Qualifications Experience 8–12 years of experience in cybersecurity or enterprise networking with a sustained focus on segmentation and Zero Trust; must include 5+ years in a senior consulting or technical leadership role with hands-on architecture and client advisory experience. Demonstrated experience serving as a segmentation or Zero Trust technical SME within pursuit or sales teams, with a track record of contributing to scoping, pricing, and winning consulting engagements. Demonstrated experience as the lead author and final owner of client-facing security strategy and assessment documents, including assessment reports, enterprise strategies, execution plans, and executive presentations. Deep technical expertise across segmentation domains, including: Enterprise and Data Center Segmentation: next-generation firewall zone architecture; fabric-layer and overlay-based segmentation, including VXLAN/EVPN and VRF design; and east-west enforcement strategy Host-Based Microsegmentation: agent-based workload segmentation platforms, including policy model design, ringfencing strategy, dependency-driven policy authoring, and phased enforcement rollout Identity- and Access-Driven Segmentation: network access control, dynamic authorization, device trust posture, and zero trust network access Cloud Segmentation: cloud provider network constructs, security groups and network security groups, transit and hub-and-spoke architectures, cloud-native policy, and container and service-mesh segmentation OT/ICS, IoT, and IoMT Segmentation: Purdue model and IEC 62443 zone-and-conduit design; passive asset visibility and risk platforms; and the brownfield constraints that limit enforcement options Discovery and Dependency Mapping: flow collection and analysis, application dependency mapping, and translating observed traffic and dependencies into segmentation policy and zone design Working knowledge of Zero Trust architecture and maturity models: NIST SP 800-207, the CISA Zero Trust Maturity Model (ZTMM), the DoD Zero Trust Reference Architecture, and protect-surface methodology. Working knowledge of the frameworks and regulatory drivers that shape segmentation: NIST CSF 2.0, NIST SP 800-53 (SC and AC control families), NIST SP 800-171/172, PCI DSS v4 segmentation and scoping, HIPAA Security Rule, ISA/IEC 62443, NERC CIP, and FFIEC/GLBA. Practical understanding of the adjacent domains that determine whether a segmentation plan is executable: identity and access management, endpoint and device trust, asset management and CMDB hygiene, change management and operational readiness, and the shared platform foundations segmentation depends on. Preferred: experience leading segmentation programs across financial services, healthcare, manufacturing, retail, energy, or public sector, particularly where segmentation intersects with regulatory scrutiny (HIPAA, PCI DSS, NERC CIP, DORA); and experience with OT/ICS, IoT, and IoMT environments and the operational constraints that shape segmentation in those environments. Preferred: contributions to segmentation or Zero Trust thought leadership through white papers, conference presentations, or intellectual property; and experience with adjacent drivers of segmentation work, including M&A network integration, data center or cloud migration, PCI scope reduction, and post-incident segmentation remediation. Certifications desired: CISSP, CISSP-ISSAP, CISM, CRISC, or CCSP; ISA/IEC 62443 is a plus for OT-adjacent work. Specialized Knowledge, Skills & Abilities Working knowledge and consulting experience in at least five of the following areas: Enterprise Segmentation and associated technologies Zero Trust Architectures including ZTMM (Zero Trust Maturity Model) Network and Systems Security Cloud Security and Cloud Network Architecture Operational Technologies and Environments (OT/ICS, IoT, IoMT) Risk Management and Assessments Policy, Governance, and Compliance Identity and Access Management Data Protection and Privacy Security Operations Demonstrated consulting delivery competencies, including: Structured discovery and assessment: design and execute current-state discovery across corporate/campus, data center, cloud, and OT/IoT environments; run stakeholder interviews and technical SME sessions; and synthesize findings into clearly structured, actionable outputs. Gap analysis and maturity evaluation: assess and communicate segmentation maturity across technology, process, governance, and organizational readiness dimensions against recognized frameworks; prioritize findings by business and security risk. Executive communication: translate complex segmentation findings into clear, concise narratives for CISO and senior leadership audiences; adapt message depth and framing to technical and business stakeholders. Workshop facilitation: design and lead executive workshops, program kickoffs, cross-functional discovery sessions, and technical design sessions; drive alignment among stakeholders with competing priorities. Roadmap and program planning: develop phased segmentation roadmaps with initiative prioritization, dependency mapping, ROM estimates, and milestone sequencing aligned to client business constraints and risk objectives. Deliverable excellence: consistent track record of producing client-ready segmentation deliverables, including assessments, gap and risk registers, enterprise strategies, executable plans, and executive readouts, that meet professional services quality standards. Stakeholder and engagement management: manage complex, multi-stakeholder engagements; navigate competing priorities, set and manage expectations, escalate risks appropriately, and sustain client trust through ambiguity. Practice development: develop, maintain, and enhance segmentation service offerings, including methodologies, marketing content, deliverable templates, and practice capabilities. Sales and pipeline management: identify, shape, and drive segmentation opportunities from initial discussions through proposals, SOW, fee estimation, level of effort, margins, leveraged team structures, and deal closure. Professional Attributes Professional writing is required : strong, demonstrable ability to produce and approve technical and business-related artifacts at a