ZERO TRUST (ZT) NETWORK ARCHITECTURE SME
Zermount, Inc.
ZERO TRUST (ZT) NETWORK ARCHITECTURE SME
POSITION OVERVIEW
The Zero Trust Network Architecture Technical SME exists to serve as the agency's primary technical advisor for the CISA ZTMM v2.0 Networks pillar. This role advances TSA's network segmentation posture, TIC 3.0 compliance, and ZTNA adoption by providing senior-level advisory on network architecture design, micro‑segmentation strategy, and software‑defined networking (SDN) capabilities. The expected outcome is a continuously advancing Networks pillar maturity posture with network macro‑ and micro‑segmentation maturing, ZTNA architecture advisory driving enforcement design, and lateral movement risk proactively identified and addressed. This is a senior technical advisory role requiring hands‑on network architecture and ZTNA design experience in a federal environment.DUTIES & RESPONSIBILITIES
General Duties Serve as the primary technical advisor for the CISA ZTMM v2.0 Networks pillar across network security architecture, segmentation, and ZTNA domains. Continuously assess the agency's network architecture against CISA ZTMM v2.0 Networks pillar criteria and NIST SP 800‑207; proactively identify emerging network risk indicators, including lateral movement exposure, traffic encryption and visibility deficiencies, and TIC 3.0 compliance drift, and deliver real‑time advisory recommendations. Provide technical advisory guidance on ZTNA architecture design options, micro‑segmentation strategies, and SDN approaches, recommending solutions and implementation pathways for agency decision‑making. Evaluate ZTNA platform capabilities (e.g., Zscaler, Palo Alto Prisma) and develop configuration and deployment recommendations aligned to federal ZT requirements for agency adoption. Advise TIC 3.0 compliance strategies, cloud network access patterns, and secure remote access approaches in a hybrid federal environment; develop recommended solutions for agency review. Assess network access control mechanisms, lateral movement risk, and east‑west traffic enforcement against ZT principles; develop findings and recommended remediation approaches for agency concurrence. Provide advisory support for the development and maturation of Networks pillar entries in the Common Control Catalog (CCC), ensuring traceability to NIST SP 800‑53 Rev. 5 control families. Develop recommended Networks pillar inputs to the ZT Roadmap, IG FISMA maturity reporting, and enterprise performance reporting for agency review and approval. Collaborate with Identity, Device, Data, and Applications SMEs to ensure network enforcement approaches integrate coherently across all ZTMM pillars. Review network‑related policy documents and technical standards; identify gaps relative to ZT mandates and develop recommended updates for agency concurrence. Support all network‑related ZT data calls, audits, and compliance reporting by providing advisory analysis and recommended responses. Prepare and present network architecture findings, maturity assessments, and advisory recommendations to senior leadership and the CISO. Leverage AI‑assisted analysis tools, automation platforms, and prompt engineering techniques to enhance advisory productivity, accelerate gap analysis and documentation tasks, and enable focus on higher‑value technical advisory work; apply all AI capabilities in accordance with agency acceptable use policies and Zermount's ethical AI use guidelines.SUBJECT MATTER EXPERTISE
SME Area #1 – Network Security Architecture, ZTNA & Micro‑Segmentation Advisory Expert‑level mastery of network security architecture including ZTNA design, micro‑segmentation strategy, and software‑defined networking demonstrated through production deployment or senior advisory engagement. Authoritative knowledge of CISA ZTMM v2.0 Networks pillar criteria, NIST SP 800‑207 network access tenets, TIC 3.0 use cases and security capabilities, and NIST SP 800‑53 Rev. 5 control families. Expert‑level proficiency with ZTNA platforms such as Zscaler and/or Palo Alto Prisma at architecture design, configuration, and deployment depth for federal environments. Expert‑level capability in network segmentation design including macro‑segmentation, micro‑segmentation, lateral movement risk assessment, and east‑west traffic enforcement strategy. Independent decision‑making authority on Networks pillar advisory scope, architecture assessment methodology, and recommended ZTNA and segmentation approach. Bring solutions for concurrence. Problem‑solving at the intersection of network enforcement and cross‑pillar ZT integration. Able to identify how network segmentation deficiencies create risk in Identity enforcement decisions and Applications access control. SME Area #2 – Enterprise Network Infrastructure & Cloud Networking Foundations Deep foundational expertise in enterprise network architecture including routing and switching (BGP, OSPF, VLAN design), firewall policy management, VPN technologies, and load balancing at architecture or senior engineering level. Hands‑on experience with enterprise network infrastructure platforms (Cisco, Palo Alto