Illumio Zero Trust Segmentation Platform Engineer...

ENS Solutions, LLC
College Park, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior

Job location

College Park, United States of America

Tech stack

Microsoft Windows
Amazon Web Services (AWS)
Azure
Bash
Cloud Computing Security
Cloud Engineering
Configuration Management Databases
Computer Security
Linux
Distributed Systems
Hyper-V
Information Technology Operations
Python
Network Security
Routing
Network Segmentation
Powershell
Ansible
Zero Trust Network Access
Runbook
Security Information and Event Management
TCP/IP
Virtualization Technology
Software Vulnerability Management
Scripting (Bash/Python/Go/Ruby)
Cloud Platform System
Delivery Pipeline
Firewalls (Computer Science)
Infrastructure Automation Frameworks
Information Technology
REST
Terraform
ServiceNow
Vulnerability Analysis
VMware

Job description

We are seeking an experienced Illumio Zero Trust Segmentation Platform Engineer to lead the design, implementation, and operational support of our enterprise micro-segmentation strategy. This role will own the Illumio Adaptive Security Platform (ASP) across hybrid environments and play a critical part in our Zero Trust initiative, partnering with security architects, cloud engineers, application teams, and IT operations to reduce lateral movement risk and strengthen our overall security posture., + Lead the design, deployment, configuration, and optimization of Illumio Core and Illumio Edge across on-premises, virtualized, and cloud environments.

  • Architect and implement Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls.

  • Develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications.

  • Integrate Illumio with SIEM/SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines.

  • Conduct traffic flow analysis using Illumio VEN telemetry and build policy recommendations to reduce attack surface and limit east-west movement.

  • Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure.

  • Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes.

  • Perform lifecycle management: upgrades, health checks, certificate operations, and policy governance.

  • Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies.

  • Contribute to architectural standards, documentation, and enterprise security playbooks.

Requirements

  • 5+ years in cybersecurity, cloud security, or infrastructure engineering.

  • 3+ years of expertise in Linux/Windows systems, virtualization (VMware, Hyper-V), and cloud environments (AWS, Azure, or GCP).

  • 2+ years of experience with network security (firewalls, routing, segmentation models, TCP/IP).

  • 2+ years of experience developing and deploying solutions for highly regulated mission-critical environments (finance, healthcare, federal, or energy).

  • 1+ year experience with infrastructure automation tools (Ansible, Terraform, or similar).

  • 1+ year experience with REST APIs, scripting (Python, Bash, PowerShell), or automation frameworks.

  • Active TS/SCI clearance; willingness to take a polygraph exam

  • Associate's degree and 5+ years of experience supporting IT projects and activities, Bachelor's degree and 3+ years of experience supporting IT projects and activities, or Master's degree and 1+ years of experience supporting IT projects and activities. Years of experience may be accepted in lieu of degree.

  • Active DoD 8570.01-M Information Assurance Technician (IAT) Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND

  • Ability to obtain a DoD 8570.01-M Cybersecurity Service Provider - Infrastructure Support Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND certification within 30 days of start date

Additional Qualifications

  • Prior Hands-on experience deploying and managing Illumio Adaptive Security Platform (ASP) in enterprise environments.

  • Illumio certifications (e.g., Illumio ASP Professional or Expert).

  • Experience with CMDB systems (ServiceNow), SIEM/SOAR tools, or vulnerability management platforms.

  • Strong understanding of Zero Trust principles, micro-segmentation, and lateral movement mitigation

  • Strong analytical and problem-solving skills with the ability to translate policies into technical controls.

Benefits & conditions

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?

  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS

About the company

AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.

Apply for this position