client-deliverable standard. Able to manage concurrent engagements and workstreams in complex environments under shifting priorities and timelines. Able to communicate and modify approach, language, and style across audiences, from technical SMEs to CISO, VP, and CxO-level stakeholders. Collaborative, with the ability to manage conflicting interests across client stakeholders, technology partners, and internal teams, and to operate effectively amid ambiguity. Commercially aware, with sound judgment on scope, effort, margin, and staffing. Self-directed and proactive, with strong problem-solving instincts and intellectual curiosity about evolving technology. Professional Behaviors Beyond technical delivery, this role is expected to demonstrate the following in front of clients and within the WWT team: Ownership and accountability : take responsibility for engagement outcomes and for the quality of every deliverable released under your approval, and follow through on commitments without being chased. Trusted advisor : build credibility quickly at both the working and executive levels, give candid and well-reasoned recommendations, and represent WWT as a partner the client relies on rather than an order-taker. Clear communication : translate technical complexity into plain language for the audience at hand, listen actively, and keep stakeholders informed without surprises. Developing others : treat mentoring as part of the role rather than an addition to it, and hold junior consultants to the standard applied to your own work. Integrity : give honest assessments even when the message is hard, and protect the client’s interests and WWT’s reputation in every recommendation. Want to learn more about Consulting & Security Services? Check us out on our platform: https://www.wwt.com/consulting-services https://www.wwt.com/category/security-transformation Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $137,200 to $171,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay. The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees: Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program Note: This is not an all-encompassing list and should not be used as a complete description of the plan’s benefits. For more information, see our US benefits website at wwt.com/us-benefits. We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for all! If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process. World Wide Technology is an Equal Opportunity Employer. If you have any questions or concerns about this posting, please email [email protected] . #LI-TB1 Why WWT? World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe. Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)—a collaborative ecosystem featuring state-of-the-art hardware and software—WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distributions capabilities. With more than 14,000 team members and over 60 locations globally, WWT's culture—grounded in core values and leadership philosophies—has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada. Want to work with highly motivated individuals on high-performance teams? Join WWT today! What is the Solutions Consulting & Engineering (SC&E) Team and why join? Solutions Consulting & Engineering is an organization that is Customer Focused and Solutions Led. We deliver end-to-end and emerging solutions to drive customer satisfaction, increase profitability and growth. Our success is enabled by our world-class management consulting, delivery excellence and engineering brilliance. Our goal is to bring together business acumen with full-stack technical know-how to develop innovative solutions for our clients' most complex challenges. Position Overview: World Wide Technology (WWT) is seeking a Lead Consultant to own network segmentation and Zero Trust engagements end to end. This is an experienced individual contributor role positioned between the Sr. Consultant and the Senior Manager or Principal Consultant: you serve as the primary client interface at both the working and leadership levels, hold accountability for delivery quality and business outcomes, and act as the domain subject matter expert who provides technical credibility to both delivery and pursuit efforts. Within WWT’s pursuit teams, the Lead Consultant partners with account executives, solution architects, and practice leadership to advance qualified segmentation and Zero Trust opportunities, from architecting the solution through executing the SOW. You are equally expected to deepen relationships within existing accounts, identifying expansion opportunities where WWT’s segmentation capabilities can deliver additional value, while collaborating with solution owners and stakeholders to continuously refine the service offering. Where the Sr. Consultant authors sections of a deliverable, the Lead Consultant owns the whole of it and is accountable for its quality. This is a full-time position with a defined growth path toward the Principal Consultant or Senior Manager level. Previous consulting experience and a portfolio of client-facing deliverables are required. Key Responsibilities Lead segmentation engagements end to end : shape scope and work plan, coordinate resources across discovery, analysis, and design workstreams, manage risk, and hold pace against the agreed schedule. Own the methodology on the engagement , including framing protect surfaces, defining zones and trust boundaries, setting readiness gates and decision criteria, and sequencing segmentation efforts against actual risk on a shared platform-readiness foundation. Set the enforcement strategy per effort , including fabric-layer enforcement, host-based workload microsegmentation, firewall-based zone enforcement, and identity- and access-driven control; substantiate the recommendation when challenged by client or partner stakeholders. Rationalize the segmentation-capable technology the client already owns , and justify net-new capability through documented requirements and platform validation rather than assumption. Account for AI systems in scope by identifying AI and machine learning workloads, including inference endpoints, retrieval pipelines, vector stores, accelerated compute, and agentic systems that hold credentials or