Networks, Fortinet, or equivalent) including firewall rule design, segmentation architecture, and traffic inspection configuration. Strong working knowledge of cloud networking constructs, including VPC/VNet design, cloud‑native security groups, transit gateways, and cloud‑based SD‑WAN, Infrastructure‑as‑Code (IaC), and hybrid connectivity patterns relevant to ZT network enforcement. Foundational understanding of database network access patterns, systems administration network dependencies, and application‑layer traffic flows as they relate to segmentation design and ZT enforcement policy. Supports Network pillar advisory by enabling technically credible engagement with agency network engineers, firewall administrators, and cloud infrastructure teams. Interacts directly with other Zero Trust SMEs.QUALIFICATIONS
Minimum Requirements A minimum of 10 years of experience in network security architecture, ZTNA design, or enterprise network engineering with demonstrated Zero Trust scope. Demonstrated hands‑on experience designing or implementing ZTNA architectures in federal or large enterprise environments, reflecting operational design and deployment, not vendor evaluation or documentation. Hands‑on experience with ZTNA platforms (e.g., Zscaler, Palo Alto Prisma, Cisco) including architecture design, configuration, and deployment. Expert knowledge of NIST SP 800‑207, CISA ZTMM v2.0 Networks pillar criteria, and TIC 3.0 requirements. Experience with micro‑segmentation design, SDN, and lateral movement risk assessment in a ZT context. Ability to assess network security controls against NIST SP 800‑53 Rev. 5 control families. Demonstrated experience designing and implementing Zero Trust network architectures operationally, not limited to assessments or gap analyses. Experience supporting ZT‑related IG FISMA metrics reporting pertaining to network security and TIC 3.0. Strong written and oral communication skills; ability to translate complex network architecture concepts into CISO‑ready findings. Demonstrated familiarity with AI‑assisted analysis tools or prompt engineering; ability to apply AI capabilities ethically to accelerate advisory work and surface higher‑value technical insights. Preferred Qualifications Five years of IT cybersecurity experience, including direct support to the U.S. Government. This experience can be concurrent with the minimum 10 years of network architecture experience. Prior direct involvement in a ZT Networks pillar implementation or enterprise ZTNA deployment in a technical architecture or advisory capacity. ZTNA vendor certification: Zscaler Zero Trust Certified Associate (ZTCA) or Palo Alto Networks PCNSE. Experience with encrypted traffic management (SSL/TLS inspection) and east‑west traffic visibility in a ZT network environment. Experience with cloud‑native networking security (Azure Virtual WAN, AWS Transit Gateway, GCP Cloud Armor, or Infrastructure‑as‑Code) in a federal hybrid environment. Competencies Technical: CISA ZTMM v2.0 Networks pillar, NIST SP 800‑207, TIC 3.0, Zscaler, Palo Alto Prisma, Cisco, ZTNA architecture, micro‑segmentation, BGP/OSPF/VLAN, VPN, firewall policy design, cloud networking (VPC/VNet), NIST SP 800‑53, AI‑assisted analysis. Leadership: Technical advisory leadership for Networks pillar; cross‑pillar SME coordination with Identity, Devices, and Applications teams; CISO‑facing network architecture briefing; engagement with agency network engineers and cloud infrastructure teams. Behavioral: Proactive continuous network posture monitoring; precision in architecture assessment and segmentation advisory; continuous learning toward evolving ZTNA platform capabilities, TIC 3.0 updates, and federal network security guidance. Education & Certifications Minimum of a Bachelor of Science (or higher) in Information Technology, Computer Science, Network Engineering, Cybersecurity, or related field. Required: Certified Information Systems Security Professional (CISSP) or Cisco Certified Network Professional Security (CCNP Security), or equivalent certification. Strongly preferred: Certified Information Security Manager (CISM) or equivalent senior security management certification. Strongly preferred: ZTNA vendor certification. Zscaler ZTCA, Palo Alto Networks PCNSE, or equivalent. Clearance Level Active Secret Clearance required.WORK LOCATION
Hybrid – Primarily Remote. Occasional onsite work required at the client location in Springfield, VA and Zermount HQ in Arlington, VA.HOURS OF OPERATION
Business Hours: 8:00 AM EST – 4:30 PM EST Core Hours: 9:00 AM EST – 3:00 PM ESTREPORTING STRUCTURE
Reports To: ZT SME Team Leader Direct Reports: None #J-18808-Ljbffr Zermount, Inc.Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the ZERO TRUST (ZT) NETWORK ARCHITECTURE SME in Arlington, VA vacancy
- ...Description Job Description ZERO TRUST (ZT) DATA SUBJECT MATTER EXPERT... ...Matter Expert (ZT Data SME) exists to provide senior-level... ...alignment with Zero Trust Architecture (ZTA) principles. This role... ...integration across Identity, Devices, Networks, and Applications &...NetworkCasual workRemote work
