A

Senior Zero Trust Engineer III

Posted 1 month ago

Job Requirements

Remote
Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
$175,000 - $185,000

Job Description

ICS Nett, Inc is seeking a highly skilled Zero Trust Engineer III with a specialized focus on Enterprise Architecture and Identity, Credential, and Access Management (ICAM). The successful candidate will be the primary technical authority for designing, integrating, and maturing the enterprise Zero Trust Architecture (ZTA) in support of critical Department of War (DoW) missions. This role requires a strategic thinker who can develop a holistic enterprise-level security architecture grounded in Zero Trust principles. The position will be responsible for ensuring that ICAM is the central pillar of our security posture, protecting critical infrastructure and CUI within Impact Level 5 (IL5) environments. The ideal candidate will possess deep expertise in the DoW Zero Trust Strategy, enterprise architecture frameworks, and the implementation of advanced ICAM solutions. This position will support our DCSA Contract based in Quantico VA.
Remote flexibility available! Telework offered with a requirement to be onsite up to three (3) days a week at Quantico, VA.
Position Description:
As a Zero Trust Engineer III, you will be a critical leader in our transition from traditional perimeter-based security to a comprehensive, identity-driven security model. Your primary focus will be on the enterprise architecture of our Zero Trust ecosystem, ensuring all security solutions and pillars — User, Device, Network, Application/Workload, Data, Visibility, and Automation/Orchestration — are cohesive, scalable, and fully integrated. You will leverage your expertise in Enterprise Architecture to develop and maintain the overall structure of the ZTA, while using your deep knowledge of ICAM to enforce granular, dynamic access control across the enterprise. This role involves close collaboration with mission owners, cybersecurity professionals, and IT staff to build a resilient and unified security framework that adheres strictly to the DoW Zero Trust Strategy.

Minimum Requirements:
• Minimum of 10 years of experience with a Bachelor’s Degree (12 years without) in cybersecurity architecture, enterprise IT security, or a related field.
• Demonstrated expertise in designing and implementing enterprise-level architectures.
• Deep understanding of the DoW/DoD Zero Trust Strategy, NIST SP 800-207, and the CISA Zero Trust Maturity Model.
• Active Secret Clearance REQUIRED, with eligibility for TS/SCI.

• Highly desired: Bachelor’s Degree, in Cybersecurity, Computer Science, Information Systems Management, or a related field.
• Highly desired: Cloud architecture certifications (e.g., AWS Certified Security Specialty, Microsoft Cybersecurity Architect Expert) or enterprise Zero Trust vendor certifications.

Highly Desired:
• Bachelor’s Degree in Cybersecurity, Computer Science, or Information Systems Management.
• Certifications in Enterprise Architecture Must meet 8140 certification requirements (E.g. CISM, CISSP-ISSAP, CISSP ISSEP, GCIA, GDSA, GICSP).
• Advanced security or architecture certifications (e.g., AWS Certified Security Specialty, Microsoft Cybersecurity Architect Expert).

Responsibilities:
• Enterprise Architecture & Strategy::
• Develop and maintain the overarching Zero Trust Enterprise Architecture, ensuring alignment with DoW mission requirements, DTM 25-003, the DoW Zero Trust Reference Architecture, and NIST SP 800-207.
• Create and manage strategic roadmaps for transitioning legacy systems into a fully integrated ZTA, minimizing disruption and maximizing security benefits.
• Serve as the lead technical architect for all Zero Trust initiatives, ensuring architectural integrity and consistency across projects.
• Identity, Credential, and Access Management (ICAM):
• Architect and lead the implementation of a robust, enterprise-wide ICAM framework as the foundation of the Zero Trust model.
• Design and enforce advanced Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) policies to ensure least-privilege access.
• Engineer solutions for continuous authentication, conditional access, and privileged access management (PAM) across all enterprise assets.
• Network and Infrastructure Security:
• Integrate network security solutions like micro-segmentation, Software-Defined Perimeters (SDP), and SASE into the broader Zero Trust Enterprise Architecture.
• Ensure network designs are governed by ICAM policies to restrict lateral movement and enforce access control at the network layer.
• Data Security and Governance:
• Design an enterprise data governance strategy that aligns with Zero Trust principles, focusing on data discovery, classification, and protection of CUI.
• Architect data security controls where access is determined by user identity, device posture, and data context, ensuring encryption for data at rest and in transit.
• Collaboration and Compliance:
• Provide expert guidance on Zero Trust Enterprise Architecture to leadership, engineering teams, and mission stakeholders.
• Ensure all architectural designs are compliant with the Risk Management Framework (RMF) and relevant DISA STIGs.
• Visibility, Analytics, and Automation:
• Integrate Zero Trust telemetry with enterprise SIEM and continuous monitoring solutions.
• Develop architectures that support automated threat response and continuous risk scoring.
• Work with SOC analysts to ensure visibility gaps are closed across all endpoints and network segments.
• Continuous Improvement:
• Stay up-to-date with the latest Zero Trust technologies, DoW policies, and adversary tactics.
• Research and evaluate new vendor solutions to enhance enterprise security capabilities.
• Document architectural standards, concept of operations (CONOPS), and best practices.

Work Environment and Physical Demands:
• This is primarily a Telework position with a requirement to be onsite up to three (3) days a week
• If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
• Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form
group id: 10191027

Similar Jobs


Job Category
IT - Security
Clearance Level
Secret