Illumio Zero Trust Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC

Washington

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary
401k contributions from Day 1
PTO plus 11 holidays
Comprehensive health coverage

Job summary

ENS Solutions, LLC is seeking a skilled cybersecurity and infrastructure engineer to design, deploy, and optimize Illumio Core and Illumio Edge across on-prem, virtualized, and cloud environments. You will architect Zero Trust segmentation, map dependencies, label resources, and enforce boundaries to protect enterprise workloads.

Join a team that integrates Illumio with SIEM, SOAR, CMDB, and vulnerability tools, building dashboards, runbooks, and segmentation models.

Qualifications

  • 5+ years in cybersecurity, cloud security, or infrastructure engineering.
  • 3+ years of Linux/Windows systems, virtualization (VMware, Hyper-V), and cloud environments (AWS, Azure, or GCP).
  • 2+ years developing and deploying solutions for highly regulated mission-critical environments (finance, healthcare, federal, or energy).
  • 1+ year experience with infrastructure automation tools (Ansible, Terraform, or similar).
  • 1+ year experience with REST APIs, scripting (Python, Bash, PowerShell), or automation frameworks.
  • Active TS/SCI clearance; willingness to take a polygraph exam
  • Associate’s degree and 5+ years of experience supporting IT projects and activities, Bachelor’s degree and 3+ years of experience supporting IT projects and activities, or Master’s degree and 1+ years of experience supporting IT projects and activities
  • Ability to obtain CSSP-IS and related certifications within specified windows.

Responsibilities

  • Assist in the design, deployment, configuration, and optimization of Illumio Core and Illumio Edge across on-premises, virtualized, and cloud environments.
  • Architect and implement Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls.
  • Develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications.
  • Integrate Illumio with SIEM/SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines.
  • Conduct traffic flow analysis using Illumio VEN telemetry and build policy recommendations to reduce attack surface and limit east-west movement.
  • Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure.
  • Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes.
  • Perform lifecycle management: upgrades, health checks, certificate operations, and policy governance.
  • Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies.
  • Contribute to architectural standards, documentation, and enterprise security playbooks.

Skills

Cybersecurity
Cloud security
Infrastructure engineering
REST APIs
Scripting
TS/SCI clearance

Education

Associate’s degree
Bachelor’s degree
Master’s degree

Tools

Illumio Core/Edge
VMware
Hyper-V
AWS
Azure
GCP
ServiceNow
SIEM
SOAR
C2C
CMDB

Job description

Assist in the design, deployment, configuration, and optimization of Illumio Core and Illumio Edge across on-premises, virtualized, and cloud environments. Support the architecting and implementation of Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls. Develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications. Integrate Illumio with SIEM, SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines.

Conduct traffic flow analysis using Illumio VEN telemetry and assist in building policy recommendations to reduce attack surface and limit east-west movement. Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure. Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes. Perform lifecycle management, including upgrades, health checks, certificate operations, and policy governance. Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies. Contribute to architectural standards, documentation, and enterprise security playbooks.

Key Responsibilities
  • Assist in the design, deployment, configuration, and optimization of Illumio Core and Illumio Edge across on-premises, virtualized, and cloud environments.

  • Architect and implement Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls.

  • Develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications.

  • Integrate Illumio with SIEM/SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines.

  • Conduct traffic flow analysis using Illumio VEN telemetry and build policy recommendations to reduce attack surface and limit east-west movement.

  • Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure.

  • Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes.

  • Perform lifecycle management: upgrades, health checks, certificate operations, and policy governance.

  • Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies.

  • Contribute to architectural standards, documentation, and enterprise security playbooks.

  • 5+ years in cybersecurity, cloud security, or infrastructure engineering.

  • 3+ years of expertise in Linux/Windows systems, virtualization (VMware, Hyper-V), and cloud environments (AWS, Azure, or GCP).

  • 2+ years of experience developing and deploying solutions for highly regulated mission-critical environments (finance, healthcare, federal, or energy).