- Zermount, Inc. is seeking a Zero Trust Network Architecture SME in Arlington, VA. This senior advisory role focuses on enhancing the agency's network architecture and ZTNA implementation, requiring extensive experience in network security and compliance with federal standards...NetworkRemote work
- ...ZERO TRUST (ZT) PROCESS RE-ENGINEERING SME Position Overview The Zero Trust Process Re-Engineering SME exists... ...v2.0 pillars: Identity, Devices, Networks, Applications & Workloads, and Data... ...constraints. SME Area #2 – Enterprise IT Architecture & Technical Domain Fluency...NetworkCasual workRemote work
- ZERO TRUST (ZT) ENDPOINT & CONNECTED SYSTEMS SME POSITION OVERVIEW The Zero Trust Systems Engineering Technical SME... ...approval. Collaborate with Identity, Network, Data, and Applications SMEs to... ...including IoT/OT platform architecture, ZT device compliance policy design...NetworkCasual workRemote work
$77.6k - $176k
Zero Trust ArchitectThe Opportunity:Everyone knows security needs to be “baked in” to system architecture, but you know how to bake it in. You can identify... ...Engineer with Zero Trust (ZT) experience who can create... ...information systems and networks. You’ll coordinate with a...NetworkFull timeContract workPart timeWork at officeLocal areaRemote work- ...Description Job Description ZERO TRUST PROJECT LEAD POSITION... ...seeking a Zero Trust (ZT) Technical Project Lead... ...ZT (identity, device, network, application and... ...management and control.Provide SME support and technical... ..., and CISA Zero Trust Architecture, Maturity Model, and...NetworkFor contractorsWork experience placementRemote work
$150k - $180k
Zero Trust Junior Architect Location: Washington, DC (Hybrid: Needs to be on-site in DC... ...all security pillars—identity, devices, networks, applications, workloads, and data. This... .... You will work on large‑scale architecture efforts, leverage leading Zero Trust platforms...NetworkContract work- Zero Trust Architect Location: Bethesda, MD (Hybrid; On-site as Required) Clearance: Tier... ..., and maturing enterprise Zero Trust Architecture (ZTA) strategies that strengthen organizational... ...initiatives across identity, devices, networks, applications, workloads, data,...NetworkFull timeWork at officeRemote work
- Digital Global Connectors is seeking an experienced Zero Trust Architect to support a Federal information security... ...designing, implementing, and maturing enterprise Zero Trust Architectures across identity, devices, networks, applications, data, and automation. The ideal...Network
- Hiring Our Heroes in Arlington, VA seeks a senior Zero Trust Policy Advisory SME to assess and re-engineer enterprise IT and cybersecurity processes... ...role translates policy into actionable roadmaps and drives ZT maturity with senior advisory guidance. You will lead risk-...
$130k - $140k
...Threat Detection and Response (ITDR), and Zero Trust trends. You see an email from a Field... ...tied to Cloud Security, Zero Trust architecture, SaaS visibility, identity protection,... ..., CASB, ITDR, XDR, MDR, and Zero Trust Network Access (ZTNA).Bonus Points• Experience...NetworkFull timeWork at officeLocal areaRemote workFlexible hours$175k - $200k
GovCIO is currently hiring a Zero Trust Team Lead to drive the implementation and governance of Zero Trust Architecture (ZTA) for the U.S. Coast Guard (USCG). This role combines... ...identity providers, endpoint protection, network segmentation).Familiarity with Agile or...NetworkCurrently hiring$103.2k - $172k
...communicate application and data architecture standards, policies, and... ...security, operating at the edge, zero trust, enterprise/managed services,... ...and 15 years' experience for SME-levelActive Security... ...services for compute, store, network, security, and automation)Strong...NetworkContract workWork experience placementH1b- ...lifecycle management of DNS, DHCP, and IPAM services for NASA networks. You will drive secure name resolution aligned with NIST SP 80... ...strategies, DNSSEC signing/validation, protective DNS deployment, and Zero Trust controls across authoritative servers, resolvers, #J-18808-...Network
$146k - $234k
...BNATCS) contract. As a trusted partner to the Federal... ...Automation Architect -SME to join our team of qualified... ...strategic vision, architecture leadership, and technical... ...with cybersecurity, network, and systems engineering... ...ensure automation supports Zero Trust, RMF, and...NetworkContract workFor subcontractorShift work$99k - $225k
Job Number: R0241661 Zero Trust Architect The Opportunity Serve as a Zero Trust Architect supporting the Joint Program Office (JPO)... ...environments. Collaborate with stakeholders to align cybersecurity architecture with operational objectives, ensuring secure access to data,...Full timeContract workPart timeWork at officeLocal areaRemote work- Tetrad Digital Integrity (TDI) seeks a Systems Engineer to advance an IDaaS platform underpinning CESO's Zero‑Trust architecture. You will work hands-on with ForgeRock ICAM components, Ping Identity tools, and enterprise directories in secure environments. The role emphasizes...
