{"id":1639171,"url":"https://alion.io/job/ideal-innovations-network-security-engineer-sme","title":"Network Security Engineer SME","company":{"id":3854329,"name":"Ideal Innovations","domain":"idealinnovations.com","url":"https://alion.io/company/ideal-innovations","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"UltiPro","truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Clarksburg, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":129000,"max_usd":261000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":297},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Agile","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Confluence","optional":false},{"name":"DLP","optional":false},{"name":"DNS","optional":false},{"name":"Jira","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false}],"status":"live","first_seen_at":"2026-06-25T13:57:48Z","employer_posted_date":"2026-06-25","last_verified_at":"2026-10-09T01:13:42Z","board_verified":true,"closed_at":null,"days_open":105,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":104},"description":"* Hands-on experience with Zscaler (ZIA/ZPA) or comparable cloud security / SWG / ZTNA platforms strongly preferred*\nHighlights:\nThis is a rare opportunity to lead a high-impact Zero Trust transformation supporting the FBI CJIS division, driving the shift from legacy network security to a modern, cloud-first architecture powered by Zscaler. You will play a key role in implementing cutting-edge security capabilities aligned with TIC 3.0 while working alongside highly experienced engineers in a mature SAFe Agile environment. This role offers the chance to shape future-state architecture, solve complex challenges at scale, and build highly marketable expertise across both federal and commercial sectors.\nThe team consists of a collaborative mix of government personnel and contractor staff from multiple organizations, working together in a mature SAFe Agile environment. The culture emphasizes teamwork, technical excellence, and shared accountability, with a strong focus on delivering high-quality solutions to mission-critical systems.\nThis role combines hands-on engineering, architecture, and transformation leadership in a single position. It provides the opportunity to work on a large-scale Zscaler implementation and Zero Trust initiative that is directly aligned with federal modernization efforts such as TIC 3.0. The position offers exposure to complex enterprise environments and the ability to make meaningful, visible contributions to a high-profile mission.\nThe individual in this role will play a critical part in modernizing the organization’s security posture, enabling secure, cloud-first access to applications and services. Their contributions will help reduce reliance on legacy infrastructure, improve visibility and control, and enhance overall cybersecurity capabilities through the implementation of Zero Trust principles.\nThe candidate will acquire the following skills should they accept:Hands-on experience with Zscaler ZIA and ZPA implementations at enterprise scale\nDeep understanding of Zero Trust architecture and SASE frameworks\nExperience aligning technical solutions to TIC 3.0 and federal security modernization initiatives\nAdvanced experience operating within a SAFe Agile environment in a large government organization\nEnhanced expertise in cloud security, identity-driven access, and network transformation strategies\n\nTypical Day:\nA typical day entails operating within a SAFe Agile environment, starting with a brief daily stand-up to align on priorities, provide updates, and identify blockers. Team communication and coordination are primarily conducted through Microsoft tools and Jira, with work tracked via assigned tickets and sprint boards.\nWork is executed in two-week sprint cycles, focusing on prioritized stories and features defined by leadership. In parallel, the role supports ongoing Operations & Maintenance (O&M) activities, including service ticket resolution, vulnerability management, and system sustainment to ensure operational stability.\nTasks:\nParticipate in SAFe Agile ceremonies (daily stand-ups, sprint planning, retrospectives) and deliver work within sprint cycles\nLead the implementation of Zscaler ZIA and ZPA to support Zero Trust and cloud-delivered security objectives\nDevelop and execute migration strategies to transition from legacy forward proxies and VPNs to Zscaler-based architectures\nDesign direct-to-cloud connectivity solutions that eliminate on-premises traffic backhaul\nConfigure and optimize Zscaler policies (URL filtering, SSL inspection, DLP, access controls) to meet security requirements\nIntegrate Zscaler with enterprise identity providers (e.g., Active Directory, Azure AD) to enforce identity-based access\nCollaborate with cross-functional teams (network, security, cloud) to support Zero Trust and TIC 3.0-aligned architectures\nManage and resolve complex network security issues, including traffic flow, access, and policy enforcement troubleshooting\nSupport Operations & Maintenance (O&M) activities such as service ticket resolution, vulnerability remediation, and system sustainment\nDevelop and maintain technical documentation, including architecture diagrams, implementation plans, and operational procedures\nRequired Qualifications:\n Hands-on experience with Zscaler (ZIA/ZPA) or comparable cloud security / SWG / ZTNA platforms strongly preferred\n10+ years of network security or cybersecurity engineering experience required\nEducation: A degree may substitute for a portion of the required experience\nProven experience as a technical lead / SME on enterprise network or security projects\nExperience supporting large-scale network security migrations (e.g., proxy/VPN to cloud-based or Zero Trust architectures)\nExperience supporting Zero Trust architecture or modern secure access solutions\nExperience integrating with identity providers (Active Directory, Azure AD, SAML/OIDC)\nStrong background in enterprise networking and security, including firewalls (Palo Alto, Cisco, etc.), routing, DNS, and proxy architectures\nExperience with SIEM/logging platforms (Splunk preferred)\nExperience troubleshooting complex network and security issues in enterprise environments\nDesired Qualifications:\nZscaler certifications (e.g., ZDTA, ZDTE, ZCCA-IA, ZCCA-PA)\nExperience leading or supporting a Zscaler ZIA/ZPA enterprise deployment\nFamiliarity with CISA TIC 3.0 and federal network security modernization initiatives\nExperience replacing on-prem forward proxies and/or VPNs with cloud-delivered security solutions\nKnowledge of Zero Trust architecture (ZTA) and SASE frameworks\nExperience designing or implementing direct-to-cloud access architectures (avoiding traditional network backhaul)\nCloud experience with AWS and/or Azure, including networking and security integration\nSecurity certifications (e.g., Security+, CASP/X, CISSP)\nCisco certifications (e.g., CCNA, CCNP)\nExperience working in a SAFe Agile environment using Jira and Confluence\nPosition Type Shift Information:\nDay Shift 8am-5pm\nUS Citizenship: US citizenship required\nClearance: Top Secret clearance required\nLocation: FBI CJIS Campus (Clarksburg, WV)\n\nIdeal Innovations, Inc. is an Equal Opportunity Employer: \nAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or veteran status. \nIdeal Innovations, Inc. is a VEVRAA Federal Contractor .","description_format":"text","description_chars":6443,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":true,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security"],"lifecycle":[{"event":"open","at":"2026-10-01T21:44:19Z"}],"visa":[],"liveness":{"score":12,"band":"cold","label":"Long shot","p_open":1,"p_active":0.434,"p_room":0.28,"age_days":104,"expected_fill_days":30,"reasons":["conf:1","win:tail","crowd:"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/ideal-innovations-network-security-engineer-sme","json_url":"https://alion.io/job/ideal-innovations-network-security-engineer-sme.json","meta":{"generated_at":"2026-10-09T02:19:57Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":123,"day_limit":5000,"remaining_today":4877,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3854329},"rest":"https://alion.io/mcp/rest/get_company?id=3854329"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fideal-innovations-network-security-engineer-sme"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fideal-innovations-network-security-engineer-sme"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fideal-innovations-network-security-engineer-sme"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/ideal-innovations-network-security-engineer-sme\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fideal-innovations-network-security-engineer-sme"}]}