Zero Trust Cyber Security Engineer
Job Description
Remote role to assess, implement, maintain, and report on the VA's Zero Trust architecture in partnership with cross-functional teams.
Responsibilities
- Evaluate the infrastructure against the Department of Defense Zero Trust Maturity Model to determine compliance levels.
- Generate a monthly Maturity Scorecard report driven by customer parameters and governance needs.
- Develop a dashboard to visualize the Monthly Maturity Scorecard results.
- Calculate and communicate the percentage compliance for each Zero Trust Pillar's capability groupings.
- Assess each Zero Trust Pillar and recommend targeted improvement opportunities.
- Refresh dashboard data using the Monthly Maturity Scorecard and its underlying sources.
- Document the assessment approach aligned with CISA and DoD Zero Trust Maturity Models.
- Extend VA specific reference architecture target capabilities to support ZTA initiatives.
- Capture how VA should implement ZTA on the target architecture across conceptual, logical, and implementation layers.
- Collaborate with ZTA Pillar Leads to determine whether current toolsets suffice or new tools are needed.
- Assist in forming ZTA Engineering and Implementation plans to deploy ZTA Use Cases across VA information systems, accounting for variations across systems.
- Update plans to reflect new use cases, deployments, and stakeholder or system owner feedback.
- Deliver 100 information system implementations within each performance period.
- Coordinate with the VA Office of Information Security to onboard systems into the Operations and Maintenance Risk Management Framework.
Requirements
- Bachelor's degree with 10+ years of cybersecurity engineering experience, or 18+ years of equivalent industry experience.
- Ability to obtain and maintain a Public Trust clearance.
- Proven experience in dashboard design and delivery.
- Demonstrated history as a Cyber Security Engineer focused on deploying and sustaining Zero Trust architectures.
- Deep knowledge of Zero Trust concepts, IAM, micro-segmentation, network security, and encryption techniques.
- Hands-on experience with core security tools including firewalls, IDS/IPS, and SIEM platforms.
- Familiarity with regulations and compliance requirements such as NIST 800-207, OMB M-22-09, CISA Zero Trust Security Model, and EO 14028.
- Strong analytical and problem-solving abilities; capable of collaborating in fast-paced, cross-functional environments.
- Excellent communication skills for conveying complex security concepts to both technical and non-technical stakeholders.
Technologies
- Department of Defense Zero Trust Maturity Model
- CISA/DoD Zero Trust Maturity Models
- NIST 800-207
- OMB M-22-09
- CISA Zero Trust Security Model
- Executive Order 14028 – Improving the Nation’s Cybersecurity
- eMASS
- ServiceNow CAM
- Software-defined perimeter (SDP) tools
- Identity and Access Management (IAM) solutions
- Micro-segmentation technologies
- Firewall solutions
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- SIEM tools
- PIV (VA certificate)
Benefits
- Competitive compensation
- Health and Wellness programs
- Income protection
- Paid leave
- Retirement benefits