Cloud / Network Security Engineer
Job Description
This role supports NIH’s Future State Zero Trust Architecture (ZTA) by co-authoring reusable cloud, network, and identity design patterns under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order. The position is primarily design and advisory work, with continued hands-on engineering to produce actionable reference architectures and control mappings.
Core Responsibilities
- Co-author cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, packaging the outcomes as reusable design patterns tied to NIST SP 800-53 Rev 5 control mappings.
- Design microsegmentation and workload-identity patterns aligned to NIST SP 800-207A and CISA and NSA Zero Trust guidance, including software-defined perimeter approaches for HPC clusters and isolated VLAN designs with brokered remote access for laboratory instruments.
- Document how centrally provided network, endpoint, and logging services are inherited to support the Centrally Provided Services Matrix.
- Define technical policy anchors for the network and device pillars by establishing segmentation policy within the controller and compliance policy within endpoint management, then map controls to telemetry to enable continuous-monitoring evidence collection.
- Support Task 3 network use cases, including flow baselining to generate and validate microsegmentation policy and lateral-movement anomaly detection.
- Support Task 4 gap assessment across the network, device, and cloud pillars, including evidence expectations within the ZTA Overlay.
- Validate the patterns with IC engineering teams, including CIT, HPC, and clinical platform owners.
Required Qualifications
- Bachelor’s degree plus 7+ years of network and/or cloud security engineering.
- Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments.
- Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services.
- Security+ or a higher security certification.
- Ability to obtain an NIH suitability determination and PIV credential, and fluency in English.
Tools and Technologies
- AWS, Azure, GovCloud
- Cloud-native IAM and CSPM
- SSE/ZTNA (including Zscaler, Palo Alto)
- Microsegmentation platforms (including Illumio)
- Palo Alto, Fortinet, Cisco firewalls
- Microsoft Defender, CrowdStrike, Forescout
- Splunk and Microsoft Sentinel
- Terraform, IaC, Git, CloudFormation
Work Location and Schedule
- Location: Bethesda, MD (hybrid)
- On-site expectations: typically 1–2 days/week for workshops and pilots during the first 120 days, then as scheduled
Citizenship and Clearance Requirements
- U.S. Citizenship required
- All staff must obtain NIH suitability and a PIV credential and be fluent in English
- For risk or vulnerability testing, a current T2 (BI) or higher investigation is required
Salary
$130,000 to $140,000 per year
Preferred Qualifications
- A cloud security certification such as AWS Security Specialty, AZ-500, or CCSP; PCNSE or CCNP Security
- Experience in FedRAMP-authorized or GovCloud environments
- Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation
- Infrastructure-as-code experience with Terraform and/or CloudFormation, including writing security patterns as code
- Current NIH or U.S. Department of Health and Human Services (HHS) experience is highly preferred
Equal Employment Opportunity
eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.