user avatar

Zero Trust Network Access Architect/Engineer 102446

Information Technology Engineering Corporation

Posted today

Job Requirements

Quantico, VA
Secret Polygraph None
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Senior Zero Trust Network Architect / Principal Engineer 
Location: Quantico, VA 
Required Clearance: Secret (TS/SCI Eligible) 

Since 1999, ITEC has delivered mission-critical support to the DoD and Intelligence Community. Now part of ManpowerGroup Public Sector (MGPS), we continue that work with expanded capabilities. Employees hired through this process will join MGPS and receive a comprehensive benefits package and competitive pay.  

U.S. Citizenship Mandatory: Due to our US federal government contract, candidates for this position are required to be a US Citizen and will be subject to a background investigation.  

Job Description:

MGPS is seeking an industry-leading cybersecurity expert to serve as a Senior Zero Trust Network Architect / Principal Engineer supporting the Defense Counterintelligence and Security Agency (DCSA) program. The position will serve as the chief technical authority for the architecture, implementation, orchestration, optimization, and governance of enterprise security boundaries.

The successful candidate will lead the strategic modernization of DCSA's hybrid workforce infrastructure, leveraging Palo Alto Networks technologies, including Panorama and GlobalProtect, and Versa Networks SASE solutions to establish a resilient, identity-aware, and context-driven security architecture aligned with NIST SP 800-207 Zero Trust principles. 

This is primarily a telework position requiring onsite support at Quantico Marine Corps Base, VA, at least two days per week or as needed, with additional onsite presence potentially required during onboarding and program integration. 

  • Job Responsibilities:
  • Serve as the Principal Architect for DCSA's Zero Trust modernization, establishing technical roadmaps, reference architectures, and engineering standards aligned with NIST SP 800-207.
  • Lead the design, implementation, optimization, and governance of Palo Alto GlobalProtect and Versa Networks SASE solutions across cloud, hybrid, on-premises, and mobile environments.
  • Define and govern enterprise security policies through Palo Alto Panorama, including micro-segmentation, application security, and threat prevention.
  • Architect DLP, SSL/TLS decryption, and advanced threat prevention strategies across enterprise ingress and egress points.
  • Conduct architectural and configuration reviews of ZTNA and SASE environments to identify security gaps, configuration drift, and performance bottlenecks.
  • Develop and implement mitigation strategies to improve security, resilience, and performance.
  • Establish enterprise-level security architecture, governance, and change-management practices.
  • Collaborate with IAM teams to integrate Zero Trust and SASE policies with identity providers such as Okta and Azure AD, incorporating user identity, device posture, and contextual access controls.
  • Guide integration of Palo Alto and Versa platforms with SOC technologies, including SIEM, SOAR, EDR, and XDR solutions.
  • Provide technical leadership and mentorship to cybersecurity engineering teams and serve as the Tier 4 escalation point for complex architecture, routing, and access-control issues.
  • Develop enterprise-level High-Level Designs (HLDs), Low-Level Designs (LLDs), System Security Plans (SSPs), and technical policies for government and executive stakeholders.
  • Communicate complex technical concepts effectively to technical and non-technical stakeholders in both written and verbal formats.
  • Evaluate emerging Palo Alto Networks and Versa Networks capabilities through proof-of-concept initiatives and recommend solutions that improve enterprise security.
  • Champion security-as-code and automation initiatives using APIs and orchestration tools to support secure connectivity and zero-touch deployments. 

Required Skills:

  • 10+ years of progressive experience in network security engineering, enterprise architecture, and infrastructure security.
  • 3–4+ years of direct experience architecting and implementing Zero Trust frameworks and SASE solutions in enterprise or federal environments.
  • Advanced architecture-level expertise with Palo Alto Networks, including Panorama and GlobalProtect.
  • Advanced experience designing and deploying Versa Networks SASE, including SD-WAN, Secure Web Gateway, CASB, and Firewall-as-a-Service.
  • Strong knowledge of NIST SP 800-207 Zero Trust Architecture principles.
  • Experience with enterprise security policies, micro-segmentation, DLP, SSL/TLS decryption, and threat prevention.
  • Experience integrating security architectures with IAM, SIEM, SOAR, EDR/XDR, and identity providers.
  • Experience with cybersecurity automation, APIs, orchestration, and security-as-code concepts.
  • Ability to develop and communicate enterprise architecture and security documentation, including HLDs, LLDs, and SSPs.
  • Ability to lead technical teams and resolve complex architectural, routing, and access-control challenges.
  • Must meet DoD 8140 certification requirements, such as CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, or GICSP.  

Desired Skills:

  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • Palo Alto Networks Certified Zero Trust Network Security Engineer (PCZTNSE)
  • Versa Certified SASE Professional (VCSP)
  • Versa Certified SASE Specialist (VCSS)
  • Experience supporting federal or Department of Defense cybersecurity programs.
  • Experience evaluating emerging network security technologies through proof-of-concept initiatives.
  • Experience implementing automated and zero-touch security deployments.  

Required Education:

  • Bachelor's degree in Cybersecurity, Computer Engineering, Information Systems Management, or a related field.
  • A Master's degree or an equivalent combination of military service and 12+ years of highly relevant experience may be accepted in lieu of the bachelor's degree requirement.  

Work Environment:

  • Primarily telework with onsite support at Quantico Marine Corps Base, VA, at least two days per week or as required.
  • Additional onsite support may be required during initial onboarding and program integration.
  • When working from an alternate location, employees must have reliable voice communication capabilities, preferably a cell phone, and a stable, capable internet connection.
group id: 91138733B
job ad image
Find Information Technology Engineering Corporation on Social Media
Recruiters
user avatar
About Us
Since 1999, ITEC has maintained a strong and reputable presence in support of DoD and Intelligence community mission-critical programs. Our strong company culture, competitive pay, great benefits package, and our friendly, welcoming atmosphere allows us to retain the most skilled technical resources in the industry. ITEC offers its employees a comprehensive benefits and recognition program.
job ad2 image

Information Technology Engineering Corporation Jobs


Job Category
IT - Hardware
Clearance Level
Secret