Zero Trust Infrastructure Engineer

DecisionPoint Corporation
Reston, VA, United States
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Application Layers Cloud Computing Cloud Computing Security Cloud Engineering CompTIA Security+ Cyber Security Information Engineering Monitoring of Systems Identity and Access Management Network Security Routing
+7 more
Zero Trust Network Access Security Information and Event Management Policy as Code Data Logging Cloud-native Network Functions (CNF) Information Technology Microservices

Job description

The Zero Trust Infrastructure Engineer collaborates with architects, cybersecurity teams, network engineers, and application teams to ensure the enterprise environment meets Zero Trust maturity goals and adheres to DoD Zero Trust strategy and implementation guidance., The Zero Trust Infrastructure Engineer will: Implement Zero Trust Policy Enforcement Points (PEPs) across network, device, and application layers.

  • Configure microsegmentation policies, identity-based routing, and dynamic access controls.

  • Support Zero Trust automation workflows, including policy-as-code and continuous verification mechanisms.

  • Integrate telemetry feeds from applications, identity services, cloud platforms, and network sensors into enforcement logic.

  • Apply Zero Trust principles to cloud network segmentation, traffic inspection, and resource access.

  • Support the implementation of device posture checks, endpoint trust validation, and conditional access rules.

  • Assist in the development and enforcement of Zero Trust security policies aligned with DoD guidance.

  • Troubleshoot enforcement issues, telemetry gaps, and policy misconfigurations.

  • Participate in Zero Trust maturity assessments, roadmap updates, and implementation planning.

  • Maintain Zero Trust infrastructure documentation, diagrams, and policy mappings.

  • Collaborate with cybersecurity teams to align Zero Trust enforcement with RMF controls and IL5 cloud requirements.

  • Support monitoring, logging, and analytics for Zero Trust events and enforcement decisions.

Requirements

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology Engineering, or a related field.

Experience (Required)

  • Minimum 7 years of experience in IT infrastructure, cloud security, or network security engineering.

  • Experience implementing Zero Trust or identity-based security controls.

  • Experience with microsegmentation, PEP configuration, or conditional access.

  • Experience supporting IL5 cloud or federal security environments.

Technical Knowledge (Required)

  • Knowledge of Zero Trust principles, DoD Zero Trust strategy, and enforcement mechanisms.

  • Familiarity with identity-based routing, access policies, and device posture enforcement.

  • Understanding of cloud networking (AWS GovCloud preferred), segmentation, and traffic inspection.

  • Familiarity with telemetry, logging, and distributed monitoring systems.

Technical Knowledge (Preferred)

  • Experience with policy-as-code frameworks or Zero Trust automation tools.

  • Experience with SIEM platforms, identity platforms, and cloud-native enforcement services.

  • Experience with microservices or container-based traffic enforcement.

Certifications

Required:

  • CompTIA Security+

Preferred:

  • ITIL v4 Foundation

  • CCSP, CISSP, or Zero Trust-focused certifications

  • AWS security or networking certifications

Skills

  • Strong analytical and troubleshooting skills for complex Zero Trust enforcement issues.

  • Excellent communication and collaboration abilities across technical and mission teams.

  • High attention to detail, especially in policy tuning and enforcement logic.

  • Ability to work in fast-paced, mission-critical environments.

  • Strong documentation discipline and ability to translate complex configurations into clear guidance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:58 min

Implementing zero trust on traditional cloud providers and serverless

Jan Peer Stöcklmair Jan Peer Stöcklmair · WWC Europe 2026

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos Ā· LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 Ā· WWC Europe 2026

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton Ā· WWC 2022

7:50 min

Prioritizing cybersecurity and zero trust in development

Ash Ryan Arnwine Ash Ryan Arnwine +3 Ā· WWC 2024

1:51 min

Overview of the three Google Maps routing applications

GermÔn Álvarez · LIVE

Videos

See all

Related articles

See all