Zero Trust Engineer Mid Level
$135k - $155kCELESTIAL INNOVATIONS GROUP LLC
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Opportunity for advancement
- Paid time off
- Training & development
- Vision insurance
POSITION SUMMARY
Celestial Innovations Group (CIG) is seeking a Zero Trust Architecture Engineer to own end-to-end access policy design across the identity, endpoint, network, and application layers for federal agency clients, spanning the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform, guided by the principle of “never trust, always verify.” The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model and Secure Access Service Edge (SASE) guidance.
These responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, acting as Trust Brokersacross the enterprise, so the organization can maintain a strong security posture ahead of adversaries. Must be located in the DC Metro Area as this role requires onsite and remote support. KEY RESPONSIBILITIES
Architecture and Strategy
- Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients
- Design and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and Data
- Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans
- Develop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks
- Support integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks
- Drive SASE convergence, consolidating network and security enforcement onto a single policy plane
- Advance security posture design and real-time trust evaluation, with a focus on insider threat detection and response
Implementation and Engineering
- Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)
- Own top-level Conditional Access policy design and privileged access governance in Microsoft Entra ID/M365
- Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management
- Deliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems
- Enforce device posture as a condition of every access decision, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals
- Define and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra ID, and Workspace ONE (WS1)
- Configure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls across the network landscape, including Palo Alto, Cisco, and wireless infrastructure
- Deploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale
- Integrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements
Compliance and Authorization
- Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirements
- Support the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance
- Document ZTA controls for system security packages, POA&Ms, and security assessment reports
- Own access policy exception management, including governance workflows and audit-ready evidence documentation
Client Engagement and Collaboration
- Serve as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts
- Produce executive-level briefings, technical white papers, and implementation status reports
- Collaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration
VENDOR ECOSYSTEM EXPERIENCE
CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:
Vendor / Framework & Relevant Capabilities
Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars
Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection
Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center
CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements
Additional Enterprise Tooling: SCCM, Workspace ONE (WS1), Qualys vulnerability management, and Cisco network/wireless fabric, supporting device posture and network segmentation enforcement across the landscape
REQUIRED QUALIFICATIONS
Experience
- 5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles
- 2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environment
- Demonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model
- Experience supporting federal government clients or DoD/civilian agency environments
Technical Skills
- Proficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stack
- Identity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM tooling
- Network security: microsegmentation, ZTNA, DNS security, SD-WAN, next-generation firewall policy
- Endpoint security: EDR/XDR deployment and management, device compliance policy enforcement
- Cloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlay
- Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)
PREFERRED QUALIFICATIONS
- Active certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA-IA or ZCCA-PA, Microsoft SC-100 (Cybersecurity Architect Expert)
- Additional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certifications
- Familiarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation
- Experience with ServiceNow, Salesforce, or IT service management tooling in a federal context
- Multi-vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)
Flexible work from home options available.
- ...POSITION SUMMARY Celestial Innovations Group (CIG) is seeking a Mid Zero Trust Engineer to support federal agency clients in the design,... ...program managers, and ISSO/ISSM counterparts Produce executive-level briefings, technical white papers, and implementation status...SuggestedRemote workWork from homeFlexible hours
$135k - $170k
...0 Security Clearance: Secret Level of Experience: Senior This opportunity... ...architecture, reverse engineering, software and hardware... ...Technologies! We are seeking a Mid-Level AWS Solutions Architect... ...accessibility (Section 508), Zero Trust, and IL5 GovCloud requirements...SuggestedFull timeWork at officeLocal areaWork from homeWorldwideHome office- ...Northstrat is seeking an experienced and driven Mid-level Software (SW) Engineer to join our dynamic team. The ideal candidate will have extensive... ...security, including access and authorization for PKI and chain trusting ~ Experience with writing unit tests and E2E testing...SuggestedFull time
- ...ZERO TRUST (ZT) PROCESS RE-ENGINEERING SME POSITION OVERVIEW The Zero Trust Process Re-Engineering SME exists to provide senior-level advisory expertise in assessing, analyzing, and re-engineering the agency's enterprise IT and cybersecurity processes to advance...SuggestedCasual workRemote work
- GTSC seeks Cybersecurity Engineer – Zero Trust / RMF / SIEM \\\ for mid -August 2026 start. Commitment to start must be by 30 June in order to complete background checks required for this position. \ \\ \ Location \ : This is a local remote position in the metropolitan...SuggestedFull timeTemporary workLocal areaRemote workFlexible hours
- ...SHINE Systems is looking for a Mid-Level Test Systems Engineer to join our team supporting the National System of Geospatial-intelligence (NSG), Allied System of Geospatial-intelligence (ASG), and Federal Agencies. In this role, you will perform Application, System, and...Contract workWork experience placementLocal area
$93.66k - $124.2k
...Requisition: Regular Clearance Level Must Currently Possess:... ...to Obtain: None Public Trust/Other Required: BI Full 6C... ...T4) Job Family: Software Engineering Job Qualifications: Skills... ...Maintenance Developer/Tester Mid-Level Transform technology...Full timeTemporary workPart timeImmediate startRemote workWork from homeWorldwideFlexible hours$87.1k - $157.45k
...passionate about delivering high-quality software that directly supports our nation’s security? Leidos is seeking an experienced Mid-Level Test Engineer to join the Chinook Program supporting an Intelligence Community customer. This is an opportunity to work alongside...Full timeContract work$120k - $180k
...established. We are proactively seeking a standout professional for whom we will finalize a formal role. Amentum is seeking a mid-level systems engineer to provide dedicated engineering support to the Portfolio Acquisition Executive (PAE) for Munitions PMX-311 Terminal...Hourly payFull timeContract workWork at officeLocal area- ...Job Description Job Description Structural Engineer (Mid-Level) Hazen and Sawyer is seeking a Structural Engineer for our Silver Spring, MD office. The position will include performing structural design and analysis of environmental structures such as low-rise industrial...Temporary workWork at officeFlexible hours
- Tetrad Digital Integrity (TDI) seeks a Systems Engineer to advance an IDaaS platform underpinning CESO's Zero‑Trust architecture. You will work hands-on with ForgeRock ICAM components, Ping Identity tools, and enterprise directories in secure environments. The role emphasizes...
