Full-Time

Zero Trust Engineer

Multiple Teams

Posted on 9/8/2026

G2IT

G2IT

Compensation Overview

$175/hr

No H1B Sponsorship

Suitland-Silver Hill, MD, USA

Hybrid

On-site or hybrid work is determined by mission requirements.

US Top Secret Clearance Required

Category
Cybersecurity (1)
Required Skills
PowerShell
Microsoft Azure
LDAP
Git
ServiceNow
Microsoft Windows
Computer Networking
Infrastructure as Code (IaC)
Vulnerability Analysis
Terraform
REST APIs
Splunk
Requirements
  • Active TS/SCI clearance.
  • 7+ years of cybersecurity, systems engineering, cloud engineering, or enterprise infrastructure experience, with significant experience supporting Department of Defense or Intelligence Community environments.
  • Demonstrated experience implementing or supporting Zero Trust architectures and cybersecurity controls in complex enterprise environments.
  • Hands-on experience with several of Tanium, Eclypsium, SteelCloud ConfigOS, Microsoft Defender, Microsoft Azure or Azure Government, and Azure Bicep or Infrastructure as Code, with strong expertise in at least two or three.
  • Experience with endpoint security, vulnerability management, configuration management, continuous monitoring, and security compliance.
  • Working knowledge of DISA STIGs, Risk Management Framework, NIST 800-53, Department of Defense cybersecurity requirements, and vulnerability remediation processes.
  • Experience engineering solutions in classified and/or disconnected or restricted Department of Defense environments.
  • Understanding of Windows Server, Windows endpoints, Active Directory or Entra ID, networking, virtualization, and enterprise infrastructure.
  • Ability to develop technical documentation and communicate complex cybersecurity concepts to engineering teams and government leadership.
  • Ability to work independently in a mission environment while collaborating with government personnel, original equipment manufacturers, integrators, and other engineering teams.
Responsibilities
  • Engineer, deploy, configure, integrate, and sustain Zero Trust security capabilities across Navy and Department of War enterprise environments.
  • Implement Zero Trust principles consistent with the Department of Defense Zero Trust Strategy and Zero Trust Capability Execution Roadmap, including continuous verification, least-privilege access, endpoint and device trust, visibility, automation, and policy enforcement.
  • Deploy and administer Tanium capabilities supporting endpoint visibility, asset discovery, vulnerability management, configuration management, compliance, and remediation.
  • Implement and support Eclypsium for firmware, hardware, supply-chain, and device-level security visibility and risk identification.
  • Engineer and administer SteelCloud ConfigOS to automate STIG compliance, security configuration, remediation, and continuous compliance activities.
  • Configure and integrate Microsoft Defender capabilities for endpoint protection, threat detection, vulnerability management, investigation, and response.
  • Design and support secure Microsoft Azure environments, including security controls, policies, identity, networking, monitoring, and logging.
  • Develop and maintain Azure Bicep Infrastructure-as-Code templates for repeatable, controlled, and auditable deployment of Azure infrastructure and security configurations.
  • Integrate security platforms and telemetry to establish a consolidated view of device posture, vulnerability, configuration compliance, threats, and remediation status.
  • Develop automated workflows for identifying, prioritizing, and remediating vulnerabilities and configuration deficiencies.
  • Support implementation and validation of DISA STIGs, Security Technical Implementation requirements, RMF controls, and applicable Department of Defense cybersecurity policies.
  • Work with cybersecurity, network, cloud, systems engineering, and operations teams to incorporate Zero Trust requirements into existing and emerging architectures.
  • Support security assessments, ATO/RMF activities, POA&M remediation, vulnerability management, and continuous monitoring.
  • Develop architecture diagrams, engineering documentation, implementation procedures, standard operating procedures, configuration baselines, and operational runbooks.
  • Troubleshoot complex integration and interoperability issues across security, endpoint, cloud, network, and identity platforms.
  • Provide technical recommendations to government engineering and cybersecurity leadership regarding Zero Trust architecture, technology selection, implementation priorities, and risk.
Desired Qualifications
  • Experience with Azure Government, IL5/IL6 environments, Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, PowerShell, Git or Azure DevOps, Terraform, REST APIs, SIEM/SOAR platforms, ACAS/Tenable, Splunk, ServiceNow, and automated STIG or compliance workflows.
  • Relevant certifications such as Security+, CISSP, CASP+/SecurityX, Microsoft Azure Security Engineer, Azure Administrator, Azure Solutions Architect, Tanium certifications, or comparable DoD 8140-aligned credentials.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A