> Markdown version of [/jobs/ext/624437-network-security-zero-trust-architect](https://www.wearedevelopers.com/jobs/ext/624437-network-security-zero-trust-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security & Zero Trust Architect - **Company:** The C.A.S.E. Engineering Group - **Location:** Washington, DC, United States - **Salary:** $120,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Access Control List, Cloud Computing Security, CompTIA Security+, Cyber Security, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Network Security, Network Segmentation, Remote Access Technology, Zero Trust Network Access, Security Information and Event Management, Traffic Analysis, Data Logging, Firewalls (Computer Science), Information Technology, Palo Alto Networks, Fortinet, Cisco - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6868ad90eb9c341d ## About the Role Do you have experience in Zero trust architecture design?, Do you have a Bachelor's degree?, Education & Certification * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred (or equivalent experience) * Certified Information Systems Security Professional (CISSP) certification required * One or more of the following strongly preferred: Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT); GIAC Defensible Security Architecture (GDSA); a vendor network-security certification (e.g., Palo Alto Networks PCNSE, Cisco CCNP Security, or Fortinet NSE); CompTIA Security+; ITIL 4 Foundation Experience * At least 10 years of progressive experience in network security and security architecture * Hands-on expertise auditing multi-vendor firewall and segmentation environments and identifying over-permissioning and trust-boundary gaps * Demonstrated experience designing Zero Trust target states and segmentation roadmaps in large, complex enterprise environments; federal experience preferred * Proven track record translating security posture into measurable findings and actionable recommendations Technical Expertise * Multi-vendor firewall and segmentation platforms (e.g., Palo Alto Networks, Cisco, Fortinet) * Firewall rulebase, ACL, and trust-boundary review, including detection of over-permissioning * Network segmentation and microsegmentation, and east-west traffic analysis * Zero Trust architecture aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model * Security telemetry, logging, SIEM, and endpoint posture assessment * VPN, secure remote access, and secure connectivity design * Working knowledge of federal security frameworks (e.g., NIST SP 800-53, Risk Management Framework, and FISMA) Additional Skills * Excellent written and verbal communication, including briefing senior leadership and federal stakeholders * Ability to translate security risk for both technical and executive audiences * Strong documentation discipline and attention to detail * Strong analytical, problem-solving, and risk-identification skills * Effective at collaborating with cross-functional teams to align technical work with program outcomes * Adaptability in a fast-paced, evolving environment with shifting priorities Clearance * Must be a U.S. citizen and be able to obtain a federal background investigation ## Description This position supports a mission-critical federal program focused on enterprise IT portfolio rationalization, modernization, and governance within a federal agency's Office of the Chief Information Officer (OCIO). Our team discovers, documents, and rationalizes a large and complex enterprise IT estate - spanning networks, infrastructure, applications, data, and identity - to establish an authoritative baseline and chart a clear path toward a consolidated, well-governed target state. We seek professionals who are not only technically proficient but also adaptable, analytical, and dedicated to excellence, ensuring that we continue to provide our clients with the best expertise available., The Network Security & Zero Trust Architect serves as the authoritative technical lead for assessing the enterprise security posture and charting its path toward Zero Trust. This role examines firewall rulebases, access controls, and trust boundaries; maps east-west traffic and segmentation; and frames the target state and roadmap that move the organization from an assumed security posture to a measurable one. The architect partners closely with the network, identity, cloud, and enterprise architecture teams to ensure security is built into the modernization and consolidation effort rather than bolted on, aligning the approach to the federal Zero Trust mandate. This is a full-time, onsite role based in Washington, D.C., requiring availability during normal business hours, with occasional night and weekend work as needed based on program demands. The Network Security & Zero Trust Architect works closely with executive leadership and cross-functional engineering teams across network, identity, cloud, data, and enterprise architecture, and supports governance processes and milestone reviews throughout the program. Key Responsibilities * Audit firewall rulebases, access control lists (ACLs), and trust boundaries to identify gaps and over-permissioning * Map east-west traffic and microsegmentation against Zero Trust pillars * Assess security telemetry, logging, and endpoint posture coverage across the environment * Frame the Zero Trust target state and the practical segmentation path to reach it * Develop a defensible Zero Trust roadmap aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model * Partner with network, identity, cloud, and enterprise architecture teams so security findings align with consolidation and modernization objectives * Translate security discovery into clear, measurable findings and prioritized recommendations * Produce professional-grade security architecture artifacts, diagrams, and documentation * Support governance processes, technical reviews, and milestone gates, and brief findings to leadership and federal stakeholders * Identify opportunities for risk reduction and continuous improvement in partnership with the broader team ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)