Zero Trust Security Engineer - SME

DecisionPoint | Cortek

$120K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in cybersecurity engineering, with at least 3 years focusing on Zero Trust or endpoint security.
  • Bachelor's degree in Computer Science, Information Systems, or relevant fields.
  • Proven expertise with Microsoft Defender, Intune, and Azure security solutions.
  • Experience with large-scale cybersecurity implementations, preferably in federal settings.
  • Certifications: Microsoft SC-200, SC-100, or CISSP required.

Responsibilities

  • Oversee deployment and configuration of Microsoft Defender for Endpoint.
  • Coordinate the onboarding process of endpoints using Microsoft Intune and Active Directory.
  • Ensure endpoint visibility, telemetry reporting, and compliance with Microsoft security practices.
  • Generate RMF artifacts including POA&Ms and data flow diagrams.
  • Lead architectural reviews to identify cybersecurity gaps and recommend improvements.
  • Evaluate logging and threat detection effectiveness across various platforms.
  • Conduct quarterly reviews to align security posture with organizational goals.

Benefits

  • Remote work arrangement, with preference for candidates in the DMV area.
  • Opportunity to be a subject matter expert in a critical security initiative.
  • Engagement in federal cybersecurity compliance efforts.
  • Dynamic work environment addressing cutting-edge security challenges.
Full Job Description
Overview

DecisionPoint Corporation is seeking a Zero Trust Security Engineer - SME to serve as the subject matter expert for Zero Trust Architecture (ZTA) implementation across GPO enterprise systems. This role leads Defender for Endpoint deployment and configuration efforts, drives continuous enterprise cybersecurity improvements, and ensures alignment with NIST, RMF, and FISMA frameworks. As a key advisor to the IT Security Division, this individual will oversee enterprise risk posture, technical validation, and optimization of cybersecurity operations.

Location: Remote - candidates located in the Washington, DC metropolitan area (DMV) are highly preferred.

Clearance Requirement: Must be able to obtain and maintain a Public Trust clearance.

Note: By applying to this position, you acknowledge and consent to having your resume included in an active competitive government contract bid.

*Please Note: This requisition is contingent upon contract award.*

Duties & Responsibilities

Zero Trust Security Engineer - SME will:
  • Oversee technical planning, scripting, testing, and enterprise-wide deployment of Microsoft Defender for Endpoint agents.
  • Coordinate onboarding of target endpoints using Microsoft Intune or Active Directory Group Policy.
  • Ensure proper telemetry reporting, endpoint visibility, and adherence to Microsoft security best practices. Create and maintain security control test results, asset inventories, and remediation documentation in GRC repositories.
  • Contribute to RMF artifact generation such as POA&Ms, data flow diagrams, and patch/upgrade schedules.
  • Ensure all documentation reflects the latest changes to production environments and security tools.
  • Lead architectural reviews and risk posture assessments to identify cybersecurity gaps and recommend remediation strategies.
  • Evaluate logging efficiency, rule tuning, and threat detection performance across SIEM and endpoint platforms.
  • Conduct quarterly executive reviews and operational touchpoints to align security posture with mission goals.
  • Contribute to the development and maintenance of RMF documentation (POA&Ms, Security Assessment Reports, Security Plans).
  • Validate and document security controls for systems affected by Defender and other ZTA tooling.
  • Ensure compliance with NIST SP 800-53, 800-37, and FISMA standards across security solutions.


Qualifications

  • Minimum Experience: 10 years of experience in cybersecurity engineering, with 3+ years in Zero Trust or endpoint security domains.
  • Minimum Education: Bachelor's degree in Computer Science, Information Systems, other related disciplines (or equivalent experience)
  • Technical Knowledge: Demonstrated expertise with Microsoft Defender suite, Intune, and Azure-based security solutions. Proven ability to lead enterprise-wide cybersecurity solution design, deployment, and validation.
  • Federal experience (preferred)
  • Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200), Microsoft Certified: Cybersecurity Architect Expert (SC-100), or CISSP (Certified Information Systems Security Professional) required.


Similar Jobs

More Jobs at DecisionPoint | Cortek

More Information Technology Jobs

Find similar Zero Trust Security Engineer - SME jobs: