JobConnect

Zero Trust Engineer

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Zero Trust Engineer to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as a critical technical function responsible for the architecture, engineering, implementation, and continuous advancement of Zero Trust security capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, enterprise applications, and hybrid network environments.

The ideal candidate is a technically proficient and strategically minded cybersecurity engineer with deep, hands-on expertise in Zero Trust Architecture principles, Federal Zero Trust policy frameworks, identity and access management technologies, network micro-segmentation, endpoint security, data protection, and the practical implementation of Zero Trust controls across diverse enterprise technology stacks. This individual must possess the technical depth, cross-domain knowledge, and collaborative leadership skills required to drive the Government's Zero Trust maturity forward in alignment with NIST SP 800-207, OMB M-22-09, and applicable Federal Zero Trust mandates and implementation guidance.

The Zero Trust Engineer will serve as the program's primary technical expert and implementation lead for Zero Trust Architecture (ZTA) initiatives, responsible for driving the design, engineering, implementation, and continuous improvement of Zero Trust security capabilities across all pillars of the enterprise environment—identity, devices, networks, applications, data, and visibility and analytics. This individual works closely with security engineers, network engineers, cloud operations teams, identity and access management specialists, DevSecOps engineers, and Government stakeholders to ensure Zero Trust principles are systematically embedded across the enterprise technology stack, advancing the Government's Zero Trust maturity in alignment with Federal mandates and the program's security objectives.

