LEAD ZERO TRUST ARCHITECT

TRIPLE POINT SECURITY INCORPORATED•Leesburg, VA
•$140,000 - $160,000•Hybrid

About The Position

Triple Point Security is seeking a Lead Zero Trust Architect to support a national research organization's enterprise Zero Trust program. This role involves leading a team to develop future state Zero Trust architecture, reference architectures for various environments, and control inheritance documentation. The position requires working directly on integrating Zero Trust requirements into client processes, aligning with enterprise architecture, and engaging with client leadership and stakeholders. The work will have a significant impact on the medical and scientific communities served by the client.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field from an accredited university
  • 5+ years of experience in cybersecurity architecture, enterprise security architecture, or security engineering, including demonstrated experience designing, assessing, or implementing Zero Trust Architecture in a Federal or large enterprise environment
  • Working knowledge of NIST SP 800-207, the CISA Zero Trust Maturity Model (ZTMM) v2.0 (five pillars and three cross-cutting capabilities), OMB Memorandum M-22-09, and Executive Order 14028
  • Strong knowledge of NIST SP 800-53 Rev. 5 and the NIST Risk Management Framework (SP 800-37), including common, hybrid, and system-specific controls and how control inheritance is claimed and evidenced
  • Experience developing target-state architectures, reference architectures, or reusable design patterns spanning cloud, on-premises, and hybrid environments
  • Hands-on architecture experience in at least one major cloud service provider (AWS, Azure, or GCP), including identity and access management, network segmentation, and logging and monitoring
  • Experience mapping security controls to capability frameworks or maturity models and producing traceability matrices, gap analyses, and remediation roadmaps
  • Experience leading technical staff, including assigning and sequencing work, reviewing deliverables for technical accuracy, and holding a team to fixed deliverable dates
  • Strong written communication skills, including the ability to produce clear, well-organized architecture deliverables for both technical and non-technical readers
  • Experience in client-facing roles, including presenting recommendations to senior leadership and governance bodies, facilitating meetings and working sessions, and building agreement among stakeholders with different priorities
  • Proven problem solving, critical analysis, and risk-based thinking skills to prioritize architecture recommendations against available time, budget, and staffing
  • Must be a U.S. citizen (client requirement).
  • Must be able to obtain and maintain a client suitability determination (Public Trust) and a client-issued Personal Identity Verification (PIV) credential, and complete required security and privacy training prior to access.
  • at least one active senior cybersecurity certification: CISSP (Certified Information Systems Security Professional), CISSP-ISSAP (Information Systems Security Architecture Professional), CCSP (Certified Cloud Security Professional), or equivalent

Nice To Haves

  • 8+ years of experience in cybersecurity or IT architecture, including 3+ years in a lead or senior architect role
  • Master's degree in Cybersecurity, Information Systems, Computer Science, or a related field
  • Experience supporting Federal civilian agencies, particularly HHS or other research and health organizations with federated IT operating models
  • Experience with enterprise architecture frameworks (TOGAF, FEAF) and with mapping a target architecture to Business, Data, Application, Technology/Infrastructure, and Security Architecture domains
  • Experience embedding security requirements into IT governance and funding processes such as Capital Planning and Investment Control (CPIC), Enterprise Performance Life Cycle (EPLC) stage gates, ATO/A&A reviews, O&M project justifications, acquisition reviews, or architecture review boards
  • Experience recording control inheritance in GRC tools such as CSAM/JCAM, RSA Archer, or ServiceNow IRM
  • Familiarity with FedRAMP, Trusted Internet Connections (TIC) 3.0, CISA Continuous Diagnostics and Mitigation (CDM), and NIST SP 1800-35 (Implementing a Zero Trust Architecture)
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Bicep) and policy-as-code, including using automation to produce continuous monitoring evidence
  • Hands-on experience with ZT enabling technologies such as ICAM and PIV/PKI, Entra ID or Okta, ZTNA/SASE, micro-segmentation, and EDR/device posture solutions
  • Experience developing and delivering training, briefings, or recurring stakeholder forums such as office hours or communities of practice
  • Prior experience in a consulting or professional services environment, including contributing to technical proposals and capability briefings
  • Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT)
  • AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or equivalent cloud security certification
  • TOGAF Enterprise Architecture certification
  • CGRC (Certified in Governance, Risk and Compliance, formerly CAP) or CISM

