Zero Trust Engineer – Tanium / Eclypsium / SteelCloud / Microsoft Defender / Azure
G2IT · Suitland, Maryland, United States · On-site
Pay: USD 130,000 – 150,000 a year
Posted Sep 8, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Zero Trust Engineer – Tanium / Eclypsium / SteelCloud / Microsoft Defender / Azure
Clearance: Active TS/SCI Location: Customer/DoD facility; on-site/hybrid as mission requirements permit Environment: U.S. Navy / Department of War classified and mission-critical networks
Position Overview
G2IT is seeking an experienced Zero Trust Engineer to design, implement, integrate, and sustain Zero Trust capabilities across classified and unclassified Navy and DoW enterprise environments. The engineer will support the modernization and hardening of complex IT environments by integrating endpoint visibility, vulnerability and firmware security, configuration compliance, threat protection, identity, and cloud security capabilities.
The ideal candidate has hands-on experience with Tanium, Eclypsium, SteelCloud ConfigOS, Microsoft Defender, Microsoft Azure, and Azure Bicep , and understands how these technologies contribute to an integrated Zero Trust architecture rather than operating as independent security tools.
Key Responsibilities
Engineer, deploy, configure, integrate, and sustain Zero Trust security capabilities across Navy and DoW enterprise environments.
Implement Zero Trust principles consistent with DoD Zero Trust Strategy and Zero Trust Capability Execution Roadmap , including continuous verification, least-privilege access, endpoint/device trust, visibility, automation, and policy enforcement.
Deploy and administer Tanium capabilities supporting endpoint visibility, asset discovery, vulnerability management, configuration management, compliance, and remediation.
Implement and support Eclypsium for firmware, hardware, supply-chain, and device-level security visibility and risk identification.
Engineer and administer SteelCloud ConfigOS to automate STIG compliance, security configuration, remediation, and continuous compliance activities.
Configure and integrate Microsoft Defender capabilities for endpoint protection, threat detection, vulnerability management, investigation, and response.
Design and support secure Microsoft Azure environments, including implementation of security controls, policies, identity, networking, monitoring, and logging.
Develop and maintain Azure Bicep Infrastructure-as-Code (IaC) templates to provide repeatable, controlled, and auditable deployment of Azure infrastructure and security configurations.
Integrate security platforms and telemetry to establish a consolidated view of device posture, vulnerability, configuration compliance, threats, and remediation status .
Develop automated workflows for identifying, prioritizing, and remediating vulnerabilities and configuration deficiencies.
Support implementation and validation of DISA STIGs, Security Technical Implementation requirements, RMF controls, and applicable DoD cybersecurity policies .
Work with cybersecurity, network, cloud, systems engineering, and operations teams to incorporate Zero Trust requirements into existing and…