Principal responsibilities will include but are not limited to:
Zero Trust Architecture & Strategy
• Serve as the program's subject matter expert and technical authority for Zero Trust Architecture, providing authoritative guidance, engineering leadership, and expert recommendations to program leadership, functional teams, and Government stakeholders on Zero Trust strategy, implementation priorities, and maturity advancement.
• Develop and maintain the program's Zero Trust Architecture documentation, including ZTA reference architecture diagrams, Zero Trust pillar maturity assessments, implementation roadmaps, and technical design specifications aligned with NIST SP 800-207, OMB M-22-09, CISA Zero Trust Maturity Model, and applicable Federal Zero Trust implementation guidance.
• Conduct comprehensive Zero Trust maturity assessments across all five Zero Trust pillars—Identity, Devices, Networks, Applications and Workloads, and Data—identifying current state capabilities, maturity gaps, and prioritized improvement opportunities across the enterprise environment.
• Develop and maintain Zero Trust implementation roadmaps, translating maturity assessment findings and Federal Zero Trust mandates into actionable, sequenced engineering initiatives with clear milestones, dependencies, and success criteria.
• Lead Zero Trust architecture reviews for new systems, infrastructure changes, application deployments, and cloud migrations, assessing Zero Trust alignment, identifying implementation gaps, and recommending compensating controls and architectural improvements.
• Evaluate emerging Zero Trust technologies, industry frameworks, and Federal policy developments, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to advance Zero Trust maturity and security posture.
• Provide technical leadership and mentorship to security engineering team members on Zero Trust principles, implementation techniques, and Federal compliance requirements, fostering a shared understanding of Zero Trust objectives across the program.
Identity Pillar Implementation
• Lead the engineering and implementation of Zero Trust identity controls across the enterprise environment, ensuring all user and non-person entity (NPE) identities are continuously verified, strongly authenticated, and least-privilege access principles are consistently enforced.
• Design and implement enterprise-wide Multi-Factor Authentication (MFA) enforcement, ensuring phishing-resistant MFA—including PIV/CAC, FIDO2, and other approved strong authentication methods—is deployed and enforced for all user access to Government systems and applications.
• Engineer and implement identity risk-based conditional access policies across enterprise identity platforms, including Microsoft Entra ID and Okta, ensuring access decisions continuously evaluate identity risk signals, device compliance, location, and behavioral context.
• Support the implementation and maturation of Privileged Access Management (PAM) capabilities, including just-in-time access provisioning, privileged session management, and credential vaulting, ensuring privileged access is tightly controlled, monitored, and auditable.
• Implement and maintain identity governance and administration (IGA) controls, including automated access provisioning and deprovisioning, access certification campaigns, and segregation of duties enforcement, in alignment with Zero Trust least-privilege and need-to-know principles.
• Develop and maintain identity-aware security policy integrations across network security, endpoint security, and application security platforms, ensuring identity context is consistently leveraged to enforce granular, risk-based access controls across the enterprise.
• Support the integration of non-person entity (NPE) identity management capabilities, including service accounts, application identities, API credentials, and machine identities, into the Zero Trust identity framework.
Device Pillar Implementation
• Lead the engineering and implementation of Zero Trust device trust capabilities, ensuring all managed and unmanaged devices seeking access to Government resources are continuously evaluated for compliance, health, and trustworthiness prior to access being granted.
• Design and implement device compliance policy frameworks across enterprise endpoint management platforms, including Microsoft Intune, ensuring device health signals—including patch compliance, EDR agent status, configuration compliance, and disk encryption status—are continuously assessed and integrated into access control decisions.
• Engineer device-based conditional access policy integrations between endpoint management platforms and enterprise identity providers, ensuring non-compliant or unmanaged devices are automatically restricted from accessing sensitive Government resources.
• Implement and maintain continuous device monitoring capabilities, ensuring device health and compliance status is continuously evaluated throughout active sessions and that access is revoked or restricted when device trust signals degrade.
• Support the implementation of enterprise certificate-based device authentication capabilities, ensuring all managed devices are issued and maintain valid device identity certificates used for network access control and Zero Trust policy enforcement.
Network Pillar Implementation
• Lead the engineering and implementation of Zero Trust network security controls, including network micro-segmentation, software-defined perimeter capabilities, encrypted communications enforcement, and identity-aware network access control across the enterprise environment.
• Design and implement network micro-segmentation architectures, working with network engineers and Palo Alto Networks platform engineers to define and enforce granular network segmentation policies that limit lateral movement and enforce least-privilege network access between workloads, applications, and user segments.
• Implement and maintain software-defined perimeter (SDP) and Zero Trust Network Access (ZTNA) capabilities, replacing legacy VPN-based remote access models with identity-aware, least-privilege application access controls that continuously verify user and device trust prior to granting network access.