  • 1+ year experience with infrastructure automation tools (Ansible, Terraform, or similar).

  • 1+ year experience with REST APIs, scripting (Python, Bash, PowerShell), or automation frameworks.

  • Active TS/SCI clearance; willingness to take a polygraph exam

  • Associate’s degree and 5+ years of experience supporting IT projects and activities, Bachelor’s degree and 3+ years of experience supporting IT projects and activities, or Master’s degree and 1+ years of experience supporting IT projects and activities

  • Ability to obtain a DoD 8570.01-M Cybersecurity Service Provider - Infrastructure Support (CSSP-IS) Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND certification within 30 days of offer accept

  • Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX (formerly CASP+), CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP certification within 45 days of CSSP-IS date (or offer accept if candidate already has CSSP-IS Cert).

Additional Qualifications:
  • Experience deploying and managing Illumio Adaptive Security Platform (ASP) in enterprise environments
  • Experience with CMDB systems such as ServiceNow, SIEM and SOAR tools, or vulnerability management platforms
  • Knowledge of Zero Trust principles, micro-segmentation, and lateral movement mitigation
  • Ability to translate policies into technical controls
  • Possession of strong analytical and problem-solving skills
  • Illumio certifications such as Illumio Platform Associate, Illumio Platform Specialist, Illumio Platform Expert, or Illumio Platform On-Prem PCE Administrator

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?
  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS
  • 401k Contribution from Day 1
  • PTO + 11 Paid Federal Holidays
  • Long & Short Term Disability Insurance
  • Group Term Life Insurance
  • Tuition, Certification & Professional Development Assistance
  • Workers’ Compensation
  • Relocation Assistance
Candidate AI Usage Policy

AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Illumio Zero Trust Engineer - Active TS/SCI with CI Poly
Illumio Zero Trust Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • United States

On-site
USD 140,000 - 190,000
Free Platinum-Level Medical/Dental/VIs
401k Contribution from Day 1
PTO + 11 Paid Holidays
+3
Illumio Zero Trust Engineer - Active TS/SCI with CI Poly
Illumio Zero Trust Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington

On-site
USD 140,000 - 200,000
Free Platinum-Level Medical/Dental/V.\
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+3
Cloud Security Engineer - Active TS/SCI with CI Poly
Cloud Security Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • United States

On-site
USD 120,000 - 180,000
Free Platinum-Level Medical/Dental/VN
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4
Cloud Security Engineer - Active TS/SCI with CI Poly
Cloud Security Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington

On-site
USD 140,000 - 190,000
Free Platinum-Level Medical/Dental/V4
401k contribution from Day 1
PTO + 11 paid holidays
+4
Sr. DevSecOps Engineer - Active TS/SCI with CI Poly
Sr. DevSecOps Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Reston (VA), Northern (KY)

On-site
USD 140,000 - 190,000
Health insurance
401k contribution from day 1
PTO + 11 paid federal holidays
+4
Cloud Security Engineer - Active TS/SCI with CI Poly
Cloud Security Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington, Northern (KY)

On-site
USD 120,000 - 180,000
Free Platinum-Level Medical Coverage
401k Contribution from Day 1
PTO + 11 Holidays
+5
Systems Engineer - Active TS/SCI with CI Poly
Systems Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington

On-site
USD 130,000 - 190,000
Medical coverage
401k
PTO and holidays
+4
Cloud Security Engineer - Active TS/SCI with CI Poly
Cloud Security Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Reston (VA)

On-site
USD 120,000 - 180,000
Medical/dental/vision insurance
401k from day 1
PTO + 11 holidays
+4
Systems Engineer - Active TS/SCI with CI Poly
Systems Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington

On-site
USD 120,000 - 180,000
Medical coverage
401k from Day 1
PTO + 11 Federal Holidays
+4
Senior DevSecOps Engineer - Active TS/SCI with CI Poly
Senior DevSecOps Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Reston (VA), Northern (KY)

On-site
USD 190,000 - 240,000
Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4