Enterprise Architect - Zero Trust
Job in
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-08-23
Listing for:
Brooksource
Full Time
position Listed on 2026-08-23
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Security Architect – Zero Trust Architecture
- Security Architect – Zero Trust Architecture
- Charlotte, NC
- Hybrid role (3 days onsite, 2 days remote)
- Pay: $65-$75 per hour
- 12-month contract with strong potential for extension or full-time conversion
Lead the design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy. Define and operationalize a “never trust, always verify” model across identity, devices, networks, applications, and data. Drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least privilege and continuous verification across all enterprise resources.
Key Responsibilities Architecture & Strategy- Define and maintain the enterprise Zero Trust Architecture (ZTA) reference model, aligned to industry frameworks (NIST SP 800-207, CISA ZTMM) and business priorities.
- Establish target-state architectures and transition roadmaps for Zero Trust adoption across hybrid cloud, SaaS, and on-prem environments.
- Define policy-driven access models leveraging identity, device posture, behavior, and environmental risk signals.
- Align Zero Trust architecture with enterprise security strategy, cloud adoption, and digital transformation initiatives.
- Lead end-to-end architecture reviews ensuring solutions align with Zero Trust principles, including least privilege, continuous verification, and explicit trust evaluation.
- Define and enforce architectural guardrails and secure patterns across identity, network, endpoint, application, and data layers.
- Establish policy decision and enforcement models (PDP/PEP) across enterprise control points (identity providers, gateways, endpoints, network controls).
- Provide governance and oversight for Zero Trust capabilities across business units, platforms, and shared services.
- Design integration patterns that unify IAM, endpoint security, network controls, application access, and data protection into a cohesive Zero Trust model.
- Define how identity, device posture, and risk signals drive dynamic access decisions across APIs, applications, and infrastructure.
- Collaborate with domain architects (IAM, Network, Cloud, Endpoint, Data) to ensure consistent enforcement of Zero Trust controls and patterns.
- Enable secure service-to-service and user-to-resource access patterns across distributed architectures (microservices, APIs, SaaS).
- Define enterprise access control strategies including adaptive authentication, conditional access, and fine-grained authorization.
- Establish policy models for user, service, and machine identity access, incorporating RBAC, ABAC, and policy-based access control.
- Define enforcement patterns across gateways, proxies, API layers, and endpoint controls to ensure consistent access decisions.
- Integrate continuous monitoring and feedback loops to adjust access decisions based on real-time risk and context.
- Lead threat modeling initiatives focused on lateral movement, identity compromise, session hijacking, and trust boundary violations.
- Define security controls to mitigate Zero Trust-specific attack vectors (credential abuse, privilege escalation, bypass of enforcement points).
- Ensure Zero Trust architecture aligns with regulatory requirements and supports continuous risk reduction and measurable security outcomes.
- Establish metrics and maturity indicators for Zero Trust adoption and effectiveness across the enterprise.
- Drive adoption of Zero Trust patterns through reusable architectures, reference implementations, and engineering guidance.
- Partner with engineering, platform, and security teams to embed Zero Trust controls into SDLC, CI/CD, and platform engineering workflows.
- Evaluate and recommend technologies supporting Zero Trust capabilities (identity platforms, ZTNA, microsegmentation, API gateways, endpoint posture).
- Communicate architecture strategy, tradeoffs, and risk posture clearly to engineering, product, and executive stakeholders.
- Define secure GenAI patterns (LLM…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×