ZERO TRUST APPLICATIONS AND WORKLOADS SME

Remote Full-time
About the position

Zermount Inc. is seeking a Zero Trust (ZT) Applications and Workloads SME to assist in providing security to one of our federal clients. The ZT Applications and Workloads SME will be part of the implementation of ZT principles across the pillars of ZT (identity, device, network, application and workload, and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The ZT Applications and Workloads SME will be responsible for leading the design, development, and assessment of virtualization and application security solutions in alignment with Zero Trust principles. You will collaborate with cross-functional teams to understand business requirements and translate them into secure and scalable technical solutions. Your expertise in virtualization technologies, application development, cloud security, and Zero Trust principles will be crucial in ensuring the organization's systems and applications are resilient, secure, and compliant.

Responsibilities
• Lead the design, development, and implementation of applications and workloads solutions aligned with Zero Trust principles.
• Support the architecture and design of innovative solutions and services to secure client networks, and provide leadership with recommendations on the right technologies, solutions, and processes required to meet the objectives of EO 14028 and other Federal requirements.
• Map ZT capabilities, requirements, and existing client capabilities, and new or approved capabilities required for the applications and workloads pillar as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, EO's, and standards.
• Collaborate with cross-functional teams to understand business requirements and translate them into technical solutions.
• Provide expertise for the secure development of applications, ensuring that security is integrated into the Software Development Lifecycle (SDLC) from the beginning and driving DevSecOps practices.
• Provide expertise for segmenting workloads to isolate them from each other, reducing the attack surface and minimizing the impact of potential breaches.
• Provides expertise for establishing continuous monitoring solutions and capabilities to detect and respond to anomalies and potential security threats within applications and workloads.
• Provides expertise to ensure the secure integration of applications and workloads across various environments (e.g., cloud, on premises, and hybrid).
• Provide expertise in the review, assessment, and solution recommendation for Zero Trust maturity evaluations.
• Stay up to date with emerging technologies and industry trends related to application security, application access controls, application threat protections, and secure application development.
• Provide technical guidance and mentorship to junior team members.

Requirements
• A minimum of 10 years of IT cybersecurity experience including direct support for the US Government and 7 years acting as an ISSO, assessor, or compliance analyst for enterprise IT systems OR a relevant Bachelor's degree in IT, computer science, or engineering and 7 years of IT cybersecurity experience including direct support for the US Government and 5 years acting as an ISSO, assessor, or compliance analyst.
• Solid experience in virtualization technologies, such as VMware, Hyper-V, or KVM.
• Strong understanding of Zero Trust principles and their application in virtualization and application development.
• Knowledge of containerization technologies like Docker and orchestration tools like Kubernetes.
• Familiarity with cloud platforms and services, such as AWS, Azure, or Google Cloud.
• Experience implementing security controls and best practices in virtualized environments and application development.
• Ability to troubleshoot and resolve issues in virtualization, cloud, and application deployment.
• Strong communication and collaboration abilities.
• Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers.
• Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures.
• Excellent communication, collaboration, and problem-solving skills.
• Knowledge of NIST Guidelines and FISMA Cybersecurity compliance requirements.
• Technical knowledge of complex enterprise IT systems.
• Knowledge and experience using relevant cybersecurity and analysis tools such as Archer, Nessus Security Center, Splunk, etc.
• Ability to work independently and as part of a team.
• Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact.
• Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact.
• Demonstrated experience in automating application access decisions with enhanced contextual information and enforced expiration conditions to ensure adherence to the principle of least privilege.
• Proven track record in automating application access decisions with expanded contextual information and enforced expiration conditions to adhere to the principle of least privilege.
• Strong background in establishing an environment that continuously authorizes application access, incorporating real-time risk analytics and considering factors such as behavior or usage patterns.
• Extensive experience in implementing advanced threat protections into all application workflows, providing real-time visibility and monitoring.
• Successful track record in delivering all relevant applications over open public networks to authorized users and devices, ensuring accessibility as needed.
• Proficient in utilizing immutable workloads wherever feasible, allowing changes to be effective only through redeployment, and eliminating administrator access to deployment environments by leveraging automated processes for code deployment.
• Expertise in integrating application security testing throughout the software development lifecycle across the entire enterprise, including routine automated testing of deployed applications.
• Minimum of a Bachelor's Degree in one of the following: Information Technology (IT), computer science, management, business administration, or a related field.
• At least one of the following security certifications: Certified Authorization Professional (CAP); Certified Information Systems Security Officer (CISSO); Certified Information Security Manager (CISM); or Certified Information Systems Security Professional (CISSP).
• Minimum of an active Secret Clearance.
• Ability to pass a minimum background investigation.

Nice-to-haves
• Relevant certifications in virtualization technologies (e.g., VMware Certified Professional) and application development (e.g., AWS Certified Developer, Microsoft Certified: Azure Developer Associate) are a plus.

Apply tot his job

Apply To this Job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Search Engine Optimisation Intern

Remote

Telephonic Nurse Case Manager (Remote)

Remote

**Mental Health Customer Service Representative III – Empathetic and Solutions-Focused Advocate for Patients and Healthcare Providers**

Remote

**Experienced Full Stack Customer Service Representative – Remote Customer Support**

Remote

Customer Service (remote work , no vaccination required)

Remote

Cybersecurity IAM Engineer-REMOTE

Remote

Experienced Remote Customer Service Agent - Work with Top Brands like Peloton, Coach, and Carnival Cruises

Remote

**Experienced Part-Time Remote Amazon Chat Representative – Unlock a Rewarding Career in E-commerce Customer Support**

Remote

**Experienced Full Stack Customer Service Representative – Remote USA Position at blithequark**

Remote

IT Audit Analyst

Remote
← Back