Zero Trust Engineer – Tanium / Eclypsium / SteelCloud / Microsoft Defender / Azure

G2IT, LLC.

Suitland (MD)

Hybrid

USD 130,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

G2IT, LLC. is seeking an experienced Zero Trust Engineer to design, implement, and sustain Zero Trust across Navy and DoW environments.

You will integrate endpoint visibility, vulnerability management, and cloud security capabilities to build an integrated security architecture. The role requires hands-on experience with Tanium, Eclypsium, SteelCloud ConfigOS, Defender, and Azure, plus experience delivering managed security in classified environments.

Qualifications

  • Active TS/SCI clearance.
  • 7+ years in cybersecurity/systems/cloud/infrastructure, with DoD/IC exposure.
  • Hands-on experience with Zero Trust architectures in complex environments.
  • Experience with Tanium, Eclypsium, SteelCloud ConfigOS, Defender, Azure, and Azure Bicep.

Responsibilities

  • Engineer, deploy, configure, integrate, and sustain Zero Trust capabilities across Navy/DoW environments.
  • Implement Zero Trust principles per DoD strategy and roadmap.
  • Deploy and administer Tanium for endpoint visibility, vulnerability management and remediation.
  • Implement Eclypsium for firmware and device security visibility and risk identification.
  • Configure SteelCloud ConfigOS for STIG compliance and continuous configuration management.
  • Integrate Defender capabilities for endpoint protection, threat detection, and response.
  • Design secure Azure environments with IAM, policies, networking, monitoring and logging.
  • Develop IaC templates in Azure Bicep for repeatable deployments.
  • Create architecture diagrams, SOPs, and runbooks for zero trust implementations.

Skills

Zero Trust
DoD experience
Security architecture

Tools

Tanium
Eclypsium
SteelCloud ConfigOS
Microsoft Defender
Microsoft Azure
Azure Bicep

Job description

Clearance: Active TS/SCI

Location: Customer/DoD facility; on-site/hybrid as mission requirements permit

Environment: U.S. Navy / Department of War classified and mission-critical networks

Position Overview

G2IT is seeking an experienced Zero Trust Engineer to design, implement, integrate, and sustain Zero Trust capabilities across classified and unclassified Navy and DoW enterprise environments. The engineer will support the modernization and hardening of complex IT environments by integrating endpoint visibility, vulnerability and firmware security, configuration compliance, threat protection, identity, and cloud security capabilities.

The ideal candidate has hands‑on experience with Tanium, Eclypsium, SteelCloud ConfigOS, Microsoft Defender, Microsoft Azure, and Azure Bicep, and understands how these technologies contribute to an integrated Zero Trust architecture rather than operating as independent security tools.

