Zero Trust Infrastructure Engineer

$100K — $130K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance (Tier 5 background investigation) required.
  • Bachelor’s degree in Cybersecurity, Computer Science, IT Engineering, or related field.
  • 7+ years of experience in IT infrastructure, cloud security, or network security engineering.
  • Proficient in implementing Zero Trust or identity-based security controls.
  • Experience with microsegmentation, PEP configuration, and conditional access.
  • Familiarity with IL5 cloud or federal security environments.
  • Knowledge of Zero Trust principles, DoD strategy, and enforcement mechanisms.

Responsibilities

  • Implement Zero Trust Policy Enforcement Points (PEPs) across all layers.
  • Configure microsegmentation policies and identity-based routing.
  • Support Zero Trust automation workflows and continuous verification.
  • Integrate telemetry from various sources into enforcement logic.
  • Apply Zero Trust principles to network segmentation and resource access.
  • Support device posture checks and endpoint trust validation.
  • Assist in enforcing Zero Trust security policies following DoD guidance.

Benefits

  • Fully remote position.
  • Collaborative work environment with architects and security teams.
  • Opportunity to contribute to government contracts with national significance.
  • Involvement in advanced cybersecurity practices and frameworks.
  • Access to professional development and technical training opportunities.
Full Job Description
Overview

DecisionPoint seeks a Zero Trust Infrastructure Engineer to implement and maintain Zero Trust-aligned network, device, and application enforcement across IL5 AWS GovCloud environments. This role focuses on configuring Policy Enforcement Points (PEPs), microsegmentation controls, identity-based routing policies, telemetry integrations, and Zero Trust automation patterns to support a large federal and DoD-aligned mission environment. 

The Zero Trust Infrastructure Engineer collaborates with architects, cybersecurity teams, network engineers, and application teams to ensure the enterprise environment meets Zero Trust maturity goals and adheres to DoD Zero Trust strategy and implementation guidance. 

This position is fully remote.

Duties & Responsibilities

The Zero Trust Infrastructure Engineer will: 

  • Implement Zero Trust Policy Enforcement Points (PEPs) across network, device, and application layers. 
  • Configure microsegmentation policies, identity-based routing, and dynamic access controls. 
  • Support Zero Trust automation workflows, including policy-as-code and continuous verification mechanisms. 
  • Integrate telemetry feeds from applications, identity services, cloud platforms, and network sensors into enforcement logic. 
  • Apply Zero Trust principles to cloud network segmentation, traffic inspection, and resource access. 
  • Support the implementation of device posture checks, endpoint trust validation, and conditional access rules. 
  • Assist in the development and enforcement of Zero Trust security policies aligned with DoD guidance. 
  • Troubleshoot enforcement issues, telemetry gaps, and policy misconfigurations. 
  • Participate in Zero Trust maturity assessments, roadmap updates, and implementation planning. 
  • Maintain Zero Trust infrastructure documentation, diagrams, and policy mappings. 
  • Collaborate with cybersecurity teams to align Zero Trust enforcement with RMF controls and IL5 cloud requirements. 
  • Support monitoring, logging, and analytics for Zero Trust events and enforcement decisions. 
Qualifications

Clearance Requirement 

Must hold an active Top Secret clearance, supported by a Tier 5 background investigation. 

 

Education (Required) 

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology Engineering, or a related field. 

 

Experience (Required) 

  • Minimum 7 years of experience in IT infrastructure, cloud security, or network security engineering. 
  • Experience implementing Zero Trust or identity-based security controls. 
  • Experience with microsegmentation, PEP configuration, or conditional access. 
  • Experience supporting IL5 cloud or federal security environments. 

 

Technical Knowledge (Required) 

  • Knowledge of Zero Trust principles, DoD Zero Trust strategy, and enforcement mechanisms. 
  • Familiarity with identity-based routing, access policies, and device posture enforcement. 
  • Understanding of cloud networking (AWS GovCloud preferred), segmentation, and traffic inspection. 
  • Familiarity with telemetry, logging, and distributed monitoring systems. 

Technical Knowledge (Preferred) 

  • Experience with policy-as-code frameworks or Zero Trust automation tools. 
  • Experience with SIEM platforms, identity platforms, and cloud-native enforcement services. 
  • Experience with microservices or container-based traffic enforcement. 

 

Certifications 

Required: 

  • CompTIA Security+ 

Preferred: 

  • ITIL v4 Foundation 
  • CCSP, CISSP, or Zero Trust-focused certifications 
  • AWS security or networking certifications 

 

Skills 

  • Strong analytical and troubleshooting skills for complex Zero Trust enforcement issues. 
  • Excellent communication and collaboration abilities across technical and mission teams. 
  • High attention to detail, especially in policy tuning and enforcement logic. 
  • Ability to work in fast-paced, mission-critical environments. 
  • Strong documentation discipline and ability to translate complex configurations into clear guidance. 

Similar Jobs

More Jobs at

More Information Technology Jobs

Find similar Zero Trust Infrastructure Engineer jobs: