Senior Deployment Engineer, AppGate ZTNA (Federal)

Gormat, LLC
Washington, DC, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Access JavaScript (Programming Language) Active Directory Amazon Web Services Microsoft Azure Bash Shell Software Debugging Domain Name System (DNS) Cryptographic Protocols Hyper-V Internet Protocol Security (IP SEC) Virtual Private Networks (VPN)
+19 more
Lightweight Directory Access Protocols (LDAP) Linux System Administration Packet Analyzer OpenID Public Key Infrastructure Windows PowerShell Ansible Zero Trust Network Access RSA (Cryptosystem) Security Assertion Markup Language (SAML) Security Content Automation Protocol Security Information and Event Management Virtualization Technology VMware VSphere Google Cloud Information Technology Code Inspection Restful APIs Terraform

Job description

  • Lead end-to-end AppGate ZTNA deployments: install and configure controllers, gateways, and clients across on-premises, cloud, and disconnected environments.
  • Integrate AppGate with customer identity providers and sources of trust and risk telemetry, including SAML, OIDC, RADIUS, LDAP(s), Active Directory, NGFWs, entitlement automation systems, SIEM/SOAR, and ITSM.
  • Design deployment architectures that meet customer requirements for availability, scale, and least privilege access enforcement.
  • Debug failures using logs, shell access, packet captures, and code inspection down to the protocol, OS, and application level.
  • Write and maintain scripts and automation (Bash, PowerShell, JavaScript, REST APIs) to support deployment and sustainment.
  • Harden deployments to STIG, SCAP, and applicable Federal compliance baselines.
  • Serve as the escalation point for complex deployment and sustainment issues.
  • Sustain and maintain deployed environments: patching, upgrades, health monitoring, and incident response.
  • Produce detailed as-built documentation, runbooks, and operational handoff materials.
  • Mentor Associate and mid-level Delivery Engineers and review their work.

Requirements

  • 8 to 12 years in networking, security, systems, platform, or automation engineering roles, with hands-on delivery experience.
  • Demonstrated mastery of Linux systems administration.
  • Hands-on scripting and automation with Bash, PowerShell, and JavaScript.
  • Working knowledge of REST APIs for integration and automation.
  • Strong experience with identity systems: Active Directory, DNS, PKI, SAML, OIDC, RADIUS, and LDAP.
  • Experience deploying to public cloud (AWS, Azure, GCP) and virtualization platforms (VMware vSphere, Microsoft Hyper-V)..
  • Familiarity with networking, transport, and cryptographic protocols such as TLS, IPsec, AES, PKI, and RSA.
  • Experience supporting Federal or other high-assurance environments.
  • Familiarity with STIG and SCAP hardening; process frameworks such as ITIL or ITSM a plus.
  • Excellent written and verbal communication for documentation and customer handoff.
  • Bachelor’s degree in engineering, information technology, or a related discipline, or equivalent related experience., * CCNP, CCIE, RHCE, CISSP, CCNA, Security +, MCSE or equivalent certifications.
  • Prior experience deploying ZTNA, software-defined perimeter (SDP), or VPN-replacement technologies.
  • Experience with infrastructure as code and configuration as code (Terraform, Ansible).

Clearance

  • Active U.S. security clearance, or the ability to obtain and maintain one. Top Secret a plus., * Willingness to travel to customer sites as project and customer needs require. Travel can exceed 50% depending on the deployment.

Benefits & conditions

  • This is a remote opportunity, though we are ideally looking for someone from the following locations

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · World Congress 2025

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all