Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Amatriot Group, LLC seeks a Zero Trust Network Access Architect/Engineer to support the DCSA program in Quantico, VA. You will lead design, implementation and governance of enterprise security boundaries, focusing on remote work modernization with SASE, ZTNA, and identity-aware controls.
The role requires 10+ years in network security engineering and hands-on experience with Palo Alto GlobalProtect, Panorama and Versa SASE, plus relevant certifications and a active Secret clearance.
Location Quantico VA Hybrid 2 days onsite Security Clearance Active Secret or higher Required Job Type Full Time Target Salary Range 190000 220000 This represents the potential salary range for this position depending on education level years of experience andor certifications in addition to other position specific requirements which may impact salary
Amatriot is hiring a Zero Trust Network Access ArchitectEngineer to support the Defense Counterintelligence and Security Agency DCSA program in Quantico VA 22134 USA The role serves as the chief technical authority for the design orchestration implementation and long term governance of enterprise security boundaries It leads modernization of DCSAs hybrid workforce infrastructure using Palo Alto Networks Panorama and GlobalProtect and Versa Networks SASE platforms to establish resilient identity aware context driven security
Strategic Architecture and EngineeringServe as Principal Architect for DCSAs Zero Trust initiative establishing technical roadmaps reference architectures and engineering guidelines aligned with NIST SP 800 207 Lead the design implementation and optimization of Palo Alto GlobalProtect and Versa Networks SASE to secure cloud hybrid on premises and mobile endpoints Define and govern global security policy templates in Palo Alto Panorama to enforce micro segmentation application level security and threat prevention Policy Governance and OptimizationArchitect data loss prevention DLP SSLTLS decryption and threat prevention strategies across all ingress and egress points Review SASE and ZTNA architectures for performance bottlenecks configuration drift and security gaps and develop advanced mitigation strategies Identity and Ecosystem IntegrationCollaborate with Identity and Access Management IAM teams to integrate ZTNASASE policies with identity providers such as Okta and Azure AD ensuring real time evaluation of device posture user context and continuous authentication Guide integration of Versa SASE and Palo Alto platforms with existing Security Operations Center SOC environments including SIEM SOAR and EDRXDR tools Technical Leadership and DocumentationProvide technical leadership and guidance to cybersecurity engineers serving as the Tier 4 escalation point for complex architectural routing and access control challenges Develop enterprise level high level designs HLD low level designs LLD system security plans SSP and change management policies for executive and government stakeholders Vendor Evaluation and AutomationTrack Palo Alto PAN OS and Versa Networks features and conduct proofs of concept PoCs to evaluate and deploy next generation capabilities Lead security as code and automation initiatives using APIs and orchestration tools to automate secure connectivity and zero touch deployments
EducationBachelors degree in Cybersecurity Computer Engineering Information Systems Management or a related field A masters degree or an equivalent combination of military service and 12 years of highly relevant experience is accepted Required ExperienceMinimum of 10 years of progressive experience in network security engineering enterprise architecture and infrastructure security Required At least 34 years of direct experience architecting and implementing Zero Trust frameworks aligned with NIST SP 800 207 and SASE solutions in enterprise or federal environments Required SkillsAdvanced architecture level knowledge of Palo Alto Networks enterprise solutions including Panorama management and GlobalProtect secure access deployments Required Deep technical proficiency in designing and deploying Versa Networks SASE including SD WAN Secure Web Gateway Cloud Access Security Broker and Firewall as a Service Required Ability to communicate complex technical ideas to a diverse customer base verbally and in writing Required CertificationsMeet 8140 certification requirements with examples including CISM CISSP ISSAP CISSP ISSEP GCIA GDSA and GICSP Required ClearanceActive Secret clearance and eligibility for an upgrade to TSSCI Required Working ConditionsPrimarily a telework position with a requirement to be onsite at least two 2 days a week or as needed at Quantico Marine Corps Base VA Additional onsite time may be required during initial onboarding and program integration Required If the alternate worksite is outside DCSA facilities or corporate office space reliable voice communication capability cell phone preferred and a stable capable internet connection are required Required Preferred QualificationsCertificationsPalo Alto Networks Certified Network Security Engineer PCNSE Palo Alto Networks Certified Zero Trust Network Security Engineer PCZTNSE Versa Certified SASE Professional VCSP or Versa Certified SASE Specialist VCSS Alternate Worksite CommunicationCell phone for voice communication when working outside DCSA facilities or corporate office space