Lead Consultant – Network Segmentation & Zero Trust
About the Role
World Wide Technology (WWT) is seeking a Lead Consultant to own network segmentation and Zero Trust engagements end to end. This is an experienced individual contributor role positioned between the Sr. Consultant and the Senior Manager or Principal Consultant: you serve as the primary client interface at both the working and leadership levels, hold accountability for delivery quality and business outcomes, and act as the domain subject matter expert who provides technical credibility to both delivery and pursuit efforts.
Within WWT's pursuit teams, the Lead Consultant partners with account executives, solution architects, and practice leadership to advance qualified segmentation and Zero Trust opportunities, from architecting the solution through executing the SOW. You are equally expected to deepen relationships within existing accounts, identifying expansion opportunities where WWT's segmentation capabilities can deliver additional value, while collaborating with solution owners and stakeholders to continuously refine the service offering. Where the Sr. Consultant authors sections of a deliverable, the Lead Consultant owns the whole of it and is accountable for its quality.
This is a full-time position with a defined growth path toward the Principal Consultant or Senior Manager level. Previous consulting experience and a portfolio of client-facing deliverables are required.
Responsibilities
- Lead segmentation engagements end to end: shape scope and work plan, coordinate resources across discovery, analysis, and design workstreams, manage risk, and hold pace against the agreed schedule.
- Own the methodology on the engagement, including framing protect surfaces, defining zones and trust boundaries, setting readiness gates and decision criteria, and sequencing segmentation efforts against actual risk on a shared platform-readiness foundation.
- Set the enforcement strategy per effort, including fabric-layer enforcement, host-based workload microsegmentation, firewall-based zone enforcement, and identity- and access-driven control; substantiate the recommendation when challenged by client or partner stakeholders.
- Rationalize the segmentation-capable technology the client already owns, and justify net-new capability through documented requirements and platform validation rather than assumption.
- Account for AI systems in scope by identifying AI and machine learning workloads, including inference endpoints, retrieval pipelines, vector stores, accelerated compute, and agentic systems that hold credentials or invoke tools; document their east-west dependencies, non-human identity requirements, and trust boundaries; and reflect them in protect-surface definition, policy enforcement placement, and least-privilege recommendations, accounting for the risk introduced where agentic systems hold standing credentials or excessive tool access.
- Author and quality-assure the full client-ready deliverable set, including current-state discovery summaries, control gap and risk assessments, risk-based enterprise segmentation strategy, executable segmentation plans, and executive findings and recommendations, to a standard that consistently meets professional services requirements.
- Own deliverable review cycles through to client acceptance, partnering with the WWT Program Manager on cadence and the Principal Consultant or Senior Manager on quality.
- Review and approve major deliverables, engagement strategies, and solution approaches before they reach the client.
- Oversee multiple workstreams or engagement teams while actively developing Consultants and Sr. Consultants through coaching, structured feedback, and hands-on technical guidance.
- Own client relationships at the working and leadership levels for key segmentation engagements, acting as a senior trusted advisor across the engagement lifecycle.
- Translate complex segmentation findings into business-level recommendations; present to senior leadership and CISO/VP-level audiences; and facilitate workshops, steering committees, and program governance sessions.
- Map segmentation strategy to the regulatory drivers that shape client funding decisions, including HIPAA Security Rule (45 CFR 164.312), PCI DSS scope reduction, FFIEC and GLBA, NIST SP 800-53/800-171/800-172/800-207, NERC CIP, and ISA/IEC 62443; defend that alignment to audit and compliance stakeholders.
- Identify and develop expansion opportunities within existing accounts where segmentation, Zero Trust, OT security, and secure access capabilities can deliver additional client value.
- Serve as the segmentation and Zero Trust technical SME on pursuit teams, partnering with account and sales teams to define the engagement approach and solution architecture.
- Build Rough Order of Magnitude estimates that validate scoping, define effort levels, and establish pricing parameters for client review.
- Develop Statements of Work that articulate scope, price, deliverables, assumptions, and timelines for segmentation consulting engagements.
