SKILLBRIDGE.MIL DATALAST SYNC 2026-07-24
SkillBridgeConnectby Civic HackingPrograms
Programs / Zermount, Inc.
In official directorySynced 2026-07-24

Security Architect

USAFUSAUSMCUSCGUSNUSSFCISSPAWS cert
Program summary

Zermount Inc. is seeking a Cybersecurity Architect intern/fellow who can create government solutions that will withstand even the most complex of IT and Cyber threats. We will train you to lead the architecture and design of innovative solutions and services to secure federal networks. You will coordinate with a dynamic team of thought leaders and experts to determine the right tools and methods to translate your client's IT needs and future goals into a plan that delivers secure and efficient solutions. We need to find the best solution for you to explore new methods, break free from the outdated model and go where the industry is heading. You will guide the team through a critical approach to network design, suggesting alternatives and tweaking solutions to maintain a balance between security and mission needs. Your technical expertise will be vital as you help clients overcome their toughest challenges with cutting-edge technologies and cybersecurity domains. Join our team as we address cybersecurity challenges and build capabilities to deliver solutions and service offerings using investments and proven capabilities.

Roles & job description

Roadmap and StrategyProvide input to the Cybersecurity roadmap and strategy for key organization strategic initiatives for the following and related areas:Security Architecture: Develop and Recommend Security Architecture and Standards including Cloud Security for government approval.Cybersecurity Operations: Improve Cloud monitoring, detection, and response; Improve Security Operations (SOC) operations.Privacy & Continuous Monitoring: Improve Vulnerability Assessment program; Integrate security scanning in Cloud Pipeline; Improve Cloud vulnerability coverage and scanning.Cybersecurity Authorizations and Compliance: Reduce time to ATO through continuous ATO; Improve Cloud Compliance.Executive Order (EO) 14028 "Improving the Nation's Cybersecurity" in terms of: Implementing Zero Trust; Enhancing Supply Chain Risk Management (SCRM); Addressing critical software; and Developing secure Cloud adoption.Security Architecture ReviewsDevelop, and integrate with other Cybersecurity workflow to include: ATO Intake, assessment, and Vulnerability Scanning process.Integrate with Enterprise Architecture (EA) review process.Perform security reviews based on RMF controls compliance, clients, and security best practices.Develop security architectural patterns to enable faster ATO or assessment process by creating architectural designs that already meet compliance controls.Develop Security Architecture Standards in Cybersecurity SharePoint site and cross-link with Cloud Operations (SSB) and Enterprise Architecture (EA) sites.Provide security input on Cloud Center of Excellence (CCOE) and Cloud Advisory Council (CAC) agenda items by participating in technical working groups, providing security analysis, and providing recommendations.Provide security architecture input for DevSecOps security strategy and roadmap including application and infrastructure vulnerability scanning, automated assessments, and security controls.Research, document, and publish a Cloud Security Codex to include security best practices based on security architecture patterns or Cloud services guidance's such as security configuration or use-cases and design.Recommends security requirements, architectural direction, and assists in pilot testing of key enterprise-wide initiatives to include:Zero Trust Architecture (ZTA),Secure Access Service Edge (SASE) including Cloud Access Security Broker (CASB),Zero Trust Network Access (ZTNA),Secure Web Gateway (SWG)Trusted Internet Connection (TIC) 3.0Identity, Credential, and Access Management (ICAM) - OKTAConfiguration Management Database (CMDB).Evaluate a subset of the agency's High Value Asset (HVA) security posture to determine whether the agency has properly architected its cybersecurity solutions and provides agency leadership the risks inherent in the implemented cybersecurity solution.Performs architecture design reviews including configuration and log reviews and perform network traffic analyses.Produces a SAR Report to include HVAs architecture strengths and findings.Cloud Security EngineeringDrive the pilot and adoption of Cloud Security Posture Management (CSPM).Design and deploy native Cloud security services in AWS, Microsoft Azure, and Google Cloud.Perform proof of value of Cloud-native, COTS, 3rd party, or opensource security capabilities by hands-on deploying and evaluating against security requirements.Lead the development of scripts or code to perform Cloud Security assessments through Cloud native API or SDK.Lead the development of enterprise cloud security blueprints to include security in Infrastructure as Code (IaC templates).Research new and emerging security practices and capabilities such as AI/ML to address compliance and mitigate security risk.System Security Engineering (SSE)Collaborate with the CyberOps Branch to improve Cloud Security monitoring to include ingestion of logs such as: API, application/database, and flow logs into SIEM; and improve Cloud SME on Cloud log analysis to analyze, create, and tune Cloud events to increase coverage and alerting in the Cloud.Collaborate with the Privacy and Continuous Monitoring Branch to increase Cloud vulnerability coverage in the areas of Operating System (OS), application code, and Infrastructure level; and develop architecture for integrating findings into a centralized dashboard that allows product owners direct access to team's specific systems or cloud account findings.Collaborate with the Cybersecurity Authorizations and Compliance Branch to provide input on designing compliance systems that perform continuous ATO process to decrease the processing lead times of current ATO process; provide responses on data calls; and participate in working groups in order to collaborate and share technical knowledge.Identify security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle.Ensure the team provides system engineering and architectural design support services to include Studies and analysis of proposed operations modifications; End-to-end architecture tradeoff assessment; Development of strategic and tactical plans; Evaluation of new program requirements; and Investigation and development of new technologies for possible operations modifications.

Eligibility notes

The candidate must have a:Certified Information Systems Security Professional (CISSP), andAt least one of the following, or equivalent:Certified Cloud Security Professional (CCSP),AWS Certified Solutions Architect Associate,AWS Certified Security Specialist,Microsoft Azure Solutions Architect,Google Professional Cloud Architect.

Additional notes

Hybrid - primarily remote. Occasional times that the team could be asked to report to the office locations in Alexandria and Arlington, VA.

Candidate reviews

No reviews yet. Reviews unlock for candidates 30 days after adding this program to their tracker — integrity over volume.

Interview prep for this program
Ask them
  • ▸ "How many of your past SkillBridge interns received full-time offers?" — a serious program knows the number.
  • ▸ "Who will my day-to-day mentor be, and what does week one look like?"
  • ▸ "The listing says 1 - 30 days — can that flex to my approved window if my command shortens it?"
  • ▸ "Is relocation expected for a full-time offer, or can I convert where I am?"
  • ▸ Confirm the eligibility notes above — ask exactly what they need from you and when.
Bring to the conversation
  • ✓ Your projected start window and separation date (from your profile)
  • ✓ Your command's approval status — even "packet drafted" signals you're serious
  • ✓ Your civilian-translated resume bullets (generate them here)
  • ✓ A written training-plan ask — you'll need it for your packet anyway
More from Zermount, Inc.