Zero Trust Network Security Engineer
About the role
Are you looking for an opportunity to combine your technical skills with big-picture thinking to make an impact on national security? You understand how identity, device posture, and policy come together to keep sensitive resources secure, and you know how to translate that understanding into resilient engineering solutions. Your ability to turn real-world access control challenges into technical specifications makes you an integral part of delivering a customer-focused Zero Trust capability.
As a Zero Trust Network Security Engineer on our team, you’ll have the chance to design and support remote access and conditional access enforcement solutions in support of the Department of Defense's (DoD) Zero Trust mission. Your technical expertise will be vital as you help evaluate and modernize legacy VPN infrastructure into Security Service Edge (SSE) and Zero Trust Network Access (ZTNA) capabilities. You'll develop your skills in identity, device posture, and policy-based access control while gaining experience supporting a large-scale, DoD-wide Zero Trust conditional access initiative. Grow your skills by merging network security engineering with Zero Trust architecture and policy enforcement design to create conditional access solutions that evaluate users and devices in real time before they reach mission-critical resources. Join our team and help turn Zero Trust strategy into accomplishments that drive change.
Requirements
- 5+ years of experience supporting DoD enterprise security architectures
- Experience designing, deploying, and supporting remote access solutions, including traditional VPN or SSE solutions
- Knowledge of networking fundamentals, including IP addressing, routing, LAN or WAN architecture, and firewall concepts
- Ability to design and support solutions that enforce ZTNA based on user identity, device posture, and organizational policy
- Secret clearance
- HS diploma or GED
Nice to have
- Experience with Secure Access Service Edge (SASE) platforms such as Versa Networks and Palo Alto Prisma Access
- Experience implementing solutions in classified spaces
- Experience collaborating with cross-functional teams, including identity, endpoint management, and infrastructure, to design and deliver end-to-end solutions
- Knowledge of DoD Comply to Connect (C2C) requirements
- Knowledge of DoD Identity, Credential, and Access Management (ICAM) capabilities and related technologies
- Knowledge of federal compliance standards, including NIST 800-53, FIPS, and DoD STIGs
- Knowledge of Linux or UNIX environments, including navigating and troubleshooting basic OS issues
- Strong verbal and written communication skills
- Security+ Certification
Benefits
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values.
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.
Pay
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees.
Schedule
This posting will close within 90 days from the Posting Date.
Work Model:
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.