CrawlJobs Logo

Zero Trust / Security Engineering SME

altamiracorp.com Logo

Altamira Technologies

Location Icon

Location:
United States , Dayton, OH

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

Altamira is seeking a Zero Trust / Security Engineer to support the design, implementation, and operation of secure cloud and platform environments for mission-critical systems. This role focuses on identity and access management, secrets management, authentication and authorization frameworks, and Zero Trust architectures within classified environments. The ideal candidate brings strong experience in cloud security, DevSecOps practices, and enterprise identity systems, and is comfortable collaborating with platform, infrastructure, and application teams to embed security into all phases of system development and operations.

Job Responsibility:

  • Design and implement Zero Trust security architectures in cloud and hybrid environments
  • Configure and manage identity and access management systems, including Keycloak and OAuth2-based solutions
  • Implement and operate secrets management platforms such as HashiCorp Vault
  • Develop and enforce authentication, authorization, and access control policies
  • Integrate security controls into CI/CD and DevSecOps pipelines
  • Support system hardening, vulnerability management, and security compliance activities
  • Monitor and respond to security events, incidents, and anomalies
  • Conduct security assessments, reviews, and risk analyses
  • Collaborate with engineering teams to implement secure-by-design solutions
  • Support accreditation, authorization, and audit processes
  • Develop and maintain security documentation, standards, and runbooks

Requirements:

  • Ability to obtain TS/SCI clearance
  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
  • Experience in cybersecurity, DevSecOps, or security engineering roles
  • Experience implementing IAM and authentication systems
  • Hands-on experience with secrets management and secure credential handling
  • Experience supporting cloud-based and hybrid security architectures
  • Strong understanding of network, application, and identity security principles
  • Experience working in compliance-driven environments (e.g., RMF, NIST, STIGs)
  • Strong troubleshooting and incident response skills
  • Ability to work effectively in secure, mission-focused environments

Nice to have:

  • Certified Kubernetes Application Developer (CKAD) Certification
  • Experience with HashiCorp Vault and Keycloak in production environments
  • Experience with Kubernetes security and container hardening
  • Experience implementing Zero Trust frameworks in DoD or IC environments
  • Familiarity with OpenTelemetry, SIEM, and security monitoring platforms
  • Experience with infrastructure and configuration automation (Terraform, Ansible, etc.)
  • Relevant certifications (CISSP, CCSP, Security+, AWS Security Specialty, etc.)
  • Prior experience supporting DoD or Intelligence Community programs

Additional Information:

Job Posted:
March 19, 2026

Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Zero Trust / Security Engineering SME

Security Engineer II

PagerDuty is seeking an Enterprise Security Engineer to join its global IT Opera...
Location
Location
Canada , Toronto
Salary
Salary:
122000.00 - 185000.00 CAD / Year
https://www.pagerduty.com Logo
PagerDuty
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • At least 3 years of experience in the information security industry, with 2+ years in network security or zero-trust, and 2+ years in security architecture or solution experience
  • Knowledge of Information Security concepts, especially in the areas of security threats, analyzing security logs and driving Incident response
  • Knowledge and practical experience in network security and zero-trust
  • Understanding of the IAM cybersecurity landscape, including identity stores, authentication/authorization, strong authentication, and privileged access management capabilities and methodologies
  • Understanding of security technologies and concepts, including SIEM, MDR/XDR, EDR and vulnerability management
  • Understanding of security best practices and frameworks (e.g., MITRE ATT&CK, NIST Cybersecurity Framework)
  • Knowledge of incident response processes
Job Responsibility
Job Responsibility
  • Partner closely with CISO organization to design and implement enterprise IT security architectures and solutions
  • Tracking the evolution of cutting-edge security technologies, and keeping up to date of the latest security threats and trends
  • Focus on enterprise security and zero-trust technology, serving as the principal technical expert in this area within the Enterprise Security department
  • Monitors security alerts and leads the team in identifying and responding to security threats
  • Monitors systems for vulnerabilities, provides prioritization, and drives remediation efforts
  • Working cross-functionally to triage suspicious activity and drive remediation (performing L2-L3 duties as needed)
  • Analyzing threat intelligence feeds to develop metrics, alerts, and techniques to protect against new and emerging attack vectors
  • Develop metrics, thresholds, alerts, dashboards, and incident response playbooks
  • Drive the design and development of automated security response and maintenance solutions
  • Oversee our workstation vulnerability management & endpoint compliance program
What we offer
What we offer
  • Competitive salary
  • Comprehensive benefits package
  • Flexible work arrangements
  • Company equity
  • ESPP (Employee Stock Purchase Program)
  • Retirement or pension plan
  • Generous paid vacation time
  • Paid holidays and sick leave
  • Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
  • Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent
  • Fulltime
Read More
Arrow Right

