Zero Trust Infrastructure Engineer

DecisionPoint | Cortek,
Remote

About The Position

DecisionPoint seeks a Zero Trust Infrastructure Engineer to implement and maintain Zero Trust-aligned network, device, and application enforcement across IL5 AWS GovCloud environments. This role focuses on configuring Policy Enforcement Points (PEPs), microsegmentation controls, identity-based routing policies, telemetry integrations, and Zero Trust automation patterns to support a large federal and DoD-aligned mission environment. The Zero Trust Infrastructure Engineer collaborates with architects, cybersecurity teams, network engineers, and application teams to ensure the enterprise environment meets Zero Trust maturity goals and adheres to DoD Zero Trust strategy and implementation guidance. This position is fully remote.

Requirements

  • Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology Engineering, or a related field.
  • Minimum 7 years of experience in IT infrastructure, cloud security, or network security engineering.
  • Experience implementing Zero Trust or identity-based security controls.
  • Experience with microsegmentation, PEP configuration, or conditional access.
  • Experience supporting IL5 cloud or federal security environments.
  • Knowledge of Zero Trust principles, DoD Zero Trust strategy, and enforcement mechanisms.
  • Familiarity with identity-based routing, access policies, and device posture enforcement.
  • Understanding of cloud networking (AWS GovCloud preferred), segmentation, and traffic inspection.
  • Familiarity with telemetry, logging, and distributed monitoring systems.
  • CompTIA Security+ certification.
  • Strong analytical and troubleshooting skills for complex Zero Trust enforcement issues.
  • Excellent communication and collaboration abilities across technical and mission teams.
  • High attention to detail, especially in policy tuning and enforcement logic.
  • Ability to work in fast-paced, mission-critical environments.
  • Strong documentation discipline and ability to translate complex configurations into clear guidance.

Nice To Haves

  • Experience with policy-as-code frameworks or Zero Trust automation tools.
  • Experience with SIEM platforms, identity platforms, and cloud-native enforcement services.
  • Experience with microservices or container-based traffic enforcement.
  • ITIL v4 Foundation certification.
  • CCSP, CISSP, or Zero Trust-focused certifications.
  • AWS security or networking certifications.

Responsibilities

  • Implement Zero Trust Policy Enforcement Points (PEPs) across network, device, and application layers.
  • Configure microsegmentation policies, identity-based routing, and dynamic access controls.
  • Support Zero Trust automation workflows, including policy-as-code and continuous verification mechanisms.
  • Integrate telemetry feeds from applications, identity services, cloud platforms, and network sensors into enforcement logic.
  • Apply Zero Trust principles to cloud network segmentation, traffic inspection, and resource access.
  • Support the implementation of device posture checks, endpoint trust validation, and conditional access rules.
  • Assist in the development and enforcement of Zero Trust security policies aligned with DoD guidance.
  • Troubleshoot enforcement issues, telemetry gaps, and policy misconfigurations.
  • Participate in Zero Trust maturity assessments, roadmap updates, and implementation planning.
  • Maintain Zero Trust infrastructure documentation, diagrams, and policy mappings.
  • Collaborate with cybersecurity teams to align Zero Trust enforcement with RMF controls and IL5 cloud requirements.
  • Support monitoring, logging, and analytics for Zero Trust events and enforcement decisions.

Benefits

  • Equal Employment Opportunity and Affirmative Action employer
  • Will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service