- Cybersecurity / Zero Trust Architect - Principal Arlington, VA Are you ready to enhance your skills and build your career in a rapidly... ...in the design and implementation of enterprise cybersecurity architectures supporting CDAO mission systems. This role leads the...Work at officeWork from homeHome office
- Digital Global Connectors is seeking an experienced Zero Trust Architect to design, implement, and mature enterprise ZTA strategies for a federal security program. You will lead identity-centric security across IAM, MFA, and privileged access while collaborating with cross...
- Booz Allen seeks an ICAM Architect to deliver identity and access management solutions for clients, focusing on zero trust, SSO, and MFA. You will interface with stakeholders and engineering teams to analyze identities, define enterprise identity records, and design, deploy...
- Chenega Corporation in Arlington, VA is seeking a Principal Cybersecurity / Zero Trust Architect to provide senior technical leadership in cybersecurity architecture supporting government operations. The ideal candidate will have 12+ years of experience in federal environments...
$77.6k - $176k
Booz Allen Hamilton is seeking a Zero Trust Architect to lead the architecture and design of innovative cybersecurity solutions for the U.S. Government. The role requires coordinating with experts to advance Zero-Trust concepts across various fields. Ideal candidates will...- ...to support our government customer by engineering, deploying, automating, and sustaining an IDaaS platform that underpins zero-trust architecture. The role involves hands-on work with ForgeRock components, SSO/SAML/OIDC, CI/CD pipelines, and ICAM integration patterns,...
$146k - $234k
...lead for Kubernetes platform architecture, automation, infrastructure... ...cluster foundations including networking, storage integrations,... ...Kubernetes Subject Matter Expert (SME) providing architectural... ...logging stacksFamiliarity with Zero Trust Architecture and federal...NetworkContract workShift work- ...our talented Team. Job Title: AWS Cloud Firewall SME. Location: McLean, VA. Job Description:Need an... ...Subject Matter Expert (SME) focused on the architecture, implementation, and central management of network security across cloud environments.Core Responsibilities...NetworkImmediate start
$180k - $225k
...-owned federal contractor, is seeking a Network Architect / Subject Matter Expert to support... ...role is focused on future-state network architecture rather than day-to-day operations and... ....ResponsibilitiesAs a Network Architect SME with AMERICAN SYSTEMS, you will have the...NetworkFor contractors$220k - $240k
...hiring a Cybersecurity Engineer (RMF / Zero Trust) with an active Secret clearance to design... ...activities.Design Zero Trust architectures and security solutions.Perform vulnerability... ...Implement identity, access, endpoint, and network security controls.Conduct security...NetworkRemote work- ...modernization program. You will drive DevSecOps integration, enforce Zero Trust across architectures, and guide ATO processes while coordinating with OIS and senior government stakeholders. The role requires SME-level experience, CISSP/CCSP, and deep expertise in NIST...Remote work
$239k - $278.75k
...Our Mission At Palo Alto Networks®, we’re united by a shared... ...part of a culture that values trust, accountability, and shared... ...delivering authoritative architectural roadmaps that create a... ...Secure Access Service Edge/Zero Trust (SASE/ZT), Cloud Security, Security...NetworkRemote workVisa sponsorshipWork visa- GTSC seeks Cybersecurity Engineer – Zero Trust / RMF / SIEM \\\ for mid -August 2026 start... ...SP 800 -53, NIST SP 800 -207, cloud, network, endpoint, and identity environments. \... ...Implement security controls and Zero Trust architecture. \\ Support vulnerability management...NetworkFull timeTemporary workLocal areaRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ZERO TRUST (ZT) NETWORK ARCHITECTURE SME. Be the first to apply!
Related searches
- networking Arlington, VA
- food network test kitchen Arlington, VA
- provider network consultant Arlington, VA
- director of network operations Arlington, VA
- network operations center technician Arlington, VA
- network operations center engineer Arlington, VA
- food network Arlington, VA
- learning network Arlington, VA
- rn network Arlington, VA
- compass health network Arlington, VA



