Amatriot logo

Zero Trust Network Access Architect/Engineer

Salary
$190K–$220K
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Location: Quantico, VA. Hybrid 2 days onsite.
Security Clearance: Active Secret or higher [Required]
Job Type: Full-Time

Target Salary Range*: $190,000 - $220,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary


Position Overview

Amatriot is hiring a Zero Trust Network Access Architect/Engineer to support the Defense Counterintelligence and Security Agency (DCSA) program in Quantico, VA 22134, USA.

The role serves as the chief technical authority for the design, orchestration, implementation, and long-term governance of enterprise security boundaries. It leads modernization of DCSA’s hybrid workforce infrastructure using Palo Alto Networks Panorama and GlobalProtect and Versa Networks SASE platforms to establish resilient, identity-aware, context-driven security.


Key Responsibilities

Strategic Architecture and Engineering

  • Serve as Principal Architect for DCSA’s Zero Trust initiative, establishing technical roadmaps, reference architectures, and engineering guidelines aligned with NIST SP 800-207.

  • Lead the design, implementation, and optimization of Palo Alto GlobalProtect and Versa Networks SASE to secure cloud, hybrid on-premises, and mobile endpoints.

  • Define and govern global security policy templates in Palo Alto Panorama to enforce micro-segmentation, application-level security, and threat prevention.

Policy, Governance, and Optimization

  • Architect data loss prevention (DLP), SSL/TLS decryption, and threat prevention strategies across all ingress and egress points.

  • Review SASE and ZTNA architectures for performance bottlenecks, configuration drift, and security gaps, and develop advanced mitigation strategies.

Identity and Ecosystem Integration

  • Collaborate with Identity and Access Management (IAM) teams to integrate ZTNA/SASE policies with identity providers such as Okta and Azure AD, ensuring real-time evaluation of device posture, user context, and continuous authentication.

  • Guide integration of Versa SASE and Palo Alto platforms with existing Security Operations Center (SOC) environments, including SIEM, SOAR, and EDR/XDR tools.

Technical Leadership and Documentation

  • Provide technical leadership and guidance to cybersecurity engineers, serving as the Tier 4 escalation point for complex architectural, routing, and access control challenges.

  • Develop enterprise-level high-level designs (HLD), low-level designs (LLD), system security plans (SSP), and change management policies for executive and government stakeholders.

Vendor Evaluation and Automation

  • Track Palo Alto PAN-OS and Versa Networks features and conduct proofs of concept (PoCs) to evaluate and deploy next-generation capabilities.

  • Lead security-as-code and automation initiatives using APIs and orchestration tools to automate secure connectivity and zero-touch deployments.


Qualifications

Education

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Information Systems Management, or a related field. A master’s degree or an equivalent combination of military service and 12+ years of highly relevant experience is accepted. [Required]

Experience

  • Minimum of 10 years of progressive experience in network security engineering, enterprise architecture, and infrastructure security. [Required]

  • At least 3–4 years of direct experience architecting and implementing Zero Trust frameworks aligned with NIST SP 800-207 and SASE solutions in enterprise or federal environments. [Required]

Skills

  • Advanced architecture-level knowledge of Palo Alto Networks enterprise solutions, including Panorama management and GlobalProtect secure access deployments. [Required]

  • Deep technical proficiency in designing and deploying Versa Networks SASE, including SD-WAN, Secure Web Gateway, Cloud Access Security Broker, and Firewall-as-a-Service. [Required]

  • Ability to communicate complex technical ideas to a diverse customer base verbally and in writing. [Required]

Certifications

  • Meet 8140 certification requirements, with examples including CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, and GICSP. [Required]

Clearance

  • Active Secret clearance and eligibility for an upgrade to TS/SCI. [Required]

Working Conditions

  • Primarily a telework position, with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base, VA. Additional onsite time may be required during initial onboarding and program integration. [Required]

  • If the alternate worksite is outside DCSA facilities or corporate office space, reliable voice communication capability (cell phone preferred) and a stable, capable internet connection are required. [Required]


Preferred Qualifications

Certifications

  • Palo Alto Networks Certified Network Security Engineer (PCNSE).

  • Palo Alto Networks Certified Zero Trust Network Security Engineer (PCZTNSE).

  • Versa Certified SASE Professional (VCSP) or Versa Certified SASE Specialist (VCSS).

Alternate Worksite Communication

  • Cell phone for voice communication when working outside DCSA facilities or corporate office space.

Similar jobs

Apply for this job