invoke tools; document their east-west dependencies, non-human identity requirements, and trust boundaries; and reflect them in protect-surface definition, policy enforcement placement, and least-privilege recommendations, accounting for the risk introduced where agentic systems hold standing credentials or excessive tool access. Author and quality-assure the full client-ready deliverable set , including current-state discovery summaries, control gap and risk assessments, risk-based enterprise segmentation strategy, executable segmentation plans, and executive findings and recommendations, to a standard that consistently meets professional services requirements. Own deliverable review cycles through to client acceptance , partnering with the WWT Program Manager on cadence and the Principal Consultant or Senior Manager on quality. Review and approve major deliverables , engagement strategies, and solution approaches before they reach the client. Oversee multiple workstreams or engagement teams while actively developing Consultants and Sr. Consultants through coaching, structured feedback, and hands-on technical guidance. Own client relationships at the working and leadership levels for key segmentation engagements, acting as a senior trusted advisor across the engagement lifecycle. Translate complex segmentation findings into business-level recommendations ; present to senior leadership and CISO/VP-level audiences; and facilitate workshops, steering committees, and program governance sessions. Map segmentation strategy to the regulatory drivers that shape client funding decisions , including HIPAA Security Rule (45 CFR 164.312), PCI DSS scope reduction, FFIEC and GLBA, NIST SP 800-53/800-171/800-172/800-207, NERC CIP, and ISA/IEC 62443; defend that alignment to audit and compliance stakeholders. Identify and develop expansion opportunities within existing accounts where segmentation, Zero Trust, OT security, and secure access capabilities can deliver additional client value. Serve as the segmentation and Zero Trust technical SME on pursuit teams , partnering with account and sales teams to define the engagement approach and solution architecture. Build Rough Order of Magnitude estimates that validate scoping, define effort levels, and establish pricing parameters for client review. Develop Statements of Work that articulate scope, price, deliverables, assumptions, and timelines for segmentation consulting engagements. Align technology partners to client requirements without ceding WWT’s architectural independence. Drive practice maturity through reusable delivery assets, discovery and assessment frameworks, standard segmentation patterns, methodology enhancements, and segmentation thought leadership content. Support marketing and digital platform initiatives that drive segmentation practice visibility and pipeline generation. Typical Deliverables The Lead Consultant holds final authorship and quality accountability for the engagement’s segmentation deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, the enterprise segmentation strategy, and a phased, executable roadmap. Approving these documents for release to the client is a defining function of the role. You are the final owner and approver of record for the deliverable set below: Current-State Segmentation Discovery Summary: consolidated findings across all input areas, organized by protect surface, with prioritized quick wins and gaps spanning corporate/campus, data center, cloud, and OT/IoT. Segmentation Control Gap & Risk Assessment: gap analysis quantifying current deficiencies and risk exposure, with protect surfaces and trust boundaries defined per effort. Risk-Based Enterprise Segmentation Strategy: enterprise direction, guiding principles, protect surfaces, zone definitions, and trust-boundary recommendations. Executable Segmentation Plan: implementation-ready plan with decision trees, estimated timelines, milestone definitions, recommended enforcement approach and tooling per effort, and next-phase prioritization, sequence, and funding inputs. Executive Findings & Recommendations: executive-level presentation consolidating key findings, gap analysis, strategic recommendations, and roadmap summary, presented directly to client leadership. Statements of Work and ROM Estimates: pursuit-stage artifacts defining scope, effort, price, deliverables, assumptions, and timelines for segmentation consulting engagements. Growth & Development Maintain technical currency as segmentation, Zero Trust, and cloud enforcement models evolve, through hands-on lab work, partner roadmap engagement, and independent evaluation of emerging platforms. Broaden capability across the adjacent domains that determine whether a segmentation plan can be executed, including identity, endpoint and device trust, cloud architecture, and OT operations, to a depth sufficient to lead the discussion and to recognize when specialist support is required. Maintain working currency in AI security as the field develops, including the evolution of AI risk frameworks, the security implications of agentic and tool-calling systems, and the controls available to govern them; AI competence is expected of every consultant in the practice, independent of specialization. Build commercial fluency: engagement economics, margin, leverage models, and the pricing and staffing decisions that make an engagement viable. Develop the practice-leadership capabilities required at the Principal Consultant or Senior Manager level, including shaping service offerings, anticipating demand, expanding accounts, and developing practice capacity through structured mentoring rather than informal assistance. Seek and act on feedback from Principal Consultants, Senior Managers, and clients; use delivery retrospectives as a source of both individual and practice improvement.
Senior Network Engineer Cloud Infrastructure & Zero Trust
Restonconsultinggroup
Senior Professional Services Consultant - Zero Trust Cloud Specialist
Zscaler
Senior Cyber Security Architect - SME - Architecture/Zero Trust Lead
QBE LLC
Zero Trust Engineer (R-00205)
True Zero Technologies
Principal Zero Trust Architect (R-00204)
True Zero Technologies
Cloud Security & Zero Trust Architect
ERP International