waypointjobs

CELESTIAL INNOVATIONS GROUP LLC

Zero Trust Identity and ICAM Engineer Mid Level

washington, DC

Check who can apply and the requirements below before continuing.

Availability awaiting confirmation

We are waiting for a fresh update from the source. This page preserves the last received job details; current availability is not confirmed.

Job description

Benefits:

401(k)

Competitive salary

Dental insurance

Health insurance

Opportunity for advancement

Paid time off

Training & development

Vision insurance

POSITION SUMMARY

Celestial Innovations Group (CIG) is seeking a Zero Trust Identity and ICAM Engineer to own end-to-end access policy design across the identity, endpoint, network, and application layers for federal agency clients, spanning the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform, guided by the principle of “never trust, always verify.” The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model and Secure Access Service Edge (SASE) guidance. These responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, acting as Trust Brokers across the enterprise, so the organization can maintain a strong security posture ahead of adversaries.

Must be located in the DC Metro Area as this role requires onsite and remote support.

KEY RESPONSIBILITIES

Architecture and Strategy

Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients

Design and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and Data

Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans

Develop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks

Support integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks

Drive SASE convergence, consolidating network and security enforcement onto a single policy plane

Advance security posture design and real-time trust evaluation, with a focus on insider threat detection and response

Implementation and Engineering

Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)

Own top-level Conditional Access policy design and privileged access governance in Microsoft Entra ID/M365

Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management

Deliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems

Enforce device posture as a condition of every access decision, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals

Define and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra ID, and Workspace ONE (WS1)

Configure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls across the network landscape, including Palo Alto, Cisco, and wireless infrastructure

Deploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale

Integrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements

Compliance and Authorization

Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirements

Support the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance

Document ZTA controls for system security packages, POA&Ms, and security assessment reports

Own access policy exception management, including governance workflows and audit-ready evidence documentation

Client Engagement and Collaboration

Serve as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts

Produce executive-level briefings, technical white papers, and implementation status reports

Collaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration

VENDOR ECOSYSTEM EXPERIENCE

CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:

Vendor / Framework & Relevant Capabilities

Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars

Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection

Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center

CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements

Additional Enterprise Tooling: SCCM, Workspace ONE (WS1), Qualys vulnerability management, and Cisco network/wireless fabric, supporting device posture and network segmentation enforcement across the landscape

REQUIRED QUALIFICATIONS

Experience

5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles

2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environment

Demonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model

Experience supporting federal government clients or DoD/civilian agency environments

Technical Skills

Proficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stack

Identity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM tooling; Federal PKI/ICAM experience, with demonstrated hands‑on PIV/PIV‑I Smartcard credential issuance and lifecycle management

Intercede MyID CMS Enterprise architecture and deployment: hands‑on experience designing, deploying, configuring, and operating Intercede MyID CMS Enterprise, including credential profiles, enrollment workflows, Smartcard issuance, certificate provisioning, renewal, revocation, and integration with PKI and enterprise identity services

Microsoft Entra Certificate Based Authentication (CBA)

Network security: microsegmentation, ZTNA, DNS security, SD-WAN, next‑generation firewall policy

Endpoint security: EDR/XDR deployment and management, device compliance policy enforcement

Cloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlay

Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)

PREFERRED QUALIFICATIONS

Active certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA‑IA or ZCCA‑PA, Microsoft SC‑100 (Cybersecurity Architect Expert)

Additional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certifications

Familiarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation

Experience with ServiceNow, Salesforce, or IT service management tooling in a federal context

Multi‑vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)

Flexible work from home options available.

#J-18808-Ljbffr

Worksite address

washington, DC, 20022, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Explore related searches

Current related jobs

U.S. Army Corps of Engineers

USAJOBS

Interdisciplinary Waterways Maintenance Chief

Portland, OR

$114,684.00 – $149,091.00 per yearfull time

About the Position: As Chief of the Waterways Maintenance Section, the incumbent exercises full technical, administrative, and managerial authori…

Closes 2026-10-16View job

U.S. Army Corps of Engineers

USAJOBS

ENGINEERING TECHNICIAN (CIVIL)

Philadelphia, PA

$44,887.00 – $106,982.00 per yearfull time

About the position: Serves as cost estimator responsible for the preparation of budget, control and detailed final estimates of cost pertaining t…

Closes 2026-10-19View job

U.S. Coast Guard

USAJOBS

NAVAL ARCHITECT

Washington, DC

$121,785.00 – $158,322.00 per yearfull time

This vacancy is for a GS-0871-13, NAVAL ARCHITECT located in the Department of Homeland Security, U.S. Coast Guard, USCG MARINE SAFETY CENTER in …

Closes 2026-10-14View job

U.S. Coast Guard

USAJOBS

NAVAL ARCHITECT

Washington, DC

$121,785.00 – $158,322.00 per yearfull time

This vacancy is for a GS-0871-13, NAVAL ARCHITECT located in the Department of Homeland Security, U.S. Coast Guard, USCG MARINE SAFETY CENTER in …

Closes 2026-10-14View job

U.S. Army Corps of Engineers

USAJOBS

Interdisciplinary

Baltimore, MD

$102,415.00 – $133,142.00 per yearfull time

About the Position: You will be responsible for the environmental assessment of hazardous, toxic, and radiological waste (HTRW) sites and Militar…

Closes 2026-10-15View job

U.S. Army Corps of Engineers

USAJOBS

Student Trainee (Engineering and Architecture)

Lakewood, CO

$36,464.00 – $89,470.00 per yearfull time

About the Position: Position(s) will be filled under the Department of the Army Pathways Internship "Indefinite" Program. Click here for more inf…

Closes 2026-10-12View job