OverviewGovCIO is currently hiring a senior Zero Trust Lead (Network) to serve as the accountable technical lead for advancing DFC's Zero Trust capabilities across identity, device, network, cloud, and security domains. The role will define Zero Trust policy intent, technical standards, integration requirements, and roadmap priorities; lead cross-tower design and implementation; and ensure approved capabilities are tested, documented, operationally ready, and transitioned into production. This role is distinct from day-to-day Network Operations leadership, but requires equivalent network subject-matter expertise and is fully hands-on: the Zero Trust Lead will perform network engineering and operational tasks alongside the Network Operations team as needed. This position will be located in Washington, DC and will be hybrid
Responsibilities
- Own the Zero Trust technical strategy and cross-tower integration model, defining policy intent, technical standards, control objectives, architecture requirements, and roadmap priorities across identity, device posture, network, cloud, endpoint, and security domains.
- Provide hands-on team operations support alongside Network Operations engineers, including installation, configuration, troubleshooting, maintenance, resilience, and optimization of Cisco routing/switching and LAN/WAN services. Maintain the same depth of network subject-matter expertise required to independently execute complex network engineering tasks when needed.
- Define and lead Zero Trust integration requirements for Palo Alto firewall controls, including least-privilege policy intent, identity-aware enforcement, segmentation, and alignment with Zscaler and identity controls; remain capable of performing hands-on firewall engineering and troubleshooting as part of team operations.
- Define and lead Zero Trust requirements for Zscaler ZIA/ZPA and Client Connector, including identity-aware access, least-privilege policy, application access, posture integration, and alignment with enterprise identity and network controls; provide hands-on engineering and troubleshooting support as required.
- Define and lead Zero Trust requirements for Aruba wireless and ClearPass NAC, including secure access, identity/device posture enforcement, segmentation, and integration with identity, firewall, and Zscaler controls; provide hands-on wired/wireless engineering support as required.
- Advance DFC Zero Trust principles across the environment: no implicit trust based on location, identity-aware access, least privilege, segmentation, continuous monitoring, and integration of identity, device posture, network, cloud-security, and security policies.
- Act as the primary cross-tower coordination point for Zero Trust across Network Operations, Infrastructure/Cloud, IAM, endpoint management, Service Desk, Security Operations, and Engineering; establish priorities, define integration requirements, resolve dependencies, and ensure Zero Trust requirements are translated into sustainable operational controls.
- Lead Zero Trust design in partnership with Engineering Operations, including identity-aware access and segmentation enhancements, integration across identity, network, device posture, cloud, and security platforms, and definition of least-privilege and continuous-monitoring requirements. Lead architecture reviews, identify gaps and risks, define remediation approaches, and ensure new Zero Trust capabilities are fully tested, documented, and ready for handoff before moving into production operations.
- Lead Zero Trust technical coordination during high-impact incidents involving access controls or cross-domain dependencies; participate in Major Incident bridges and provide hands-on network troubleshooting when required, while driving long-term remediation of recurring Zero Trust integration issues.
- Ensure all network and Zero Trust changes follow ServiceNow ERB/CCB processes, including impact/risk analysis, testing, implementation, post-change validation, rollback planning, and traceability to affected services and configuration items.
- Define Zero Trust monitoring and measurement requirements across access, identity, device posture, segmentation, and security controls; use operational telemetry and incident trends to identify control gaps, risks, and improvement priorities.
- Maintain high-quality operational documentation, including network diagrams, Zero Trust architecture/control documentation, SOPs, runbooks, configuration baselines, CMDB records, and knowledge-transfer artifacts.
- Own Zero Trust technical performance reporting and roadmap progress, including control maturity, integration gaps, risks, remediation actions, and continuous-improvement recommendations; contribute network expertise to operational SLA/KPI reviews as required.
- Define and validate Zero Trust dependencies and access-control requirements within continuity and disaster recovery planning, and provide hands-on network engineering support during recovery activities as required.
Qualifications
Bachelor's Network Engineering, Computer Science, IT, or a related field, or equivalent technical experience/certifications with 12+years (or commensurate experience)
Required Skills and Experience
- Experience: Senior-level hands-on experience in enterprise network engineering/operations, including technical leadership across routing, switching, wireless, firewalls, and secure access technologies. Experience should be commensurate with a Key Personnel technical lead role.
- Zero Trust: Demonstrated experience leading the design, implementation, and operationalization of Zero Trust capabilities across identity, device posture, network access, segmentation, cloud/security controls, and continuous monitoring. Must have working experience with enterprise identity and device-control technologies such as Active Directory, Okta, Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and Microsoft Intune, in addition to strong operational knowledge of Palo Alto, Zscaler ZIA/ZPA, and Aruba/ClearPass NAC.
- Leadership and governance: Demonstrated ownership of enterprise technical initiatives, including setting technical direction, defining standards and roadmaps, leading cross-functional teams, making and communicating technical decisions, and driving work from design through production handoff. Leadership capability is a core selection criterion for this Key Personnel role. Experience with ITIL-based incident/change management and ServiceNow is required.
-
Clearance Required: US Citizenship is required to obtain an active Secret clearance
Preferred Skills and Experience
- Cisco CCNA/CCNP; Palo Alto PCNSA/PCNSE; Aruba ACMA/ACMP; Zscaler certifications.
- ITIL v4 Foundation certification.
- Experience with identity-aware access controls, network segmentation, NAC/device posture, conditional access, and integration across identity, network, and security platforms.
- Demonstrated leadership of enterprise Zero Trust initiatives, including the ability to lead technical teams and cross-functional stakeholders, translate Zero Trust architecture principles into operational controls and standards, and develop and execute Zero Trust roadmaps.
- Proven ability to provide hands-on technical leadership, make and communicate technical recommendations, mentor engineering staff, and lead complex network/security initiatives across organizational boundaries.
- Prior federal network operations experience across multi-site environments.
Posted Salary RangeUSD $143,230.00 - USD $145,000.00 /Yr.