Data Security Engineer

The data security engineer is responsible for designing, implementing, and maint...
Location
Location
United States , Spring
Salary
Salary:
106000.00 - 243000.00 USD / Year
https://www.hpe.com/ Logo
Hewlett Packard Enterprise
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Or equivalent experience
  • 8 years of experience in cybersecurity, with at least 5 years focused on DLP
  • Hands-on experience with tools like Zscaler DLP, Microsoft IPG, or equivalent
  • Strong understanding of data protection regulations (HIPPA, PCI, SOX) and enterprise compliance frameworks
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent
  • Knowledge of the NIST 800-53, ISO 27001, and Zero Trust
  • Strong analytical and problem-solving skills
  • Excellent communication and leadership skills
  • Ability to manage multiple high-impact projects simultaneously
Job Responsibility
Job Responsibility
  • Lead the design and deployment of enterprise data protection capabilities like DLP, encryption, SSPM, and CASB
  • Lead the evaluation and adoption of new security tools and technologies
  • Manage and fine tune data security policies with the changing requirements
  • Contribute to security policies, standards, and procedures to ensure compliance with industry best practices and regulatory requirements
  • Collaborate with IT and DevOps teams to integrate security into the software development lifecycle (SDLC), infrastructure as code (IaC), and cloud environments
  • Collaborate with data warehouse team to feed data into SIEM and long term storage solutions
  • SME for the technical response of high-severity security incidents
  • Contribute to playbooks and procedures
  • Collaborate with key stakeholders, including IT, DevOps, legal, and compliance teams
  • Provide expert guidance on emerging threats, technologies, and regulatory requirements
What we offer
What we offer
  • Health & Wellbeing benefits
  • Personal & Professional Development programs
  • Unconditional Inclusion environment
  • Comprehensive suite of benefits supporting physical, financial and emotional wellbeing
  • Fulltime
Read More
Arrow Right

Cloud Network Security Engineer

A Cloud Network Security Engineer is focused on Azure networking is responsible ...
Location
Location
United States , Multiple Locations
Salary
Salary:
119800.00 - 234700.00 USD / Year
https://www.microsoft.com/ Logo
Microsoft Corporation
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Doctorate in Cyber Security, Data Science, Mathematics, Computer Science, or related field
  • OR Master's Degree in Cyber Security, Data Science, Mathematics, Computer Science, or related field AND 3+ years experience in one or more of the following: Cloud security engineering (Azure, AWS, or GCP)
  • Cloud networking and network security (VNETs, firewalls, routing, segmentation, Zero Trust network controls)
  • Secure cloud architecture or zero‑trust design
  • Threat modeling for cloud-native services
  • Cloud identity & access management (IAM), RBAC, or conditional access
  • Infrastructure‑as‑Code (IaC) security (e.g., Bicep, Terraform)
  • Cloud workload protection, CSPM, CWPP
  • Cloud threat detection, anomaly detection, or behavioral analytics
  • Security monitoring and incident response for cloud environments
Job Responsibility
Job Responsibility
  • Design and secure Azure cloud network architectures supporting highly available, fully automated workloads
  • Act as the SME for Azure network security services, advising engineers, developers, analysts, and penetration testers
  • Integrate Azure network services and logs with broader security platforms and cloud‑native big‑data systems to enable monitoring, alerting, and analytics
  • Operate and manage large‑scale cloud network security services, including incident investigation, threat response, and continuous service reliability improvements
  • Automate deployments, configuration updates, and operational workflows using scripting, infrastructure‑as‑code, and AI‑driven solutions
  • Maintain overall platform health through proactive troubleshooting, monitoring, telemetry analysis, and continuous improvement of cloud network coverage
  • Execute cloud service deployments and upgrades in alignment with change management processes while driving service quality through data‑driven insights
  • Fulltime
Read More
Arrow Right