- Align technology partners to client requirements without ceding WWT's architectural independence.
- Drive practice maturity through reusable delivery assets, discovery and assessment frameworks, standard segmentation patterns, methodology enhancements, and segmentation thought leadership content.
- Support marketing and digital platform initiatives that drive segmentation practice visibility and pipeline generation.
Typical Deliverables
The Lead Consultant holds final authorship and quality accountability for the engagement's segmentation deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, the enterprise segmentation strategy, and a phased, executable roadmap. Approving these documents for release to the client is a defining function of the role. You are the final owner and approver of record for the deliverable set below:
- Current-State Segmentation Discovery Summary: consolidated findings across all input areas, organized by protect surface, with prioritized quick wins and gaps spanning corporate/campus, data center, cloud, and OT/IoT.
- Segmentation Control Gap & Risk Assessment: gap analysis quantifying current deficiencies and risk exposure, with protect surfaces and trust boundaries defined per effort.
- Risk-Based Enterprise Segmentation Strategy: enterprise direction, guiding principles, protect surfaces, zone definitions, and trust-boundary recommendations.
- Executable Segmentation Plan: implementation-ready plan with decision trees, estimated timelines, milestone definitions, recommended enforcement approach and tooling per effort, and next-phase prioritization, sequence, and funding inputs.
- Executive Findings & Recommendations: executive-level presentation consolidating key findings, gap analysis, strategic recommendations, and roadmap summary, presented directly to client leadership.
- Statements of Work and ROM Estimates: pursuit-stage artifacts defining scope, effort, price, deliverables, assumptions, and timelines for segmentation consulting engagements.
Growth & Development
- Maintain technical currency as segmentation, Zero Trust, and cloud enforcement models evolve, through hands-on lab work, partner roadmap engagement, and independent evaluation of emerging platforms.
- Broaden capability across the adjacent domains that determine whether a segmentation plan can be executed, including identity, endpoint and device trust, cloud architecture, and OT operations, to a depth sufficient to lead the discussion and to recognize when specialist support is required.
- Maintain working currency in AI security as the field develops, including the evolution of AI risk frameworks, the security implications of agentic and tool-calling systems, and the controls available to govern them; AI competence is expected of every consultant in the practice, independent of specialization.
- Build commercial fluency: engagement economics, margin, leverage models, and the pricing and staffing decisions that make an engagement viable.
- Develop the practice-leadership capabilities required at the Principal Consultant or Senior Manager level, including shaping service offerings, anticipating demand, expanding accounts, and developing practice capacity through structured mentoring rather than informal assistance.
- Seek and act on feedback from Principal Consultants, Senior Managers, and clients; use delivery retrospectives as a source of both individual and practice improvement.
Qualifications
- Experience: 8-12 years of experience in cybersecurity or enterprise networking with a sustained focus on segmentation and Zero Trust; must include 5+ years in a senior consulting or technical leadership role with hands-on architecture and client advisory experience.
- Demonstrated experience serving as a segmentation or Zero Trust technical SME within pursuit or sales teams, with a track record of contributing to scoping, pricing, and winning consulting engagements.
- Demonstrated experience as the lead author and final owner of client-facing security strategy and assessment documents, including assessment reports, enterprise strategies, execution plans, and executive presentations.
- Deep technical expertise across segmentation domains, including:
- Enterprise and Data Center Segmentation: next-generation firewall zone architecture; fabric-layer and overlay-based segmentation, including VXLAN/EVPN and VRF design; and east-west enforcement strategy
- Host-Based Microsegmentation: agent-based workload segmentation platforms, including policy model design, ringfencing strategy, dependency-driven policy authoring, and phased enforcement rollout
- Identity- and Access-Driven Segmentation: network access control, dynamic authorization, device trust posture, and zero trust network access
- Cloud Segmentation: cloud provider network constructs, security groups and network security groups, transit and hub-and-spoke architectures, cloud-native policy, and container and service-mesh segmentation
- OT/ICS, IoT, and IoMT Segmentation: Purdue model and IEC 62443 zone-and-conduit design; passive asset visibility and risk platforms