Responsibilities

  • Lead the Architecture & Engineering workstream: set the technical approach, assign and sequence work across the Cloud/Hybrid Architect and ZTA Controls Analysts, and review every team deliverable for technical accuracy before it enters independent quality review
  • Develop the Future State ZTA, integrating identity, device, network, application/workload, and data security controls supported by automation, orchestration, and continuous monitoring, aligned with Executive Order 14028, OMB M-22-09, the HHS ZTA, and CISA ZTMM v2.0, targeting Advanced maturity enterprise-wide and Optimal maturity for selected critical systems
  • Own the ZTA process integration tracker: identify, document, and maintain the processes and funding mechanisms that should require ZT evidence, including ATO/A&A reviews, cybersecurity funding requests, O&M project justifications, CPIC submissions, and procurement/acquisition reviews; for each, record the process owner, decision point, required evidence, insertion mechanism, approving governance body, and cycle date
  • Sequence ZT requirement insertions against the funding and planning calendars that govern them, and publish provisional criteria for the following cycle wherever the current cycle has closed
  • Map the Future State Target Architecture to the organization's Business, Data, Application, Technology/Infrastructure, and Security Architecture domains using the client's own taxonomy and existing architecture artifacts, in close coordination with the client's IT architecture office
  • Direct development of gold-standard reference architectures for cloud, on-premises, and hybrid environments as a cloud-agnostic pattern core with per-platform implementation guidance for AWS, Azure, and GCP, specifying for each pattern which controls are enforced through infrastructure-as-code, which are orchestrated across services, and which produce continuous monitoring evidence automatically
  • Oversee the centrally provided services matrix, ensuring each capability identifies the NIST SP 800-53 Rev. 5 controls it addresses, marks each as fully, partially, or not inherited, and carries customer responsibility statements, citable evidence sources, and suggested system security plan language
  • Oversee the mapping of the organization's FISMA-reportable systems against centrally provided and inherited ZT controls, including the bi-directional NIST SP 800-53 to ZTMM mapping, identification of unclaimed inheritance, and a risk-informed remediation roadmap
  • Coordinate architecture positions with enterprise service owners, including cloud services, network services, identity and access management, and security operations, and with the client's governance, risk, and compliance and security assurance offices
  • Provide architecture input to the ZTA control overlay, policy anchors, and architecture review criteria and checkpoints so that all ZT expectations derive from one consistent source
  • Lead the architecture portion of the coordinated quarterly refresh cycle, checking any change in a centrally provided capability against every artifact that references it before the cycle closes
  • Present architecture recommendations, deliverables, and status updates to client leadership, governance bodies, and technical stakeholders
  • Plan and facilitate client working sessions, architecture reviews, and stakeholder meetings, including preparing agendas and materials and tracking decisions and action items
  • Serve as the architecture subject matter expert for monthly institute office hours, ZTA knowledge base content, and enterprise help desk inquiries
  • Mentor analysts, junior engineers, and interns on ZT architecture, control inheritance, and Federal compliance requirements
  • Support business development efforts including proposal contributions, technical solutioning, and client presentations
  • Stay current with evolving Federal ZT policy, CISA guidance, the threat landscape, and emerging ZT technologies

Benefits

  • 401(k) company matching contributions
  • 100% of premium cost for basic employee coverage: Health, Dental, and Vision
  • 100% of premium cost: Basic Life AD&D, Short Term Disability, and Long Term Disability
  • Flexible Spending Accounts: Health, Dependent Care, and Mass Transit & Parking
  • Tuition & Training Reimbursement
  • Paid Time Off plus 10 Paid Holidays
  • Performance and referral Bonus
  • Flexible work schedule (with client approval)
  • Employee Assistance Program
  • Call A Doctor Plus Telemedicine Service
  • MetLaw Group Legal Services
  • Technology resources (HW/SW), online training, and virtual labs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service