IAM - Privileged Access Management Principal

Principal PAM Architect to lead the strategy, architecture, design, and implemen...
Location
Location
United States , Houston
Salary
Salary:
117500.00 - 270000.00 USD / Year
https://www.hpe.com/ Logo
Hewlett Packard Enterprise
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
  • 8+ years in cybersecurity or IT with demonstrated hands-on PAM specific experience in enterprise-scale environments
  • Proven experience in architecture, design, and implementation of PAM solutions across large, complex enterprises
  • Deep technical expertise with CyberArk (Privileged Cloud and on-prem)
  • Strong knowledge of Zero Trust principles, JIT/JEA access models, and privileged identity lifecycle management
  • Experience integrating PAM with cloud platforms (Azure, AWS, GCP), DevOps pipelines, and enterprise IT ecosystems
  • Experience with secrets management platforms (CyberArk Conjur, HashiCorp Vault, AWS Secrets Manager, etc.)
  • Working knowledge of modern authentication standards (SAML, OIDC, FIDO2, MFA, passwordless)
  • Hands-on expertise with Windows, Linux, Active Directory, and cloud IAM models
  • Good understanding of the privilege access models of Active Directory, Azure/Entra ID, AWS and GCP
Job Responsibility
Job Responsibility
  • Define PAM strategy, roadmap, and reference architectures aligned to enterprise security and compliance requirements
  • Design and implement scalable PAM solutions for large, complex environments across on-prem, hybrid, and multi-cloud infrastructures
  • Incorporate Zero Trust, Just-in-Time (JIT), and Just Enough Access (JEA) models into PAM solutions
  • Lead the enterprise rollout and lifecycle management of CyberArk Privileged Cloud and related modules
  • Implement and manage privileged session monitoring, endpoint privilege management (EPM), and application-to-application password management
  • Drive integration of PAM with identity providers, SIEM/SOAR, ITSM, and DevOps pipelines
  • Establish and enforce policies for privileged access governance, auditing, and regulatory compliance
  • Conduct regular reviews of PAM controls to prevent credential theft, lateral movement, and unauthorized access
  • Act as the PAM subject matter expert (SME), advising executives, architects, and engineering teams on privileged access security
  • Mentor and guide engineering teams on PAM best practices and secure operations
What we offer
What we offer
  • Health & Wellbeing benefits
  • Personal & Professional Development programs
  • Unconditional Inclusion environment
  • Comprehensive benefits suite supporting physical, financial and emotional wellbeing
  • Fulltime
Read More
Arrow Right

Infrastructure Engineer - Network Security

The Network Security team ensures that Campbell’s business operations including ...
Location
Location
United States , Camden
Salary
Salary:
131400.00 - 188900.00 USD / Year
campbells.com Logo
THE VAIL CORPORATION
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum education required, with specialization as appropriate: Bachelors Degree or equivalent work experience in Information Technology or Information Security
  • 6+ of experience in IT or Information Security
  • 3+ Years of IT Systems Management (Plan/Build/Run)
  • 3+ years of Firewall policy management (Deployment/Operations) for one or more of the leading NGFW companies (Palo Alto, Fortinet, Checkpoint)
  • Previous experience working in outsourced IT environments
  • Ability to translate business needs into implementation plans and can articulate cost implications of options
  • Extensive knowledge & understanding of NGFWs, SSL VPN, NAC & RBAC, Privileged access (PAM) & SASE solutions
  • Vendor knowledge and past implementation of Cisco, Aruba & Fortinet
  • Extensive experience with Firewall & SSL VPN based policy management
  • both with direct implementation and guiding principles with ‘zero-trust’ approach
Job Responsibility
Job Responsibility
  • Develop, document, communicate, and enforce a network technology standards policy which is delivers value, is manageable and scalable
  • Conduct analysis of security requirements and controls to identify gaps and provides recommendations of industry best practices, trends, and technology products
  • Conduct research and make recommendations on network products, services, protocols, and standards in support of network procurement and digital development efforts
  • Lead efforts on Network infrastructure transition following ‘DevSecOps’ principles & framework in alignment with business application and related Enterprise Architectural standards
  • Help build strategic plans by leveraging leading-edge scientific and technological knowledge to drive business strategies as well as enhance the value proposition of IT solutions across cost, stability and security frameworks
  • Participating and enabling successful Business projects that have network security dependencies
  • Executing and ensure the successful delivery of IT Network and Network security tech
  • Assist with the design and implementation of short- and long-term strategic plans to ensure network services meet existing and future business requirements
  • Works closely with other groups, including System Administrators, AppOps, Infosec, Incident response & Vulnerability management teams, to ensure corporate compliance & improvements across network infrastructure
  • Provide support for Infosec related project initiatives and CSIRT event responses
What we offer
What we offer
  • Benefits begin on day one and include medical, dental, short and long-term disability, AD&D, and life insurance (for individual, families, and domestic partners)
  • Employees are eligible for our matching 401(k) plan and can enroll on the first day of employment with immediate vesting
  • Campbell’s offers unlimited sick time along with paid time off and holiday pay
  • If in WHQ – free access to the fitness center
  • Access to on-site day care (operated by Bright Horizons) and company store
  • Giving back to the communities where our employees work and live is very important to Campbell’s
  • Our “Campbell’s Cares” program matches employee donations and/or volunteer activity up to $1,500 annually
  • Campbell’s has a variety of Employee Resource Groups (ERGs) to support employees
  • competitive health, dental, 401k and wellness benefits beginning on the first day of employment
  • Fulltime
Read More
Arrow Right

