> Markdown version of [/jobs/ext/2651713-security-engineer](https://www.wearedevelopers.com/jobs/ext/2651713-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Interprint Incorporated - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $116,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Agile Methodology, Artificial Intelligence, Amazon Web Services, Automation of Tests, Microsoft Azure, Bash Shell, Cloud Computing, Code Review, Continuous Integration, Information Engineering, Linux, Domain Name System (DNS), Identity and Access Management, Python (Programming Language), Networking Basics, Routing, OpenID, Public Key Infrastructure, Windows PowerShell, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Security Information and Event Management, TCP/IP, Wide Area Networks, Workflow Management Systems, Policy as Code, Scripting, Computer Network Technologies, Okta, Information Technology, Security Orchestration, Automation & Response - **Published:** August 19, 2026 - **Apply:** https://recruiting.adp.com/srccsh/public/RTI.home?r=5001219228500&c=2166501&d=WWTSoftchoice ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline preferred; an equivalent combination of education, training, and relevant experience will be considered in lieu of a degree. * A minimum of 5 years of hands-on experience with SASE/ZTNA platforms in production enterprise environments + Experience with the following technologies: ZTNA, SASE, CASB, SWG, SD-WAN, TLS/PKI, DNS and core networking/routing, SIEM, SOAR, EDR/device posture integration, SAML/OIDC/SCIM identity federation (Okta and/or Azure AD/Entra), IAM/conditional access, cloud (Azure, AWS), Linux, Windows. + Experience with the following standards: NIST 800-53, NIST 800-171, CMMC, SOC 1/2, ISO 27001. * Deep understanding of Zero Trust Network Access and Secure Access Service Edge models applied hands-on rather than at a conceptual level. * Strong grasp of underlying network fundamentals (TLS/PKI, DNS, routing, TCP/IP) sufficient to troubleshoot below the vendor UI. * Skilled in identity federation and conditional access policy design across SAML/OIDC/SCIM-based identity providers. * Proficient in Python, PowerShell, or Bash to automate policy management, reporting, and compliance workflows. * Working knowledge of NIST 800-53, NIST 800-171, and CMMC control families as they apply to access control. * Extensive troubleshooting experience in regard to traffic decryption and certificate trusts * Strong communication skills to work across identity, network, compliance, and leadership teams in both GCCH and Commercial contexts. * Excellent analytical and problem-solving skills, with the ability to balance operational needs, user experience, and security/compliance risk. * This position requires U.S. citizenship due to access requirements within the GCCH environment. Preferred * Experience operating in both FedRAMP High/GCCH and Commercial environments * Experience with scripting (Python, PowerShell, or Bash) for policy-as-code and automation highly desired. * Possession of one or more industry-recognized certifications, such as a vendor-specific SASE/ZTNA certification (any major platform), CCNA, CCSP, or CISSP, is preferred but not required. Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay. ## Description Designs, implements, and operates SASE and ZTNA architecture across GCCH and commercial environments. Owns identity-driven access controls, session management, telemetry, compliance mapping, dashboards, and audit evidence. Serves as the senior escalation point for incidents, performs root-cause analysis, integrates device posture and SOAR workflows, develops AI-enabled automations, collaborates with identity, network, compliance, and vendors, and mentors junior engineers., The Internal WWT IT team is the backbone of our company's technological infrastructure, ensuring seamless operations and continuous innovation. Our team is dedicated to managing and supporting the company's technology infrastructure, ensuring the smooth operation of hardware, software, networks, and data systems, while providing top-notch technical support to employees. By joining the Internal WWT IT team, you will play a crucial role in maintaining the efficiency and security of our IT environment, enabling the company to achieve its strategic goals. The Internal IT team offers the opportunity to work in a dynamic and collaborative environment, where your contributions will have a direct impact on the company's success. If you are passionate about technology and eager to take on new challenges, we encourage you to apply and join our team. The SASE/ZTNA Security Engineer designs, implements, and operates Zero Trust Network Access and Secure Access Service Edge architecture across WWT's GCCH and Commercial environments. This role owns ZTNA policy and identity-driven access architecture. Including session management, access policy design, and telemetry integration for compliance reporting. This position requires U.S. citizenship due to access requirements within the GCCH environment. Responsibilities * Design, implement, and operate ZTNA and SASE architecture, including access policy, session management, and steering/proxy configuration across both GCCH and Commercial environments. * Own identity-driven access control integration, including conditional access policy design with SAML/OIDC/SCIM-based identity providers. * Serve as the senior escalation point for complex ZTNA/SASE incidents, conducting root cause analysis and driving resolution. * Utilize ZTNA/SASE session telemetry to support user access reviews, compliance reporting, and incident investigation. * Map ZTNA/SASE controls to NIST 800-53 and CMMC control families (e.g., AC-17, AC-4, SC-7) and produce audit-ready evidence for GCCH and Commercial compliance requirements. * Develop and maintain dashboards and KPIs that communicate ZTNA/SASE performance, access risk, and policy health to technical stakeholders. * Build AI integrations and automations for reporting, routine tasks, and recurring compliance workflows, aligned with the broader security automation strategy. * Collaborate with identity, network, and compliance teams to align ZTNA/SASE initiatives with business and regulatory needs across both operating environments. * Evaluate and integrate SASE/ZTNA-adjacent technologies (device posture/EDR signal, SOAR-driven response workflows) with existing platforms. * Mentor junior engineers on ZTNA/SASE architecture, troubleshooting, and secure access principles. * Engage with external vendors and partners to evaluate and integrate SASE/ZTNA technologies. * Maintain documentation, runbooks, and knowledge base articles for ZTNA/SASE operations and troubleshooting., Artificial Intelligence * Big Data * Healthtech * Information Technology * Machine Learning * Software * Analytics Leads complex cybersecurity due diligence programs across mergers, acquisitions, and integrations. Coordinates architects, engineers, legal teams, and business leaders; translates technical findings into executive recommendations; develops governance structures, dashboards, KPIs, and status reporting; facilitates risk decisions; and improves assessment processes. The role requires extensive technical program leadership, cybersecurity knowledge, risk management, executive communication, and advanced visual storytelling skills. Top Skills: Architecture DiagramsCis ControlsCloud SecurityCloud TechnologiesCybersecurityDashboardsData ProtectionData VisualizationEndpoint SecurityEnterprise It InfrastructureIdentity And Access ManagementIso 27001Network SecurityNist 800-53Nist CsfProcess MappingSecurity OperationsSoc 2Vulnerability Management What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Fullstack developer salary in Germany [2023]](https://www.wearedevelopers.com/magazine/197-fullstack-developer-salary-in-germany-2023)