• Design and implement encrypted communications enforcement policies, ensuring all data in transit is encrypted using approved cryptographic protocols and that unencrypted communications are detected, blocked, or remediated across the enterprise environment.
• Support the implementation of DNS security controls, including DNS filtering, DNS-over-HTTPS (DoH) policy management, and malicious domain blocking, as a key Zero Trust network visibility and control capability.
• Develop and maintain network pillar Zero Trust metrics and reporting, providing program leadership and Government stakeholders with accurate visibility into network segmentation coverage, ZTNA adoption, encrypted traffic enforcement, and lateral movement risk reduction.
Application & Workload Pillar Implementation
• Lead the engineering and implementation of Zero Trust application and workload security controls, ensuring all applications and workloads are protected through continuous authorization, least-privilege access enforcement, and runtime security monitoring.
• Design and implement application-level Zero Trust access controls, including continuous authorization policies, step-up authentication triggers, and session risk monitoring capabilities that enforce least-privilege access throughout active application sessions.
• Support the integration of enterprise applications with Zero Trust identity and access management platforms, ensuring applications leverage centralized, policy-driven authentication and authorization rather than legacy, application-managed access control mechanisms.
• Implement and maintain application security posture monitoring capabilities, including web application firewall (WAF) integration, API security controls, and application-layer threat detection, ensuring application-level security visibility is integrated into the Zero Trust policy decision and enforcement framework.
• Support the implementation of workload identity and runtime security controls across cloud and containerized environments, including workload identity attestation, container security policies, and cloud workload protection capabilities aligned with Zero Trust principles.
Data Pillar Implementation
• Lead the engineering and implementation of Zero Trust data security controls, ensuring sensitive Government data is identified, classified, protected, and continuously monitored in alignment with Zero Trust data-centric security principles.
• Design and implement enterprise data classification and labeling capabilities, working with information security and compliance teams to ensure sensitive data—including CUI and other protected information categories—is accurately identified and labeled across all storage, processing, and transmission contexts.
• Implement and maintain data access control policies aligned with Zero Trust least-privilege principles, ensuring access to sensitive data is restricted to authorized identities and devices with legitimate, verified need-to-know, continuously evaluated throughout access sessions.
• Support the implementation of Data Loss Prevention (DLP) capabilities across endpoint, network, email, and cloud storage environments, ensuring sensitive data exfiltration attempts are detected, blocked, and alerted in accordance with defined DLP policies.
• Implement and maintain encryption controls for sensitive data at rest and in transit, ensuring approved cryptographic standards are applied consistently across all environments where sensitive Government data is stored or transmitted.
Visibility, Analytics & Automation Pillar Implementation
• Lead the engineering and implementation of Zero Trust visibility and analytics capabilities, ensuring comprehensive telemetry collection, behavioral analytics, and automated policy enforcement mechanisms are in place to support continuous trust evaluation across the enterprise.
• Design and implement Zero Trust telemetry collection architectures, ensuring security-relevant events from identity, device, network, application, and data sources are ingested into the enterprise SIEM and analytics platforms for continuous monitoring and threat detection.
• Develop and maintain Zero Trust-aligned detection content within the enterprise SIEM platform, including detection rules, behavioral analytics, and anomaly detection capabilities that operationalize Zero Trust trust signals and risk indicators for threat detection and response.
• Support the implementation of Security Orchestration, Automation, and Response (SOAR) capabilities that automate Zero Trust policy responses to detected trust violations, including automated access revocation, device isolation, and incident escalation workflows.
• Develop and maintain Zero Trust maturity metrics and analytics reporting, providing program leadership and Government stakeholders with data-driven visibility into Zero Trust implementation progress, control effectiveness, and residual risk across all pillars.
Compliance, ATO & Federal Zero Trust Policy Alignment
• Ensure all Zero Trust engineering activities are conducted in full compliance with applicable Federal Zero Trust mandates and frameworks, including NIST SP 800-207, OMB M-22-09, CISA Zero Trust Maturity Model, applicable DISA Zero Trust reference architectures, NIST SP 800-53, FISMA, FedRAMP, and client-specific Zero Trust implementation requirements.
• Support ATO activities, ensuring Zero Trust control implementations are accurately documented in system security plans, security control implementation statements, and continuous monitoring reports.
• Develop and maintain Zero Trust compliance documentation, including control implementation evidence, maturity assessment records, and audit artifacts supporting the program's ATO and continuous monitoring obligations.
• Represent Zero Trust engineering interests in compliance reviews, security assessments, and Government stakeholder briefings, communicating Zero Trust implementation progress, maturity status, and residual risk clearly and accurately.
• Monitor Federal Zero Trust policy developments, CISA guidance updates, NIST framework revisions, and emerging Zero Trust standards, ensuring the program's Zero Trust implementation roadmap remains current and aligned with evolving Federal requirements.