- ...Mid-Level Systems EngineerAmentum is seeking a mid-level systems engineer to provide dedicated engineering support to the Portfolio Acquisition Executive (PAE) for Munitions PMX-311 Terminal Defense systems (TDS), previously Program Executive Office (PEO) Integrated Warfare...Work at office
- cFocus Software seeks a Mid-Level Test Engineer to join our program supporting the Department of Homeland Security (DHS). This position is remote. This position requires a Public Trust Clearance. Qualifications: ~ Bachelor’s or master’s degree in IT, Computer Science...Full timeRemote work
$150k - $190k
As Sr. Zero Trust Engineer III, you’ll help design and implement identity-centric security for complex cloud and hybrid environments. You will use Microsoft Azure security technologies, automation, and recognized Zero Trust frameworks to reduce risk, strengthen access controls...Full timeLocal area$89.6k - $204k
Cybersecurity Systems Engineer (Entry Level to SME) TS/SCI with Poly REQUIRED Position Description... ...boundaries. Key Responsibilities (Mid-Level) Systems Engineering & Secure... .... • Cloud & DevOps Security: Design zero-trust environments, implement Infrastructure...Work at officeLocal area- Entarian is seeking an experienced TIC Systems Engineer to design, implement, and maintain secure network boundaries across multi-cloud environments. The role emphasizes TIC 3.0, Zero Trust principles, and effective configuration, monitoring, and management of boundary...
- AHU Technologies Inc in Washington is seeking a mid-level QA Engineer to ensure quality assurance in software testing. The role involves monitoring system functions, troubleshooting issues, and executing system configurations. Ideal candidates will have experience with...
- Overview Sayres is currently seeking an experienced Mid-Level Marine Engineer with an active SECRET clearance, verifiable in DISS in Washington, DC. Responsibilities: Provide engineering and technical support throughout the shipbuilding process, including concept studies...Contract work
$220k - $240k
GovCIO is hiring a Cybersecurity Engineer (RMF / Zero Trust) with an active Secret clearance to design, implement, and maintain cybersecurity solutions that protect enterprise systems while ensuring compliance with federal security frameworks, risk management requirements...Remote work- ...Federal and State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian seeks a Mid-Level InfoSec Threat Intelligence Engineer Consultant focusing on Cyber-Security/Information Security (INFOSEC) and IT Effectiveness Solution related issues...Full timeFor contractorsWork experience placementInternshipWork at officeMonday to FridayShift work
$96.33k - $192.8k
...92,801.00 Security Clearance: Secret Level of Experience: Mid This opportunity resides with Warfare... ...cybersecurity, network architecture, reverse engineering, software and hardware development... ...done.You’ll be part of small, high‑trust teams that turn ideas into functional...Full timeWork at officeLocal areaWorldwide$85.1k - $185.05k
...85,051.00 Security Clearance: Secret Level of Experience: Mid This opportunity resides with Warfare... ...cybersecurity, network architecture, reverse engineering, software and hardware development... ...openly, collaborate well, and build trust.Take Ownership - Deliver on...Full timeWork experience placementWork at officeLocal areaWorldwide$99k - $225k
Illumio Zero Trust Platform Engineer The Opportunity: Lead the design, deployment, configuration, and optimization of Illumio Core and Illumio... ...and activities ~ Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX/CASP+, CCNP Security,...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Federal and State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian Consulting Seeks an Mid Level Energy Programs Engineering Advisor to support requirements that address the global demand for, and use of, modern energy services by fostering...Full timeContract workTemporary workFor contractorsWork at officeRemote workFlexible hours
- ...preparing technical documents and performing engineering calculations in coordination with... ...skills; ability to communicate with all levels in a clear and concise manner. Effective... ...you'll enjoy some pretty awesome perks. Trust us, your friends will all have work envy...For contractorsCasual workWork at officeFlexible hours
$112k - $179k
Responsibilities Peraton is current hiring a Mid‑Level Malware Reverse Engineer for its' Federal Strategic Cyber programs. Location: Arlington,... ...integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to...Contract workLocal areaRemote workShift work- Washington, District of Columbia, United States About the job Zero Trust Cybersecurity Engineer MUST have Zero Trust Experience and an active TS/SCI Security Clearance! Position is hybrid; 3 days/week onsite in DC. Join Our Team as a Zero Trust Security Specialist! Are...Work experience placement3 days per week
$150k - $200k
...Mid-Level Systems EngineerTysons, Virginia, United StatesWhat Impact You'll HaveGRVTY's team provides tactical data engineering solutions. We embed skilled Data Engineers, Data Scientists, and ETL Developers directly into intelligence analyst groups to be their go-to data...Contract workImmediate startRemote workFlexible hours- ...Mid-Level Systems Engineer Join a collaborative engineering team in the Tysons Corner, VA area supporting critical infrastructure and applications across enterprise environments. We are seeking a mid-level Systems Engineer to help design, implement, and maintain secure...Local areaFlexible hours
$8k
...contract and, in anticipation of award, we're seeking Systems Engineers to join our team at the Naval Research Laboratory in Washington... ...deliver operational impact or breakthroughs - Define system-level and subsystem-level requirements, ensuring overall system integrity...Permanent employmentContract workTemporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Zero Trust Engineer Mid Level. Be the first to apply!



