Zero Trust Network Access Architect/Engineer

ASRC Federal Holding Company

Quantico (VA)

Hybrid

USD 170,000 - 220,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health care
Dental insurance
Vision insurance
Life insurance
401(k) university matching
Education assistance
Paid time off

Job summary

ASRC Federal Holding Company is seeking a Senior Zero Trust Network Architect / Principal Engineer to lead the DCSA Zero Trust journey. You will architect and implement ZTNA and SASE using Palo Alto Panorama/GlobalProtect and Versa Networks, securing cloud, hybrid, and mobile endpoints.

You will work primarily in a telework capacity with on-site requirements at Quantico, VA two days per week, and additional onboarding time as needed.

Qualifications

  • Minimum of 10 years of progressive experience in network security engineering, enterprise architecture, and infrastructure security.
  • At least 3–4 years of direct experience architecting Zero Trust frameworks (NIST SP 800-207) and SASE solutions in enterprise or federal environments.
  • Active Secret Clearance REQUIRED, eligible for TS/SCI upgrade.
  • Bachelor’s Degree in Cybersecurity, Computer Engineering, Information Systems Management, or related field; Master’s degree accepted.
  • Vendor certifications: PCNSE, PCZTNSE, VCSP or VCSS.

Responsibilities

  • Serve as Principal Architect for the DCSA Zero Trust journey, establishing the technical roadmap and reference architectures aligned with NIST SP 800-207.
  • Lead end-to-end design, implementation, and optimization of Palo Alto GlobalProtect and Versa Networks SASE for cloud, hybrid on‑premises, and mobile endpoints.
  • Define and govern global security policy templates within Palo Alto Panorama to enforce micro-segmentation and threat prevention.
  • Architect DLP, SSL/TLS decryption, and threat prevention strategies across all ingress/egress points.
  • Integrate ZTNA/SASE with IAM (Okta, Azure AD) ensuring real‑time context and posture checks.
  • Guide SOC integration with SIEM, SOAR, and EDR/XDR tools; support secure connectivity automation.
  • Provide technical leadership and mentorship to the cybersecurity engineering team; author HLDs, LLDs, SSPs, and change-management policies.
  • Stay current with Palo Alto PAN-OS and Versa features; run PoCs to evaluate next-generation capabilities.

Skills

ZTNA / Zero Trust
SASE
Palo Alto Networks
Panorama
GlobalProtect
Versa Networks SASE
Active Secret Clearance
NIST SP 800-207
Okta / Azure AD IAM
SOC / SIEM / SOAR / EDR/XDR
Security automation

Education

Bachelor's Degree in Cybersecurity/related field
Master's degree acceptable

Tools

Panorama
GlobalProtect
Versa Networks SASE
Okta / Azure AD integrations
SIEM / SOAR / EDR/XDR tools

Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

Position Description

ASRC Federal is actively hiring a Senior Zero Trust Network Architect / Principal Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico, VA.

We are seeking an industry-leading cybersecurity expert with a deep specialization in Zero Trust Network Architecture (ZTNA) and Secure Access Service Edge (SASE). The successful candidate will serve as the chief technical authority for the design, orchestration, implementation, and long-term governance of our enterprise security boundaries.

In this role, you will lead the strategic modernization of DCSA's hybrid workforce infrastructure. You will leverage Palo Alto Networks (Panorama, GlobalProtect) and Versa Networks SASE platforms to establish a highly resilient, identity-aware, and context-driven security posture.

This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA. Additional onsite time may be required during initial onboarding and program integration.

Minimum Requirements
  • Experience:

  • Minimum of 10 years of progressive experience in network security engineering, enterprise architecture, and infrastructure security.

  • At least 3-4 years of direct experience architecting and implementing Zero Trust frameworks (NIST SP 800-207) and SASE solutions in enterprise or federal environments.

  • Technical Mastery:

  • Advanced architecture-level knowledge of Palo Alto Networks enterprise solutions, including deep management expertise via Panorama and secure access deployments using GlobalProtect .

  • Deep technical proficiency in designing and deploying Versa Networks SASE (SD-WAN, Secure Web Gateway, Cloud Access Security Broker, and Firewall-as-a-Service).

  • Security Clearance: Active Secret Clearance REQUIRED , must be eligible to be upgraded to TS/SCI.

  • Compliance: Must meet 8140 certification requirements (e.g. CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, GICSP)

  • Education: Bachelor's Degree in Cybersecurity, Computer Engineering, Information Systems Management, or a related field. A Master's degree or an equivalent combination of military service and 12+ years of highly relevant experience is accepted.

