Zero Trust Identity and ICAM Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC

Washington (District of Columbia)

Hybrid

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k)
Competitive salary
Dental insurance
Health insurance
Opportunity for advancement
Paid time off
Training & development
Vision insurance

Job summary

Celestial Innovations Group (CIG) seeks a Zero Trust Identity and ICAM Engineer to own end-to-end access policy design across identity, endpoint, network and applications for federal agency clients, guiding ZTA programs per EO 14028 and NIST SP 800-207. The role combines architecture, implementation and sustainment, with onsite work in the DC metro area and remote support as needed.

You will lead assessments, document ZTA solutions, and integrate Entra ID, Intune, SCCM, Purview, and Palo

Qualifications

  • 5+ years in cybersecurity, network security, or IT infrastructure roles.
  • 2+ years designing or implementing Zero Trust Architecture in federal environments.
  • Understanding of ZTA across five pillars per NIST SP 800-207.
  • Experience with federal government or DoD environments.

Responsibilities

  • Lead Zero Trust Architecture assessments, gap analyses, and roadmaps for federal clients.
  • Design ZTA solutions spanning Identity, Device, Network, Application/Workload, and Data pillars.
  • Translate mandates into actionable implementation plans (EO 14028, NIST SP 800-207).
  • Develop ZTA documentation using frameworks like DODAF or TOGAF.
  • Support integration of ZTA into existing architectures and hybrid cloud environments.
  • Drive SASE convergence and policy-plane unification.
  • Advance insider threat detection and response capabilities.

Skills

Zero Trust
ZTA concepts
Federally compliant
Access policy design

Tools

Palo Alto Prisma
Zscaler
Microsoft Entra ID
Intune
SCCM
Workspace ONE
Purview
Qualys

Job description

Benefits:


  • 401(k)

  • Competitive salary

  • Dental insurance

  • Health insurance

  • Opportunity for advancement

  • Paid time off

  • Training & development

  • Vision insurance


POSITION SUMMARY

Celestial Innovations Group (CIG) is seeking a Zero Trust Identity and ICAM Engineer to own end-to-end access policy design across the identity, endpoint, network, and application layers for federal agency clients, spanning the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform, guided by the principle of “never trust, always verify.” The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model and Secure Access Service Edge (SASE) guidance. These responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, acting as Trust Brokers across the enterprise, so the organization can maintain a strong security posture ahead of adversaries.


Must be located in the DC Metro Area as this role requires onsite and remote support.


KEY RESPONSIBILITIES
Architecture and Strategy


  • Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients

  • Design and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and Data

  • Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans

  • Develop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks

  • Support integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks

  • Drive SASE convergence, consolidating network and security enforcement onto a single policy plane

  • Advance security posture design and real-time trust evaluation, with a focus on insider threat detection and response


Implementation and Engineering


  • Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)

  • Own top-level Conditional Access policy design and privileged access governance in Microsoft Entra ID/M365

  • Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management

  • Deliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems

  • Enforce device posture as a condition of every access decision, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals

  • Define and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra ID, and Workspace ONE (WS1)

  • Configure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls across the network landscape, including Palo Alto, Cisco, and wireless infrastructure

  • Deploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale

  • Integrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements


Compliance and Authorization


  • Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirements

  • Support the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance

  • Document ZTA controls for system security packages, POA&Ms, and security assessment reports

  • Own access policy exception management, including governance workflows and audit-ready evidence documentation


Client Engagement and Collaboration


  • Serve as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts

  • Produce executive-level briefings, technical white papers, and implementation status reports

  • Collaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration


VENDOR ECOSYSTEM EXPERIENCE

CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:


Vendor / Framework & Relevant Capabilities


  • Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars

  • Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection

  • Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center

  • CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements

  • Additional Enterprise Tooling: SCCM, Workspace ONE (WS1), Qualys vulnerability management, and Cisco network/wireless fabric, supporting device posture and network segmentation enforcement across the landscape


REQUIRED QUALIFICATIONS
Experience


  • 5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles

  • 2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environment

  • Demonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model

  • Experience supporting federal government clients or DoD/civilian agency environments


Technical Skills


  • Proficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stack

  • Identity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM tooling; Federal PKI/ICAM experience, with demonstrated hands‑on PIV/PIV‑I Smartcard credential issuance and lifecycle management

  • Intercede MyID CMS Enterprise architecture and deployment: hands‑on experience designing, deploying, configuring, and operating Intercede MyID CMS Enterprise, including credential profiles, enrollment workflows, Smartcard issuance, certificate provisioning, renewal, revocation, and integration with PKI and enterprise identity services

  • Microsoft Entra Certificate Based Authentication (CBA)

  • Network security: microsegmentation, ZTNA, DNS security, SD-WAN, next‑generation firewall policy

  • Endpoint security: EDR/XDR deployment and management, device compliance policy enforcement

  • Cloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlay

  • Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)


PREFERRED QUALIFICATIONS


  • Active certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA‑IA or ZCCA‑PA, Microsoft SC‑100 (Cybersecurity Architect Expert)

  • Additional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certifications

  • Familiarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation

  • Experience with ServiceNow, Salesforce, or IT service management tooling in a federal context

  • Multi‑vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)


Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Zero Trust Identity and ICAM Engineer
Senior Zero Trust Identity and ICAM Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 135,000 - 180,000
401(k)
Competitive salary
Dental insurance
+4
Zero Trust Engineer Mid Level
Zero Trust Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 100,000 - 130,000
401(k)
Dental insurance
Health insurance
+3
ZERO TRUST (ZT) NETWORK ARCHITECTURE SME
ZERO TRUST (ZT) NETWORK ARCHITECTURE SME

Zermount, Inc. • Arlington (VA)

Hybrid
USD 120,000 - 160,000
Zero Trust Strategist
Zero Trust Strategist

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Zero Trust (ZT) Technical Lead
Zero Trust (ZT) Technical Lead

Zermount, Inc. • Arlington (VA)

Hybrid
USD 120,000 - 160,000
Zero Trust Security Architect
Zero Trust Security Architect

Brooksource • United States

Hybrid
USD 140,000 - 190,000
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMEN[...]
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMEN[...]

Zermount, Inc. • Arlington (VA)

On-site
USD 130,000 - 160,000
Zero Trust (ZT) Technical Lead
Zero Trust (ZT) Technical Lead

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Zero Trust Architecture Specialist
Zero Trust Architecture Specialist

Cornerstone Defense LLC • Bethesda (MD), Northern (KY)

Hybrid
USD 180,000 - 240,000
ZERO TRUST (ZT) ENDPOINT & CONNECTED SYSTEMS SME
ZERO TRUST (ZT) ENDPOINT & CONNECTED SYSTEMS SME

Zermount, Inc. • Arlington (VA)

Hybrid
USD 120,000 - 150,000