Education and Experience:
Required:
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Network Engineering, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
• Minimum of 5 years of hands-on experience in cybersecurity engineering, network security, identity and access management, or a closely related discipline within a federal government IT contracting or enterprise security environment.
• Demonstrated hands-on experience implementing Zero Trust security controls across one or more Zero Trust pillars, including identity, devices, networks, applications, or data, within an enterprise IT environment.
• Experience with enterprise identity and access management platforms, including Microsoft Entra ID, Okta, or equivalent, including MFA enforcement, conditional access policy development, and identity governance capabilities.
• Experience supporting Federal cybersecurity compliance activities, including NIST SP 800-53 security control implementation, ATO documentation, and continuous monitoring.
• Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.
Preferred:
• Prior experience serving as a Zero Trust engineer or architect on a federal IT program of comparable scale and complexity.
• Hands-on experience implementing Zero Trust capabilities across multiple Zero Trust pillars in a Federal agency environment, with demonstrated alignment to OMB M-22-09 and CISA Zero Trust Maturity Model requirements.
• Experience with network micro-segmentation implementation using Palo Alto Networks, Illumio, or equivalent platforms in a Federal enterprise environment.

Required Skills and Competencies:
• Deep knowledge of Zero Trust Architecture principles and Federal Zero Trust policy frameworks, including NIST SP 800-207, OMB M-22-09, CISA Zero Trust Maturity Model, and applicable DISA Zero Trust reference architectures, with demonstrated ability to translate policy requirements into practical engineering implementations.
• Strong cross-domain technical expertise spanning identity and access management, network security, endpoint security, cloud security, application security, and data protection, sufficient to engineer and integrate Zero Trust controls across all Zero Trust pillars.
• Demonstrated experience with enterprise identity and access management platforms, including Microsoft Entra ID and/or Okta, including conditional access policy development, MFA enforcement, privileged access management, and identity governance capabilities.
• Experience implementing network micro-segmentation and Zero Trust Network Access (ZTNA) capabilities, including software-defined perimeter architectures and identity-aware network access control policies.
• Knowledge of enterprise endpoint management and device compliance platforms, including Microsoft Intune or equivalent, and their integration with identity providers for device-based conditional access enforcement.
• Experience with enterprise SIEM platform integration for Zero Trust telemetry collection, Zero Trust-aligned detection content development, and behavioral analytics capabilities.
• Strong knowledge of Federal cybersecurity compliance frameworks, including NIST SP 800-53, FISMA, FedRAMP, and applicable DISA STIGs, as they relate to Zero Trust control implementation and documentation.
• Proficiency with at least one scripting or programming language, including Python, PowerShell, or Bash, for Zero Trust automation, API integration, and policy enforcement scripting.
• Excellent written and verbal communication skills with demonstrated ability to develop comprehensive Zero Trust architecture documentation, maturity assessment reports, and implementation roadmaps, and to present complex Zero Trust concepts clearly to both technical and non-technical audiences including senior Government stakeholders.
• Strong analytical and problem-solving skills with demonstrated ability to assess complex enterprise environments, identify Zero Trust implementation gaps, and develop prioritized, actionable improvement plans.

Desired Skills and Competencies:
• Certified Information Systems Security Professional (CISSP) or equivalent senior cybersecurity certification.
• GIAC Security Essentials (GSEC), GIAC Certified Enterprise Defender (GCED), or equivalent GIAC cybersecurity certification.
• Microsoft Certified: Identity and Access Administrator Associate (SC-300), Microsoft Certified: Security Operations Analyst Associate (SC-200), or equivalent Microsoft identity and security certification.
• Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent network security certification demonstrating Palo Alto Networks micro-segmentation and ZTNA implementation expertise.
• CompTIA Security+, CompTIA CySA+, or CompTIA CASP+ certification.
• Experience with CISA Continuous Diagnostics and Mitigation (CDM) program capabilities and their integration into enterprise Zero Trust implementations.
• Familiarity with Illumio, Guardicore, or equivalent micro-segmentation platform implementation and administration.
• Experience with SOAR platform development and playbook engineering for automated Zero Trust policy enforcement and incident response workflows.
• Familiarity with service mesh technologies such as Istio or Linkerd and their application to Zero Trust workload identity and service-to-service security enforcement in containerized environments.
• Experience with data classification and labeling platform implementation, including Microsoft Purview Information Protection or equivalent tools.
• Knowledge of quantum-resistant cryptography standards and post-quantum cryptography transition planning as it relates to Zero Trust encrypted communications requirements.
• Experience with FedRAMP authorization support and cloud security posture management as they relate to Zero Trust cloud security control implementation.
• Familiarity with MITRE ATT&CK framework and its application to Zero Trust control gap analysis, detection engineering, and threat-informed defense activities.
• Experience developing and delivering Zero Trust training materials and awareness briefings for technical and non-technical audiences in a federal IT environment.
• Familiarity with Section 508 compliance requirements for security dashboards, reporting tools, and documentation products delivered under federal contracts.
• Knowledge of emerging Zero Trust standards, NIST framework updates, and Federal Zero Trust policy developments, with demonstrated ability to incorporate new requirements into program Zero Trust implementation roadmaps.

Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Skills

  • Zero Trust Architecture
  • Identity and Access Management (IAM)
  • Network Micro-segmentation
  • Endpoint Security
  • Data Protection
  • Cloud Security
  • Federal Security Frameworks

Related jobs

Koniag Government ServicesApply for this job