Contractor - Enterprise Technology Systems

TechWish

Vienna (VA)

On-site

USD 90,000 - 130,000

Full time

3 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

TechWish in Vienna, Virginia is seeking a Zero Trust Readiness Analyst to analyze existing network, identity, and access configurations to determine what can be reused, refined, or newly created to support Zero Trust security policies. This role focuses on investigation, discovery, and design input, not rule implementation.

The analyst works closely with Zero Trust Engineers, IAM teams, and firewall/security teams to ensure Zero Trust policies are grounded in accurate understanding of the

Qualifications

  • Strong understanding of network security fundamentals.
  • Experience analyzing enterprise firewall rule-bases (Palo Alto or similar).
  • Familiarity with identity-based access controls (AD groups, Entra ID groups, RBAC).
  • Ability to read and interpret complex security configurations and translate them into actionable requirements.
  • Experience documenting security findings in a clear, structured manner.

Responsibilities

  • Analyze existing network security rules, firewall policies, address groups, and user/group-based access controls to determine Zero Trust applicability and reuse.
  • Review current identity sources (AD, Entra ID, IGA, RBAC structures) to identify reusable groupings or role models for Zero Trust enforcement.
  • Assess application access patterns (web, console, database, API, internal services) to understand required network paths and trust boundaries.
  • Identify gaps, overlaps, and overly permissive rules that must be remediated to align with Zero Trust principles.
  • Determine whether existing firewall rules, user groups, and address objects can be leveraged or must be redesigned for Zero Trust enforcement.
  • Document required net new security objects, including user groups, address groups, application definitions, and metadata dependencies.
  • Support application onboarding by validating that proposed Zero Trust rules meet least privilege access requirements.
  • Produce clear analysis artifacts that define: o What exists today o What can be reused o What must be created new
  • Provide structured inputs to Zero Trust Engineers for rule implementation and firewall request packages.
  • Maintain traceability between application identifiers, security objects, and Zero Trust policies for audit and compliance purposes.

Skills

Network security basics
Firewall rule analysis
Identity-based access control
Security configurations translation
Documentation skills

Job description

Description

Note: The selected candidate will not start until 6/1/2026. The Zero Trust Security Analyst is responsible for analyzing existing network, identity, and access configurations to determine what can be reused, refined, or must be newly created to support Zero Trust security policies. This role focuses on investigation, discovery, and design input, not rule implementation. The analyst works closely with Zero Trust Engineers, application owners, IAM teams, and firewall/security teams to ensure Zero Trust policies are grounded in accurate understanding of the current environment and avoid unnecessary duplication or overly permissive controls.

Key Responsibilities
  • Analyze existing network security rules, firewall policies, address groups, and user/group-based access controls to determine Zero Trust applicability and reuse.
  • Review current identity sources (AD, Entra ID, IGA, RBAC structures) to identify reusable groupings or role models for Zero Trust enforcement.
  • Assess application access patterns (web, console, database, API, internal services) to understand required network paths and trust boundaries.
Zero Trust Readiness Assessment
  • Identify gaps, overlaps, and overly permissive rules that must be remediated to align with Zero Trust principles.
  • Determine whether existing firewall rules, user groups, and address objects can be leveraged or must be redesigned for Zero Trust enforcement.
  • Document required net new security objects, including user groups, address groups, application definitions, and metadata dependencies.
  • Support application onboarding by validating that proposed Zero Trust rules meet least privilege access requirements.
Documentation & Handoff
  • Produce clear analysis artifacts that define: o What exists today o What can be reused o What must be created new
  • Provide structured inputs to Zero Trust Engineers for rule implementation and firewall request packages.
  • Maintain traceability between application identifiers, security objects, and Zero Trust policies for audit and compliance purposes.
Required Skills & Experience
  • Strong understanding of network security fundamentals (firewalls, zones, L4/L7 rules).
  • Experience analyzing enterprise firewall rule-bases (Palo Alto or similar).
  • Familiarity with identity-based access controls (AD groups, Entra ID groups, RBAC).
  • Ability to read and interpret complex security configurations and translate them into actionable requirements.
  • Experience documenting security findings in a clear, structured manner.
Preferred Qualifications
  • Experience with Zero Trust Network Access (ZTNA) or user-based firewall policies.
  • Exposure to IAM, IGA, or identity governance tooling.
  • Familiarity with CMDB, application identifiers, and service onboarding workflows.
  • Prior experience supporting audits or security assessments.
Success Looks Like
  • Minimal re work due to accurate upfront analysis.
  • Clear reuse of existing controls where appropriate.
  • Well defined, least privilege Zero Trust requirements handed to engineering teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Zero Trust Security Consultant - Hybrid role - Locals Only
Zero Trust Security Consultant - Hybrid role - Locals Only

Zillion Technologies, Inc. • Pensacola (FL)

Hybrid
Medical insurance
Dental insurance
Vision insurance
+2
Zero Trust Security Engineer
Zero Trust Security Engineer

247Hire • Vienna (VA)

On-site
USD 110,000 - 140,000
Zero Trust Security Architect
Zero Trust Security Architect

Brooksource • United States

Hybrid
USD 140,000 - 190,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Irving (TX)

On-site
USD 170,000 - 230,000
Zero Trust Engineer Mid Level
Zero Trust Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Dental insurance
Health insurance
+3
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Wilmington (DE)

On-site
USD 150,000 - 210,000
Zero Trust Identity and ICAM Engineer Mid Level
Zero Trust Identity and ICAM Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 120,000 - 180,000
401(k)
Competitive salary
Dental insurance
+5
Zero Trust Cybersecurity Engineer
Zero Trust Cybersecurity Engineer

ProTalent Finders • Washington

Hybrid
USD 100,000 - 140,000
Competitive compensation
PTO and paid holidays
Continuing education reimbursements
+2
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Urbandale (IA)

On-site
USD 127,000 - 236,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Zero Trust Identity and ICAM Engineer
Senior Zero Trust Identity and ICAM Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 135,000 - 180,000
401(k)
Competitive salary
Dental insurance
+4