Zero Trust Architect
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection, Network Security
Zero Trust Architect
Location:
Bethesda, MD (Hybrid; On-site as Required)
Clearance:
Tier 2 Public Trust (Required)
Employment Type:
Full-Time
Digital Global Connectors (DGC) is seeking an experienced Zero Trust Architect to support a Federal information security program. The Zero Trust Architect is responsible for designing, implementing, and maturing enterprise Zero Trust Architecture (ZTA) strategies that strengthen organizational cybersecurity through identity-centric, risk-based security principles.
This position provides technical leadership for Zero Trust initiatives across identity, devices, networks, applications, workloads, data, automation, and visibility. The Zero Trust Architect collaborates with Security Architects, Cloud Engineers, Security Engineers, ISSOs, Network Engineers, System Owners, and program leadership to integrate Zero Trust principles into enterprise technology modernization efforts.
The successful candidate will possess extensive experience implementing Zero Trust concepts, cloud security architectures, identity governance, and modern cybersecurity technologies that align with Federal cybersecurity guidance and industry best practices.
Essential Duties and Responsibilities:Zero Trust Strategy
- Develop and maintain enterprise Zero Trust Architecture roadmaps.
- Design security architectures based on Zero Trust principles.
- Assess existing environments and identify opportunities to improve Zero Trust maturity.
- Recommend phased implementation strategies that minimize operational disruption.
- Align Zero Trust initiatives with organizational business and mission objectives.
- Support long-term cybersecurity modernization efforts.
- Design secure enterprise architectures that integrate identity, devices, networks, applications, and data protection.
- Develop reference architectures and technical standards supporting Zero Trust implementation.
- Review proposed technologies for architectural alignment.
- Identify architectural risks and recommend mitigation strategies.
- Support secure integration across cloud, hybrid, and on-premises environments.
- Ensure security is incorporated throughout the system development lifecycle.
- Design enterprise Identity and Access Management (IAM) architectures.
- Implement least-privilege and just-in-time access models.
- Support deployment of Multi-Factor Authentication (MFA), Conditional Access, Privileged Identity Management (PIM), and Privileged Access Management (PAM).
- Develop identity governance strategies.
- Support continuous identity verification and adaptive access controls.
- Recommend improvements to authentication and authorization processes.
- Design secure network segmentation strategies.
- Implement policy-based access controls.
- Recommend micro-segmentation solutions that limit lateral movement.
- Evaluate secure remote access technologies.
- Support software-defined perimeter (SDP) and Zero Trust Network Access (ZTNA) initiatives.
- Review network architectures for Zero Trust compliance.
- Design secure cloud architectures supporting Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), and hybrid environments.
- Implement cloud-native Zero Trust capabilities.
- Develop data protection strategies utilizing encryption, data classification, and data loss prevention (DLP).
- Recommend secure workload protection mechanisms.
- Evaluate cloud security posture and identify opportunities for improvement.
- Support secure cloud modernization initiatives.
Design and integrate enterprise security technologies including:
- Microsoft Entra
- Microsoft Defender XDRMicrosoft Defender for Cloud
- Microsoft Sentinel
- Microsoft Intune
- Azure Policy
- Microsoft Purview
- Conditional Access
- Privileged Identity Management (PIM)
- Privileged Access Management (PAM)
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Zero Trust Network Access (ZTNA)
Evaluate new technologies supporting Zero Trust maturity.
Risk Management Framework (RMF) Support- Support implementation of NIST SP 800-53 security controls.
- Review system architectures supporting Authorization to Operate (ATO) activities.
- Assist ISSOs and Security Assessors during architecture reviews.
- Recommend technical solutions supporting continuous monitoring.
- Evaluate architectural risks identified during security assessments.
- Support development of architecture documentation associated with RMF activities.
Develop and maintain:
- Zero Trust Roadmaps
- Enterprise Security Architectures
- Reference Architectures
- Technical Design Documents
- Security Architecture Diagrams
- Technology Standards
- Implementation Guides
- Executive Briefings
- Maturity Assessments
- Architecture Decision Records (ADRs)
Ensure documentation remains current, technically accurate, and aligned with organizational standards.
Collaboration- Coordinate with Security Architects, Security Engineers, Cloud Engineers, ISSOs, Network Engineers,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).