Clera home
·Dashboard

Jobs at Celestial Innovations Group (Now Hiring) — 1 open

Celestial Innovations Group

Zero Trust Engineer Mid Level

District of Columbia, United States · Hybrid

$135k–$155k/yr

Senior

POSITION SUMMARY Celestial Innovations Group (CIG) is seeking a Mid Zero Trust Engineer to support federal agency clients in the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This rol…

Skills: Zero Trust Architecture, Identity And Access Management, Network Security, Microsegmentation, Cloud Security

Zero Trust Engineer Mid Level

Celestial Innovations Group

District of Columbia, United States • Hybrid

Apply
Senior

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

  • $135k–$155k/yr
  • Full-time
  • professional certificate
  • Posted 37d ago
  • ~40 hrs/week

Responsibilities

Lead the design, implementation, and sustainment of Zero Trust Architecture solutions for federal agency clients across five security pillars. Translate federal mandates into actionable technical roadmaps and manage the full RMF lifecycle for system authorization.

Requirements

Requires 5+ years of cybersecurity engineering experience with at least 2 years specifically in Zero Trust implementation within federal environments. Proficiency in at least one major vendor stack (Palo Alto, Zscaler, or Microsoft) is mandatory.

Full job description

POSITION SUMMARY
Celestial Innovations Group (CIG) is seeking a Mid Zero Trust Engineer to support federal agency clients in the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform. The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model.

Must be located in the DC Metro Area as this role requires onsite and remote support.


KEY RESPONSIBILITIES
Architecture and Strategy
  • Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients
  • Design and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and Data
  • Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans
  • Develop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks
  • Support integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks
Implementation and Engineering
  • Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)
  • Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management
  • Configure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls
  • Deploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale
  • Integrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements
Compliance and Authorization
  • Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirements
  • Support the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance
  • Document ZTA controls for system security packages, POA&Ms, and security assessment reports
Client Engagement and Collaboration
  • Serve as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts
  • Produce executive-level briefings, technical white papers, and implementation status reports
  • Collaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration

VENDOR ECOSYSTEM EXPERIENCE
CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:

Vendor / Framework & Relevant Capabilities
Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars
Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection
Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center
CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements

REQUIRED QUALIFICATIONS
Experience
  • 5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles
  • 2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environment
  • Demonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model
  • Experience supporting federal government clients or DoD/civilian agency environments

Technical Skills
  • Proficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stack
  • Identity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM tooling
  • Network security: microsegmentation, ZTNA, DNS security, SD-WAN, next-generation firewall policy
  • Endpoint security: EDR/XDR deployment and management, device compliance policy enforcement
  • Cloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlay
  • Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)

PREFERRED QUALIFICATIONS
  • Active certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA-IA or ZCCA-PA, Microsoft SC-100 (Cybersecurity Architect Expert)
  • Additional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certifications
  • Familiarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation
  • Experience with ServiceNow, Salesforce, or IT service management tooling in a federal context
  • Multi-vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)
  • Familiarity with post-quantum cryptography standards (FIPS 203/204/205) and their ZTA implications

Flexible work from home options available.

Related keywords

Zero TrustZTAEO 14028OMB M-22-09NIST SP 800-207CISA ZT Maturity ModelPalo Alto NetworksPrisma AccessZscalerMicrosoft Entra IDMicrosoft SentinelAzureAWSMFARBACZTNA

About Celestial Innovations Group

LinkedInVisit site

Securing the Universe, Starting with You

Industry
IT Services and IT Consulting
Company size
11-50 employees
Headquarters
Rockville, Maryland
LinkedIn followers
166

CIG grew from an idea to reality out of a need in the IT industry. The need of delivering resources and services with a different approach, an approach with our primary focus of establishing long term customer relationship. Our Founders have decades of combined experience in both the public sector and private sector. Our team of subject matter experts have deep knowledge in all critical areas of IT. From the strong base foundations of infrastructure design and data transfer, to application system implementation and cybersecurity, CIG has a team of experts to meet today’s ever changing demanding needs!

Offices: 1201 Seven Locks Rd, Suite 360, Rockville, Maryland 20854, US

View all jobs at Celestial Innovations Group

About Celestial Innovations Group

LinkedInVisit site

Securing the Universe, Starting with You

Industry
IT Services and IT Consulting
Company size
11-50 employees
Headquarters
Rockville, Maryland
LinkedIn followers
166

CIG grew from an idea to reality out of a need in the IT industry. The need of delivering resources and services with a different approach, an approach with our primary focus of establishing long term customer relationship. Our Founders have decades of combined experience in both the public sector and private sector. Our team of subject matter experts have deep knowledge in all critical areas of IT. From the strong base foundations of infrastructure design and data transfer, to application system implementation and cybersecurity, CIG has a team of experts to meet today’s ever changing demanding needs!

Offices: 1201 Seven Locks Rd, Suite 360, Rockville, Maryland 20854, US

View all jobs at Celestial Innovations Group

Similar companies hiring

Capgemini (4836)Oracle (2289)Hewlett Packard Enterprise (2251)KBR, Inc. (2156)PACS (1970)Arvato Systems (1636)CONA Services (1417)NTT DATA North America (1406)Verizon (1026)Schwarz IT KG (1023)VOIS (1007)GovTech Singapore (962)
Clera home

Your AI-talent agent. Connecting talents with dream jobs.

Earn $5,000

Tools

  • Salary Calculator
  • Resume Review
  • Startup Map

Explore

  • Jobs
  • Discover Jobs
  • Companies
  • Case Studies
  • Referral

Platform

  • Pricing
  • Integrations
  • Partners
  • Acquihire

Clera

  • Manifesto
  • Engineering
  • We are hiring!
  • FAQs
  • Blog
  • Press

Tools

  • Salary Calculator
  • Resume Review
  • Startup Map

Explore

  • Jobs
  • Discover Jobs
  • Companies
  • Case Studies
  • Referral

Platform

  • Pricing
  • Integrations
  • Partners
  • Acquihire

Clera

  • Manifesto
  • Engineering
  • We are hiring!
  • FAQs
  • Blog
  • Press

© 2026 Clera Labs, Inc.

PrivacyTermsBug Bounty