud Engineer SME is a principal cloud architecture and operations authority within the WDP...  ..., and multi-national AI/ML and Zero Trust initiatives-this role is expected to bring... 
    Contract work
    Worldwide

    ECS Limited

    Falls Church, VA
    3 days ago
  • $178.5k - $241.5k

     ...Top Secret/SCI Public Trust/Other Required: None...  ...: Skills: Building Architecture, Design, VMware Certifications...  ...protecting high profile client networks. As a Sr. Architect you will...  ...Infrastructures Acting as advisor/SME for Client teams on security... 
    Network
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    4 days ago
  •  ...governance of enterprise cybersecurity architectures and engineering initiatives. The Cybersecurity...  .... The role provides leadership for Zero Trust Architecture (ZTA), cybersecurity...  ...architecture integration activities for network infrastructure, applications, APIs,... 
    Network

    cFocus Software Incorporated

    Washington DC
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to ZERO TRUST (ZT) NETWORK ARCHITECTURE SME. Be the first to apply!