Benefits:
n401(k)
nDental insurance
nHealth insurance
nOpportunity for advancement
nPaid time off
nTraining & development
nVision insurance
nPOSITION SUMMARY
nCelestial Innovations Group (CIG) is seeking a Zero Trust Architecture Engineer to own end-to-end access policy design across the identity, endpoint, network, and application layers for federal agency clients, spanning the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform, guided by the principle of “never trust, always verify.” The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model and Secure Access Service Edge (SASE) guidance.
nThese responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, acting as Trust Brokers across the enterprise, so the organization can maintain a strong security posture ahead of adversaries.
nMust be located in the DC Metro Area as this role requires onsite and remote support.
nKEY RESPONSIBILITIES Architecture and Strategy
nLead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients
nDesign and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and Data
nTranslate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans
nDevelop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks
nSupport integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks
nDrive SASE convergence, consolidating network and security enforcement onto a single policy plane
nAdvance security posture design and real-time trust evaluation, with a focus on insider threat detection and response
nImplementation and Engineering
nDeploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)
nOwn top-level Conditional Access policy design and privileged access governance in Microsoft Entra ID/M365
nImplement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management
nDeliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems
nEnforce device posture as a condition of every access decision, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals
nDefine and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra ID, and Workspace ONE (WS1)
nConfigure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls across the network landscape, including Palo Alto, Cisco, and wireless infrastructure
nDeploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale
nIntegrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements
nCompliance and Authorization
nAlign ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirements
nSupport the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance
nDocument ZTA controls for system security packages, POA&Ms, and security assessment reports
nOwn access policy exception management, including governance workflows and audit-ready evidence documentation
nClient Engagement and Collaboration
nServe as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts
nProduce executive-level briefings, technical white papers, and implementation status reports
nCollaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration
nVENDOR ECOSYSTEM EXPERIENCE CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:
nVendor / Framework & Relevant Capabilities Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements Additional Enterprise Tooling: SCCM, Workspace ONE (WS1), Qualys vulnerability management, and Cisco network/wireless fabric, supporting device posture and network segmentation enforcement across the landscape
nREQUIRED QUALIFICATIONS Experience
n5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles
n2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environment
nDemonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model
nExperience supporting federal government clients or DoD/civilian agency environments
nTechnical Skills
nProficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stack
nIdentity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM tooling
nNetwork security: microsegmentation, ZTNA, DNS security, SD-WAN, next-generation firewall policy
nEndpoint security: EDR/XDR deployment and management, device compliance policy enforcement
nCloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlay
nFamiliarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)
nPREFERRED QUALIFICATIONS
nActive certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA-IA or ZCCA-PA, Microsoft SC-100 (Cybersecurity Architect Expert)
nAdditional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certifications
nFamiliarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation
nExperience with ServiceNow, Salesforce, or IT service management tooling in a federal context
nMulti-vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)
nFlexible work from home options available.
Zero Trust Engineer Mid Level in washington at Unknown Company
This position is listed as full time and able to be worked remotely.