Enterprise Architect - Zero Trust


Brooksource
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Roadmaps
- Evaluation
- Shared Services
- Collaboration
- Microservices
- RBAC
- Proxies
- Real-time
- Security Controls
- Software Development Methodology
- Continuous Integration
- Continuous Delivery
- Workflow
- Identity Management
- Multi-factor Authentication
- Endpoint Protection
- Mobile Devices
- Network
- Data Security
- Encryption
- Continuous Monitoring
- Analytics
- Decision Support
- Use Cases
- Extraction
- Testing
- Generative Artificial Intelligence (AI)
- Data Governance
- Computer Science
- Information Security
- NIST SP 800 Series
- CISA
- Authentication
- Authorization
- Access Control
- Network Security
- Cloud Computing
- Amazon Web Services
- Microsoft Azure
- SaaS
- API
- Threat Modeling
- Risk Assessment
- FFIEC
- PCI DSS
- Sarbanes-Oxley
- Communication
- Presentations
- SAP WM
Summary
- Security Architect - Zero Trust Architecture
- Charlotte, NC
- Hybrid role (3 days onsite, 2 days remote)
- Pay: $65-$75 per hour
- 12-month contract with strong potential for extension or full-time conversion
Objective:
Lead the design, governance, and adoption of enterprise Zero Trust Architecture (ZTA) aligned to NIST SP 800-207 and organizational security strategy. Define and operationalize a "never trust, always verify" model across identity, devices, networks, applications, and data. Drive the transition from perimeter-based security to policy-driven, risk-aware access controls that enforce least privilege and continuous verification across all enterprise resources.
Key Responsibilities:
Architecture & Strategy
- Define and maintain the enterprise Zero Trust Architecture (ZTA) reference model, aligned to industry frameworks (NIST SP 800-207, CISA ZTMM) and business priorities.
- Establish target-state architectures and transition roadmaps for Zero Trust adoption across hybrid cloud, SaaS, and on-prem environments.
- Define policy-driven access models leveraging identity, device posture, behavior, and environmental risk signals.
- Align Zero Trust architecture with enterprise security strategy, cloud adoption, and digital transformation initiatives.
Architecture & Governance
- Lead end-to-end architecture reviews ensuring solutions align with Zero Trust principles, including least privilege, continuous verification, and explicit trust evaluation.
- Define and enforce architectural guardrails and secure patterns across identity, network, endpoint, application, and data layers.
- Establish policy decision and enforcement models (PDP/PEP) across enterprise control points (identity providers, gateways, endpoints, network controls).
- Provide governance and oversight for Zero Trust capabilities across business units, platforms, and shared services.
Cross-Domain Integration
- Design integration patterns that unify IAM, endpoint security, network controls, application access, and data protection into a cohesive Zero Trust model.
- Define how identity, device posture, and risk signals drive dynamic access decisions across APIs, applications, and infrastructure.
- Collaborate with domain architects (IAM, Network, Cloud, Endpoint, Data) to ensure consistent enforcement of Zero Trust controls and patterns.
- Enable secure service-to-service and user-to-resource access patterns across distributed architectures (microservices, APIs, SaaS).
Policy, Access & Control Enforcement
- Define enterprise access control strategies including adaptive authentication, conditional access, and fine-grained authorization.
- Establish policy models for user, service, and machine identity access, incorporating RBAC, ABAC, and policy-based access control.
- Define enforcement patterns across gateways, proxies, API layers, and endpoint controls to ensure consistent access decisions.
- Integrate continuous monitoring and feedback loops to adjust access decisions based on real-time risk and context.
Threat Modeling, Risk & Assurance
- Lead threat modeling initiatives focused on lateral movement, identity compromise, session hijacking, and trust boundary violations.
- Define security controls to mitigate Zero Trust-specific attack vectors (credential abuse, privilege escalation, bypass of enforcement points).
- Ensure Zero Trust architecture aligns with regulatory requirements and supports continuous risk reduction and measurable security outcomes.
- Establish metrics and maturity indicators for Zero Trust adoption and effectiveness across the enterprise.
Engineering Enablement & Adoption
- Drive adoption of Zero Trust patterns through reusable architectures, reference implementations, and engineering guidance.
- Partner with engineering, platform, and security teams to embed Zero Trust controls into SDLC, CI/CD, and platform engineering workflows.
- Evaluate and recommend technologies supporting Zero Trust capabilities (identity platforms, ZTNA, microsegmentation, API gateways, endpoint posture).
- Communicate architecture strategy, tradeoffs, and risk posture clearly to engineering, product, and executive stakeholders.
Core Security Domains
Identity & Access Management
Authentication, federation, adaptive MFA, conditional access, service-to-service identity, least privilege, and identity governance.
Device & Endpoint Security
Device posture, endpoint detection and response (EDR), mobile/device trust, health validation, and enforcement of device-based access conditions.
Network Security & Segmentation
Microsegmentation, software-defined perimeters, ingress/egress controls, secure connectivity, and enforcement of network-level policy decisions.
Application & API Security
Application access control, API authentication/authorization, secure service communication, token-based access, and policy enforcement at application layers.
Data Security
Data classification, encryption, data minimization, access controls aligned to sensitivity, and protection of data across states (in transit, at rest, in use).
Visibility, Analytics & Automation
Centralized telemetry, continuous monitoring, behavioral analytics, policy decision support, and automated response and enforcement.