IAM Security Engineer

Truveta is the world’s first health provider led data platform with a vision of ...
Location
Location
United States , Seattle; Bellevue
Salary
Salary:
128000.00 - 155000.00 USD / Year
truveta.com Logo
Truveta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree or equivalent in Computer Science, Information Security, or Information Systems
  • 3-5 years of hands-on experience in an Identity and Access Management (IAM) role with a strong focus on Azure environments
  • Strong understanding of Azure Entra ID (Azure Active Directory), including Conditional Access, MFA, Identity Governance, PIM, directory services, and RBAC
  • Experience supporting SSO integrations and identity protocols such as SAML, OAuth 2.0, OpenID Connect, and SCIM provisioning
  • Ability to analyze and improve access models, workflows, and entitlements, applying least privilege and zero-trust principles
  • Proficiency with PowerShell or similar scripting tools to automate IAM tasks
  • Experience monitoring for identity-related threats, anomalous login behavior, and misconfigurations in cloud IAM environments
  • Working knowledge of IT/security governance and compliance frameworks (e.g., SOC 2, ISO 27001, NIST) and experience supporting audits or access reviews
  • Strong troubleshooting and diagnostic skills for identity issues involving authentication, authorization, directory sync, and permissions
  • Excellent written and verbal communication skills, including the ability to work cross-functionally with engineering, IT, and security teams
Job Responsibility
Job Responsibility
  • Identity Lifecycle & Access Management: Manage and improve provisioning, de-provisioning, and modification processes for user accounts and service principals across cloud and enterprise systems
  • Conduct access reviews, entitlement cleanups, and role evaluations to ensure least-privilege access
  • Identify gaps in lifecycle processes and recommend enhancements or workflow automation opportunities
  • Access Requests & Role Governance: Process and validate access requests, ensuring alignment with RBAC models, security policies, and job function requirements
  • Contribute to the development and refinement of RBAC roles, access policies, and approval workflows
  • Partner with stakeholders to analyze access patterns and propose more efficient and secure role structures
  • Application Integration & IAM Enablement: Support onboarding applications into IAM systems, including SSO configuration, SCIM provisioning, OAuth app integration, and secure authentication setup
  • Work with application and engineering teams to ensure proper identity integration and consistent enforcement of IAM standards
  • Assist with evaluating and implementing new IAM tools or capabilities as the organization evolves
  • Security Controls & Identity Governance: Implement and support IAM security controls such as MFA, Conditional Access policies, PIM, and identity governance features
What we offer
What we offer
  • Interesting and meaningful work for every career stage
  • Comprehensive benefits with strong medical, dental and vision insurance plans
  • 401K plan
  • Professional development & training opportunities for continuous learning
  • Work/life autonomy via flexible work hours and flexible paid time off
  • Generous parental leave
  • Regular team activities (virtual and in-person)
  • Additional compensation such as incentive pay and stock options for certain roles.
  • Fulltime
Read More
Arrow Right