Key Responsibilities
  • Engineer, deploy, configure, integrate, and sustain Zero Trust security capabilities across Navy and DoW enterprise environments.
  • Implement Zero Trust principles consistent with DoD Zero Trust Strategy and Zero Trust Capability Execution Roadmap, including continuous verification, least‑privilege access, endpoint/device trust, visibility, automation, and policy enforcement.
  • Deploy and administer Tanium capabilities supporting endpoint visibility, asset discovery, vulnerability management, configuration management, compliance, and remediation.
  • Implement and support Eclypsium for firmware, hardware, supply‑chain, and device‑level security visibility and risk identification.
  • Engineer and administer SteelCloud ConfigOS to automate STIG compliance, security configuration, remediation, and continuous compliance activities.
  • Configure and integrate Microsoft Defender capabilities for endpoint protection, threat detection, vulnerability management, investigation, and response.
  • Design and support secure Microsoft Azure environments, including implementation of security controls, policies, identity, networking, monitoring, and logging.
  • Develop and maintain Azure Bicep Infrastructure-as-Code (IaC) templates to provide repeatable, controlled, and auditable deployment of Azure infrastructure and security configurations.
  • Integrate security platforms and telemetry to establish a consolidated view of device posture, vulnerability, configuration compliance, threats, and remediation status.
  • Develop automated workflows for identifying, prioritizing, and remediating vulnerabilities and configuration deficiencies.
  • Support implementation and validation of DISA STIGs, Security Technical Implementation requirements, RMF controls, and applicable DoD cybersecurity policies.
  • Work with cybersecurity, network, cloud, systems engineering, and operations teams to incorporate Zero Trust requirements into existing and emerging architectures.
  • Support security assessments, ATO/RMF activities, POA&M remediation, vulnerability management, and continuous monitoring.
  • Develop architecture diagrams, engineering documentation, implementation procedures, SOPs, configuration baselines, and operational runbooks.
  • Troubleshoot complex integration and interoperability issues across security, endpoint, cloud, network, and identity platforms.
  • Provide technical recommendations to government engineering and cybersecurity leadership regarding Zero Trust architecture, technology selection, implementation priorities, and risk.
Required Qualifications
  • Active TS/SCI clearance.
  • 7+ years of cybersecurity, systems engineering, cloud engineering, or enterprise infrastructure experience, with significant experience supporting DoD or Intelligence Community environments.
  • Demonstrated experience implementing or supporting Zero Trust architectures and cybersecurity controls in complex enterprise environments.
  • Hands‑on experience with several of the following, with strong expertise in at least two or three:
    • Tanium
    • Eclypsium
    • SteelCloud ConfigOS
    • Microsoft Defender
    • Microsoft Azure / Azure Government
    • Azure Bicep / Infrastructure as Code
  • Experience with endpoint security, vulnerability management, configuration management, continuous monitoring, and security compliance.
  • Working knowledge of DISA STIGs, RMF, NIST 800‑53, DoD cybersecurity requirements and vulnerability remediation processes.
  • Experience engineering solutions in classified and/or disconnected/restricted DoD environments.
  • Understanding of Windows Server, Windows endpoints, Active Directory/Entra ID, networking, virtualization, and enterprise infrastructure.
  • Ability to develop technical documentation and communicate complex cybersecurity concepts to both engineering teams and government leadership.
  • Ability to work independently in a mission environment while collaborating with government personnel, OEMs, integrators, and other engineering teams.
Preferred Qualifications

Experience with Azure Government, IL5/IL6 environments, Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, PowerShell, Git/Azure DevOps, Terraform, REST APIs, SIEM/SOAR platforms, ACAS/Tenable, Splunk, ServiceNow, and automated STIG/compliance workflows is highly desirable.

Relevant certifications may include Security+, CISSP, CASP+/SecurityX, Microsoft Azure Security Engineer, Azure Administrator, Azure Solutions Architect, Tanium certifications, or comparable DoD 8140-aligned credentials.

Salary range: $130K-$150K, depending on experience

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Zero Trust Engineer – Tanium / Eclypsium / SteelCloud / Microsoft Defender / Azure
Zero Trust Engineer – Tanium / Eclypsium / SteelCloud / Microsoft Defender / Azure

G2IT • Suitland (MD)

On-site
USD 158,000 - 193,000
Zero Trust Engineer — Navy/DoD SecOps (Tanium, Azure)
Zero Trust Engineer — Navy/DoD SecOps (Tanium, Azure)

G2IT • Suitland (MD)

On-site
USD 158,000 - 193,000
Zero Trust Engineer (DoD/Navy) – Tanium & Azure
Zero Trust Engineer (DoD/Navy) – Tanium & Azure

G2IT, LLC. • Suitland (MD)

Hybrid
USD 130,000 - 150,000
Zero Trust Cybersecurity Engineer
Zero Trust Cybersecurity Engineer

ProTalent Finders • Washington

Hybrid
USD 100,000 - 140,000
Competitive compensation
PTO and paid holidays
Continuing education reimbursements
+2
Zero Trust Identity and ICAM Engineer Mid Level
Zero Trust Identity and ICAM Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 120,000 - 180,000
401(k)
Competitive salary
Dental insurance
+5
Zero Trust Architecture Specialist
Zero Trust Architecture Specialist

Cornerstone Defense LLC • Bethesda (MD), Northern (KY)

Hybrid
USD 180,000 - 240,000
Zero Trust Engineer Mid Level
Zero Trust Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Dental insurance
Health insurance
+3
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph

Synertex LLC • Bethesda (MD)

On-site
USD 140,000 - 180,000
Senior Zero Trust Identity and ICAM Engineer
Senior Zero Trust Identity and ICAM Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 135,000 - 180,000
401(k)
Competitive salary
Dental insurance
+4
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph, Immediate Hire
Zero Trust Architecture Specialist- Bethesda, MD; Must have an active TS/SCI with Polygraph, Immediate Hire

Synertex LLC • Bethesda (MD)

On-site
USD 180,000 - 260,000