GenAI Security
- Define secure GenAI patterns (LLM access controls, prompt/response handling, RAG security, agent/tooling boundaries).
- Threat model GenAI use cases (prompt injection, data leakage, model extraction/poisoning, unsafe output handling) and define mitigations/testing.
- Set GenAI data governance requirements (sensitive data use, retention, auditability) and vendor/model assurance expectations.
MINIMUM QUALIFICATIONS:
- 7+ years of relevant experience
- Bachelor's Degree in Computer Science, Information Security, or related field of study or equivalent
PREFERRED QUALIFICATIONS:
- Master's in Computer Science, Information Security, or related field.
- 5+ years designing or implementing Zero Trust Architecture or similar enterprise security transformation initiatives
- Deep understanding of Zero Trust principles and frameworks (NIST SP 800-207, CISA Zero Trust Maturity Model)
- Strong experience in IAM, authentication/authorization, and policy-based access control models
- Experience with network security, segmentation, ZTNA, and modern connectivity architectures
- Experience with endpoint/device security and integration of device posture into access decisions
- Experience designing secure architectures across hybrid cloud (AWS/Azure), SaaS, and on-prem environments
- Proven experience integrating multiple security domains into cohesive architecture patterns
- Hands-on or architectural experience with technologies such as identity platforms, ZTNA solutions, API gateways, and microsegmentation tools
- Strong experience with threat modeling, architecture reviews, and security risk assessments
- Familiarity with regulatory frameworks (FFIEC, PCI DSS, SOX) and security frameworks (NIST, CIS)
- Demonstrated ability to influence cross-functional teams and drive enterprise adoption of security patterns
- Strong communication and executive presentation skills
#LI-WM1
- Dice Id: 10110651
- Position Id: a1Wcv000000iI7hEAE
- Posted 2 days ago
Company Info
Here at Brooksource, relationships are at the center of everything we do. Since 2000, we have established and maintained long-lasting relationships with our clients and consultants to create an unparalleled experience. Brooksource is a trusted services provider that specializes in delivering Engineering and IT solutions for Fortune 500 organizations through Experience-Driven Staffing, Professional Services, and Elevate, our Workforce Transformation program. As a certified partner for Salesforce, AWS, Microsoft, Google Cloud, and many other technology alliances, we are looking for professionals who want to be on the frontline of the latest trends in the industry.
We offer contract, contract-to-hire, and direct placement consultant opportunities, to provide a career path that can meet anyone's desires. The job search is hard, but you don’t have to do it alone! We know a successful partnership requires a good fit. Your personality, experience, and skill set are all important, contributing factors to that partnership. You can count on us to take the time to understand the type of technical and cultural fit that is right for you. As a Brooksource consultant, you will be provided with a comprehensive benefits plan, competitive compensation, and even paid time off!
Cyber Security Warning: Please be aware that all official Brooksource communications will ONLY come from emails displayed as [name]@brooksource.com. The use of any other domains is NOT an official Brooksource employee and could be fraudulent.
Brooksource provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, national origin, age, sex, citizenship, disability, genetic information, gender, sexual orientation, gender identity, marital status, amnesty or status as a covered veteran in accordance with applicable federal, state, and local laws.
Benefits & Perks:
Brooksource offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.
Pay Disclaimer:
The pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Partnerships:
- Gold Microsoft Partner – Cloud Platform
- Gold Microsoft Partner – Data Analytics
- Silver Microsoft Partner – Data Platform
- Silver Microsoft Partner – Security
- Silver Microsoft Partner – Application Development
- Silver Microsoft Partner – Data Center
- AWS Partner
- Salesforce Partner
- Salesforce – Authorized Training Provider
- Salesforce Talent Alliance Employer
- Tableau Services Partner
- Snowflake Partner
- Google Cloud Platform (GCP) Services Partner
Awards (Extended):
- Best Places to Work 2022, Charlotte Business Journal, 2022
- Best Places to Work in Jacksonville, Jacksonville Business Journal, 2021
- Best Places to Work in Jacksonville, Jacksonville Business Journal, 2020
- Best Places to Work in Charlotte (#8 Small Business), Charlotte Business Journal, 2019
- 2019 Best Places Work in Kentucky, Kentucky Chamber of Commerce, 2019
- Top Workplaces, Indy Star, 2019
- Best Places to Work in Jacksonville, Jacksonville Business Journal, 2019
- Best & Brightest Companies to Work For in the Nation, Best & Brightest, 2018
- Top Work Places, Indy Star, 2018
- Best Places to Work, Jacksonville Business Journal, 2018
- Best Places to Work, Charlotte Business Journal, 2018
- Best Places to Work in Kentucky (Small/Medium), Kentucky Society for Human Resource Management State Council and the Kentucky Chamber of Commerce, 2018
- Milwaukee’s 2018 Best And Brightest Companies To Work For, Milwaukee's Best and Brightest Place to Work, 2018
- Best Places to Work, Best Places to Work in Kentucky, 2017
- Best Places to Work, Best Places to Work in Kentucky, 2016
- Best Places to Work, Jacksonville Business Journal, 2016
- Top Workplaces, The Indianapolis Star, 2016
- Top Workplaces, Indianapolis Star, 2015
- Best Places to Work, Charlotte Business Journal, 2015
- Best Places to Work Atlanta, Atlanta Business Chronicle, 2014

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs