×
Register Here to Apply for Jobs or Post Jobs. X

Senior Zero Trust Identity and ICAM Engineer

Job in Washington, District of Columbia, 20022, USA
Listing for: CELESTIAL INNOVATIONS GROUP LLC
Full Time position
Listed on 2026-09-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer, Network Security
Salary/Wage Range or Industry Benchmark: 135000 - 180000 USD Yearly USD 135000.00 180000.00 YEAR
Job Description & How to Apply Below

Benefits:

  • 401(k)
  • Competitive salary
  • Dental insurance
  • Health insurance
  • Paid time off
  • Training & development
  • Vision insurance
POSITION SUMMARY

Celestial Innovations Group (CIG) is seeking a Zero Trust Identity and ICAM Engineer to own end-to-end access policy design across the identity, endpoint, network, and application layers for federal agency clients, spanning the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform, guided by the principle of “never trust, always verify.”

The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model and Secure Access Service Edge (SASE) guidance.

These responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, acting as Trust Brokers across the enterprise, so the organization can maintain a strong security posture ahead of adversaries.

Must be located in the DC Metro Area as this role requires onsite and remote support.

KEY RESPONSIBILITIES Architecture and Strategy
  • Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients
  • Design and document ZTA solutions spanning all five pillars:
    Identity, Device, Network, Application/Workload, and Data
  • Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans
  • Develop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworks
  • Support integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networks
  • Drive SASE convergence, consolidating network and security enforcement onto a single policy plane
  • Advance security posture design and real-time trust evaluation, with a focus on insider threat detection and response
Implementation and Engineering
  • Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)
  • Own top-level Conditional Access policy design and privileged access governance in Microsoft Entra /M365
  • Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management
  • Deliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems
  • Enforce device posture as a condition of every access decision, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals
  • Define and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra , and Workspace ONE (WS1)
  • Configure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controls across the network landscape, including Palo Alto, Cisco, and wireless infrastructure
  • Deploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scale
  • Integrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirements
Compliance and Authorization
  • Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary