ZERO TRUST APPLICATIONS AND WORKLOADS SME

Hiring Our Heroes
Arlington, VA

Job Description

Job Description

ZERO TRUST APPLICATIONS AND WORKLOADS SME

MILITARY FRIENDLY & PREFERRED - HOH SPONSOR

Zermount Inc. is seeking a Zero Trust (ZT) Applications and Workloads SME to assist in providing security to one of our federal clients. The ZT Applications and Workloads SME will be part of the implementation of ZT principles across the pillars of ZT (identity, device, network, application and workload, and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The ZT Applications and Workloads SME will be responsible for leading the design, development, and assessment of virtualization and application security solutions in alignment with Zero Trust principles. You will collaborate with cross-functional teams to understand business requirements and translate them into secure and scalable technical solutions. Your expertise in virtualization technologies, application development, cloud security, and Zero Trust principles will be crucial in ensuring the organization's systems and applications are resilient, secure, and compliant.

Duties & Responsibilities:

The ZT Applications and Workloads SME will ensure the Zermount ZT solutions and services secure federal networks and meet the objectives of EO 14028 and other Federal requirements. Additionally, the ZT Applications and Workloads SME will provide support and services to include:

  • Lead the design, development, and implementation of applications and workloads solutions aligned with Zero Trust principles.
  • Support the architecture and design of innovative solutions and services to secure client networks, and provide leadership with recommendations on the right technologies, solutions, and processes required to meet the objectives of EO 14028 and other Federal requirements.
  • Map ZT capabilities, requirements, and existing client capabilities, and new or approved capabilities required for the applications and workloads pillar as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, EO's, and standards.
  • Collaborate with cross-functional teams to understand business requirements and translate them into technical solutions.
  • Provide expertise for the secure development of applications, ensuring that security is integrated into the Software Development Lifecycle (SDLC) from the beginning and driving DevSecOps practices.
  • Provide expertise for segmenting workloads to isolate them from each other, reducing the attack surface and minimizing the impact of potential breaches.
  • Provides expertise for establishing continuous monitoring solutions and capabilities to detect and respond to anomalies and potential security threats within applications and workloads.
  • Provides expertise to ensure the secure integration of applications and workloads across various environments (e.g., cloud, on premises, and hybrid).
  • Provide expertise in the review, assessment, and solution recommendation for Zero Trust maturity evaluations.
  • Stay up to date with emerging technologies and industry trends related to application security, application access controls, application threat protections, and secure application development.
  • Provide technical guidance and mentorship to junior team members. 

Qualifications:

  • A minimum of 10 years of IT cybersecurity experience including direct support for the US Government and 7 years acting as an ISSO, assessor, or compliance analyst for enterprise IT systems OR a relevant Bachelor's degree in IT, computer science, or engineering and 7 years of IT cybersecurity experience including direct support for the US Government and 5 years acting as an ISSO, assessor, or compliance analyst.
  • Solid experience in virtualization technologies, such as VMware, Hyper-V, or KVM. 
  • Strong understanding of Zero Trust principles and their application in virtualization and application development. 
  • Knowledge of containerization technologies like Docker and orchestration tools like Kubernetes. 
  • Familiarity with cloud platforms and services, such as AWS, Azure, or Google Cloud. 
  • Experience implementing security controls and best practices in virtualized environments and application development.
  • Ability to troubleshoot and resolve issues in virtualization, cloud, and application deployment. 
  • Strong communication and collaboration abilities. 
  • Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers.
  • Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures.
  • Excellent communication, collaboration, and problem-solving skills.
  • Knowledge of NIST Guidelines and FISMA Cybersecurity compliance requirements.
  • Technical knowledge of complex enterprise IT systems.
  • Knowledge and experience using relevant cybersecurity and analysis tools such as Archer, Nessus Security Center, Splunk, etc.
  • Ability to work independently and as part of a team.
  • Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact.
  • Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact.