  • Desired Vendor Certifications:

  • Palo Alto Networks Certified Network Security Engineer (PCNSE)

  • Palo Alto Networks Certified Zero Trust Network Security Engineer (PCZTNSE)

  • Versa Certified SASE Professional (VCSP) or Versa Certified SASE Specialist (VCSS)

Responsibilities
Strategic Architecture & Engineering
  • Serve as the Principal Architect for the DCSA Zero Trust journey, establishing the technical roadmap, reference architectures, and engineering guidelines aligned with NIST SP 800-207 standards.

  • Lead the end-to-end design, implementation, and optimization of Palo Alto GlobalProtect and Versa Networks SASE to secure cloud, hybrid on-premises, and mobile endpoints.

  • Define and govern global security policy templates within Palo Alto Panorama to enforce micro-segmentation, application-level security, and threat prevention.

Policy, Governance & Optimization
  • Architect advanced data loss prevention (DLP), SSL/TLS decryption, and threat prevention strategies across all egress and ingress points.

  • Conduct regular architectural reviews of the SASE and ZTNA configurations to identify performance bottlenecks, configuration drifts, or security gaps, providing advanced mitigation strategies.

Identity & Ecosystem Integration
  • Collaborate with Identity and Access Management (IAM) teams to integrate ZTNA/SASE policies with identity providers (e.g., Okta, Azure AD), ensuring device posture, user context, and continuous authentication are evaluated in real time.

  • Guide the integration of Versa SASE and Palo Alto platforms with existing Security Operations Center (SOC) environments, including SIEM, SOAR, and endpoint detection (EDR/XDR) tools.

Technical Leadership & Mentorship
  • Provide technical leadership and guidance to the cybersecurity engineering team, serving as the tier-4 escalations point for complex architectural, routing, and access control challenges.

  • Author enterprise-level high-level designs (HLD), low-level designs (LLD), system security plans (SSP), and change-management policies for executive-level and government stakeholders.

Vendor & Capability Evaluation
  • Stay abreast of the latest Palo Alto PAN-OS and Versa Networks feature sets, performing proof-of-concepts (PoC) to evaluate and deploy next-generation capabilities.

  • Champion security-as-code and automation initiatives, using APIs and orchestration tools to automate secure connectivity and zero-touch deployments.

Work Environment and Physical Demands
  • This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA. Additional onsite time may be required during initial onboarding and program integration.

  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection

  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form

  • Benefits offered may include health care, dental, vision, life insurance
  • 401(k)
  • education assistance
  • paid time off including PTO, holidays, and any other paid leave required by law.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Job Details
Job Family

Information Technology

Job Function

Cyber Security

Pay Type

Salary

Education Level

Bachelor's Degree

Hiring Min Rate

170,000 USD

Hiring Max Rate

219,695 USD

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Zero Trust Network Access Architect/Engineer
Zero Trust Network Access Architect/Engineer

ASRC Federal • Quantico (VA)

Hybrid
USD 180,000 - 230,000
Health benefits
401(k) plan
Education assistance
+1
Zero Trust Network Access Architect/Engineer
Zero Trust Network Access Architect/Engineer

ASRC Federal • Virginia (IL), Northern (KY)

Hybrid
USD 150,000 - 210,000
Health care
Dental
Vision
+4
Senior Zero Trust Architect (Remote/Hybrid)
Senior Zero Trust Architect (Remote/Hybrid)

ASRC Federal Holding Company • Quantico (VA)

Hybrid
USD 170,000 - 220,000
Health care
Dental insurance
Vision insurance
+4
Senior Cyber Tools Architect/Engineer
Senior Cyber Tools Architect/Engineer

ASRC Federal • Quantico (VA)

On-site
USD 140,000 - 210,000
Health care
Dental
Vision
+4
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Irving (TX)

On-site
USD 170,000 - 230,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Wilmington (DE)

On-site
USD 150,000 - 210,000
Zero Trust Network Architect — Hybrid/Telework, Secret Clearance
Zero Trust Network Architect — Hybrid/Telework, Secret Clearance

ASRC Federal • Quantico (VA)

Hybrid
USD 180,000 - 230,000
Health benefits
401(k) plan
Education assistance
+1
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Socket.dev • California (MO)

On-site
USD 154,000 - 250,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks • Santa Clara (CA)

On-site
USD 154,000 - 250,000
Senior Network Security Architect
Senior Network Security Architect

Stellent IT LLC • San Jose (CA)

On-site
USD 180,000 - 240,000