Network and Security Architect - SASE

We are seeking a highly skilled and experienced Network and Security Architect w...
Location
Location
Poland , Łódź
Salary
Salary:
Not provided
https://www.bosch.pl/ Logo
Robert Bosch Sp. z o.o.
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of progressive experience in network and security architecture, with a strong focus on cloud security
  • 5+ years of hands-on experience designing, deploying, and managing large-scale ZTNA and SASE solutions in enterprise environments
  • Deep understanding and practical experience with leading SASE vendor platforms (e.g., Zscaler, Palo Alto Networks Prisma Access, Fortinet FortiSASE, Netskope, etc.)
  • Proven expertise in Zero Trust principles and their practical implementation across various layers (identity, device, application, data)
  • Strong knowledge of networking protocols (TCP/IP, BGP, OSPF, DNS, HTTP/S), VPN technologies (IPsec, SSL VPN), and network security concepts (firewalls, IDS/IPS, WAF)
  • Experience with cloud platforms (Azure, AWS, GCP) and their security services
  • Proficiency in identity and access management (IAM) concepts and technologies (SAML, OAuth, OpenID Connect, MFA)
  • Excellent analytical, problem-solving, and decision-making skills
  • Strong communication, presentation, and interpersonal skills with the ability to influence and persuade stakeholders at all levels
  • Ability to work independently and as part of a global, cross-functional team
Job Responsibility
Job Responsibility
  • Lead the design, development, and evolution of Bosch's global ZTNA and SASE architecture, ensuring alignment with industry best practices, regulatory requirements, and Bosch's security policies
  • Define architectural patterns, standards, and blueprints for ZTNA and SASE components, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall-as-a-Service (FWaaS), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), and advanced threat protection
  • Evaluate and recommend new technologies, vendors, and solutions within the ZTNA/SASE ecosystem to enhance Bosch's security capabilities and optimize performance
  • Develop and maintain the architectural roadmap for ZTNA and SASE, forecasting future needs and anticipating technological shifts
  • Oversee the end-to-end deployment of ZTNA and SASE solutions, including planning, design, implementation, testing, and go-live
  • Collaborate with network engineering, security operations, application development, and business units to ensure seamless integration of ZTNA/SASE with existing IT infrastructure and applications
  • Define integration strategies for identity providers (e.g., Azure AD), endpoint security solutions, and other security tools
  • Provide expert guidance and technical leadership to implementation teams and external vendors
  • Translate high-level security requirements into detailed ZTNA and SASE policies, rules, and configurations
  • Develop and enforce security standards and guidelines for secure access, data protection, and threat prevention within the SASE framework
What we offer
What we offer
  • Competitive salary + annual bonus
  • Hybrid work with flexible working hours
  • Referral Bonus Program
  • Copyright costs for IT employees
  • Complex environment of working, professional support and possibility to share knowledge and best practices
  • Ongoing development opportunities in a multinational environment
  • Broad access to professional trainings (incl. language courses), conferences and webinars
  • Private medical care and life insurance
  • Cafeteria System with multiple benefits (incl. MultiSport, shopping vouchers, cinema tickets, etc.)
  • Prepaid Lunch Card
  • Fulltime
Read More
Arrow Right

Senior Cloud Security Assurance

NTT DATA is one of the world's largest global security service providers, partne...
Location
Location
Romania , Cluj
Salary
Salary:
Not provided
nttdata.com Logo
NTT DATA
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in Information Security, Cybersecurity, or a relevant IT field (Master’s degree preferred)
  • Minimum 5-10 years experience in security architecture, compliance, and cloud security roles, working with frameworks such as ISO 27001, NIS/NIS2, or NIST CSF
  • Deep understanding of cloud security principles including management on AWS, and GCP platforms
  • Familiarity with IAM, CASB, SIEM, and container security solutions
  • CISSP or SABSA certifications required
  • Cloud-specific certifications preferred (e.g., AWS Security Specialty, zure Solutions ArchitectA)
  • Direct experience working in government, military, or intelligence organizations advantageous
  • Must meet UK SC Clearance eligibility guidelines
  • Proven ability to collaborate across diverse technical teams, influencing senior stakeholders in an advisory capacity
  • Excellent communication and presentation skills for delivering complex technical concepts to non-specialist audiences
Job Responsibility
Job Responsibility
  • Translate business and compliance requirements into practical, well-documented security architecture designs using recognized frameworks (e.g., ISO 27001, NIST, CIS)
  • Develop, document, and maintain consistent secure architectural patterns with an emphasis on cloud security (AWS, GCP)
  • Implement threat-informed design principles, integrating zero trust architectures and defensive depth strategies to address security gaps and enhance resilience
  • Maintain alignment between security policies, enterprise architecture principles, and client expectations
  • Conduct comprehensive risk assessments and threat modeling to evaluate existing or proposed architectures for vulnerabilities
  • Provide actionable mitigation strategies informed by a risk-based approach and evolving threat intelligence data
  • Participate in or support incident response initiatives, aiding in root cause analysis and the development of post-incident recommendations
  • Act as a trusted advisor to clients by engaging in technical discussions to inform strategic security decisions
  • Collaborate cross-functionally with development, operations, and engineering teams to validate that security controls are effectively implemented across the development lifecycle
  • Deliver technical insights in presentations, workshops, and reports tailored to both technical and executive audiences
What we offer
What we offer
  • Smooth integration and a supportive mentor
  • Pick your working style: choose from Remote, Hybrid or Office work opportunities
  • Projects have different working hours to suit your needs
  • Sponsored certifications, trainings and top e-learning platforms
  • Private Health Insurance
  • Individual coaching sessions or joining our accredited Coaching School
  • Epic parties or themed events
Read More
Arrow Right