Zero Trust Specific Qualifications: System Maturity Model

  • Application Access
    • Demonstrated experience in automating application access decisions with enhanced contextual information and enforced expiration conditions to ensure adherence to the principle of least privilege.
    • Proven track record in automating application access decisions with expanded contextual information and enforced expiration conditions to adhere to the principle of least privilege.
    • Strong background in establishing an environment that continuously authorizes application access, incorporating real-time risk analytics and considering factors such as behavior or usage patterns.
  • Application Threat Protections:
    • Extensive experience in implementing advanced threat protections into all application workflows, providing real-time visibility and monitoring.
  • Accessible Applications:
    • Successful track record in delivering all relevant applications over open public networks to authorized users and devices, ensuring accessibility as needed.
    • Secure Application Development and Deployment Workflow:
    • Proficient in utilizing immutable workloads wherever feasible, allowing changes to be effective only through redeployment, and eliminating administrator access to deployment environments by leveraging automated processes for code deployment.
  • Application Security Testing:
    • Expertise in integrating application security testing throughout the software development lifecycle across the entire enterprise, including routine automated testing of deployed applications.

Education:

  • Minimum of a Bachelor's Degree in one of the following: Information Technology (IT), computer science, management, business administration, or a related field.
    • Relevant years of experience may be used in substitution for situations where the candidate does not have a Bachelor's degree in the required field.

Certifications:

  • At least one of the following security certifications:
    • Certified Authorization Professional (CAP);
    • Certified Information Systems Security Officer (CISSO);
    • Certified Information Security Manager (CISM); or
    • Certified Information Systems Security Professional (CISSP).
  • Relevant certifications in virtualization technologies (e.g., VMware Certified Professional) and application development (e.g., AWS Certified Developer, Microsoft Certified: Azure Developer Associate) are a plus.

Clearance level :

  • Minimum of an active Secret Clearance .

Work Location :

  • Remote.
Posted 2025-07-25

Recommended Jobs

Aviation Planner - Mid Level

HNTB
Arlington, VA

What We're Looking For It is an exciting time to join HNTB’s aviation planning practice! We are looking for a highly motivated candidate with excellent analytical and communication skills and a pa…

View Details
Posted 2025-07-27

DoD Authorization to Operate (ATO) Specialists

Peraton
Alexandria, VA

Program Overview Supports the transformation and modernization of legacy Coast Guard systems and services including mobility, messaging, ITSM, ITAM, Network Infrastructure, and legacy data systems…

View Details
Posted 2025-07-31

Welder Fabricator

Aerotek
Fredericksburg, VA

Job Description Job Description Description The candidate will be performing primarily MIG welding and Fabricating various metals. Must have schooling or OTJ experience in both. Responsibilite…

View Details
Posted 2025-07-28

Case Manager Sailor Assistance and Intercept for Life (SAIL)

International SOS Government Medical Services
Richmond, VA

Job Description Job Description Company Description International SOS delivers customized medical and security risk management and wellbeing solutions to enable our clients to operate safely…

View Details
Posted 2025-07-26

SUD Counselor - Jail Based Services

Hampton-Newport News Community Services Board
Hampton, VA

Job Description Job Description Substance Use Disorder Counselor - Jail Based Services Annual Salary: $54,371 with $2,000 Sign-on Bonus Work Schedule: Monday-Friday, 8:30 am to 5:00 pm J…

View Details
Posted 2025-07-26

ELECTRIC SERVICE TECHNICIAN

City of Martinsville
Martinsville, VA

JOB TITLE: ELECTRIC SERVICE TECHNICIAN DEPARTMENT: ELECTRIC REPORTS TO: LINE CREW SUPERVISOR OR SUBSTATION/METERING SUPERVISOR CLASSIFICATION: GRADE 11 FLSA STATUS: NON-EXEMPT RATE OF P…

View Details
Posted 2025-07-31

Remote Notary Specialist

Certified Mobile Notary Service
Virginia Beach, VA

JOB TYPE: Full-time RESPONSIBILITIES: - Execute assigned processes, such as signing loan documents, prepare affidavits, organize physical/electronic files, answer email correspondence, and commun…

View Details
Posted 2025-07-27

Experienced Commercial Door and Dock Technician

DuraServ Corp
Sterling, VA

Job Description Job Description Overview Are you coachable, accountable, and a safety-focused team player with an optimistic outlook? Do you want to provide new and creative input to help the …

View Details
Posted 2025-07-24