×
Register Here to Apply for Jobs or Post Jobs. X

Zero Trust Network Access Architect​/Engineer

Job in Quantico, Prince William County, Virginia, 22134, USA
Listing for: ASRC Federal
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Network Security
Job Description & How to Apply Below

Senior Zero Trust Network Architect / Principal Engineer

ASRC Federal is actively hiring a Senior Zero Trust Network Architect / Principal Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico, VA.

We are seeking an industry-leading cybersecurity expert with a deep specialization in Zero Trust Network Architecture (ZTNA) and Secure Access Service Edge (SASE). The successful candidate will serve as the chief technical authority for the design, orchestration, implementation, and long-term governance of our enterprise security boundaries.

In this role, you will lead the strategic modernization of DCSA's hybrid workforce infrastructure. You will leverage Palo Alto Networks (Panorama, Global Protect) and Versa Networks SASE platforms to establish a highly resilient, identity-aware, and context-driven security posture.

This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA. Additional onsite time may be required during initial onboarding and program integration.

Minimum Requirements:

  • Experience:

    Minimum of 10 years of progressive experience in network security engineering, enterprise architecture, and infrastructure security.
  • At least 3–4 years of direct experience architecting and implementing Zero Trust frameworks (NIST SP 800-207) and SASE solutions in enterprise or federal environments.
  • Technical Mastery:
    Advanced architecture-level knowledge of Palo Alto Networks enterprise solutions, including deep management expertise via Panorama and secure access deployments using Global Protect.
  • Deep technical proficiency in designing and deploying Versa Networks SASE (SD-WAN, Secure Web Gateway, Cloud Access Security Broker, and Firewall-as-a-Service).
  • Security Clearance:
    Active Secret Clearance REQUIRED, must be eligible to be upgraded to TS/SCI.
  • Compliance:
    Must meet 8140 certification requirements (e.g. CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, GICSP)
  • Education:

    Bachelor's Degree in Cybersecurity, Computer Engineering, Information Systems Management, or a related field. A Master's degree or an equivalent combination of military service and 12+ years of highly relevant experience is accepted.
  • Desired Vendor

    Certifications:

    Palo Alto Networks Certified Network Security Engineer (PCNSE), Palo Alto Networks Certified Zero Trust Network Security Engineer (PCZTNSE), Versa Certified SASE Professional (VCSP) or Versa Certified SASE Specialist (VCSS)

Responsibilities:

Strategic Architecture & Engineering

  • Serve as the Principal Architect for the DCSA Zero Trust journey, establishing the technical roadmap, reference architectures, and engineering guidelines aligned with NIST SP 800-207 standards.
  • Lead the end-to-end design, implementation, and optimization of Palo Alto Global Protect and Versa Networks SASE to secure cloud, hybrid on-premises, and mobile endpoints.
  • Define and govern global security policy templates within Palo Alto Panorama to enforce micro-segmentation, application-level security, and threat prevention.

Policy, Governance & Optimization

  • Architect advanced data loss prevention (DLP), SSL/TLS decryption, and threat prevention strategies across all egress and ingress points.
  • Conduct regular architectural reviews of the SASE and ZTNA configurations to identify performance bottlenecks, configuration drifts, or security gaps, providing advanced mitigation strategies.

Identity & Ecosystem Integration

  • Collaborate with Identity and Access Management (IAM) teams to integrate ZTNA/SASE policies with identity providers (e.g., Okta, Azure AD), ensuring device posture, user context, and continuous authentication are evaluated in real time.
  • Guide the integration of Versa SASE and Palo Alto platforms with existing Security Operations Center (SOC) environments, including SIEM, SOAR, and endpoint detection (EDR/XDR) tools.

Technical Leadership & Mentorship

  • Provide technical leadership and guidance to the cybersecurity engineering team, serving as the tier-4 escalations point for complex architectural, routing, and access control challenges.
  • Author enterprise-level high-level designs (HLD),…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary