MetroStar logo
MetroStarPosted 1 week ago

Sr. Zero Trust Engineer III (6794)

$150,000–$190,000 year

On-siteArlington, Virginia, United States

Full TimeSenior LevelMediumTechnology Services

Job Summary

Design and maintain Zero Trust security architectures across cloud, hybrid, and on-premises environments using Microsoft Azure technologies. Implement identity-centric controls via Microsoft Entra ID, Defender for Cloud, and Sentinel to strengthen access and enable continuous monitoring. Develop automation with PowerShell, Python, and Terraform to enforce policy compliance and integrate security into CI/CD pipelines. Conduct maturity assessments, architecture reviews, and gap analyses while collaborating with stakeholders to align roadmaps with organizational objectives. Requires Top Secret clearance, 10+ years in cybersecurity, and 5+ years in Zero Trust design.

Required Qualifications

  • Active Top Secret security clearance
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical discipline
  • 10+ years of experience in cybersecurity, cloud security engineering, systems engineering, or enterprise security architecture
  • 5+ years of experience designing, implementing, and supporting Zero Trust architectures within Microsoft Azure and hybrid cloud environments
  • Strong knowledge of Zero Trust principles and frameworks, including NIST SP 800-207, CISA Zero Trust Maturity Model and other recognized Zero Trust guidance
  • Experience implementing Microsoft security technologies, including Microsoft Entra ID (Azure Active Directory), Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Microsoft Intune, Conditional Access, Privileged Identity Management (PIM), and Azure Key Vault
  • Hands-on experience with Infrastructure as Code (Terraform, ARM Templates, or Bicep), cloud automation, and CI/CD platforms such as GitLab, GitHub, Jenkins, or Azure DevOps
  • Proficiency with PowerShell, Python, Azure CLI, or other scripting languages used for security automation and cloud administration
  • Strong understanding of Azure networking, identity management, encryption, PKI, network segmentation, secure access, and cloud-native security services
  • Experience supporting large enterprise, public sector, or regulated environments and implementing security controls aligned with NIST RMF, FedRAMP, applicable security baselines, and security authorization requirements
  • Excellent analytical, communication, and stakeholder engagement skills with the ability to present technical recommendations to engineering teams, cybersecurity leadership, and client stakeholders
  • In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce