Senior Deployment Engineer, AppGate ZTNA (Federal)

Remote in Washington, DC, US • Posted 2 days ago • Updated 4 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Management
  • IT Management
  • DoD
  • SIEM
  • Debugging
  • Shell
  • Inspection
  • Regulatory Compliance
  • Incident Management
  • Mentorship
  • Network Security
  • Linux Administration
  • Scripting
  • Bash
  • Windows PowerShell
  • JavaScript
  • Active Directory
  • DNS
  • Dragon NaturallySpeaking
  • SAML
  • OIDC
  • RADIUS
  • LDAP
  • Cloud Computing
  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud
  • Google Cloud Platform
  • Virtualization
  • VMware vSphere
  • Hyper-V
  • Computer Networking
  • TLS
  • IPsec
  • PKI
  • RSA
  • STIG
  • SCAP
  • Hardening
  • ITIL
  • IT Service Management
  • Communication
  • Documentation
  • Information Technology
  • Red Hat Certified Engineer
  • CISSP
  • Cisco Certifications
  • Security+
  • Microsoft Certified Professional
  • SDP
  • Service Delivery Platform
  • Virtual Private Network
  • Terraform
  • Ansible
  • Security Clearance
  • Exceed
  • Adobe AIR

Summary

*** This is a direct hire for AppGate.

The Senior Deployment Engineer is the hands-on technical lead for deploying, installing, configuring, and sustaining the AppGate ZTNA platform across U.S. Federal and DoD environments. The work is engineering, not advisory: standing up controllers and gateways, integrating with customer identity and telemetry systems, hardening to STIG and SCAP baselines, and troubleshooting live issues at the protocol, OS, and application level. The Senior Deployment Engineer owns delivery from project kickoff through operational handoff and mentors junior engineers on the team.

Key Responsibilities
  • Lead end-to-end AppGate ZTNA deployments: install and configure controllers, gateways, and clients across on-premises, cloud, and disconnected environments.
  • Integrate AppGate with customer identity providers and sources of trust and risk telemetry, including SAML, OIDC, RADIUS, LDAP(s), Active Directory, NGFWs, entitlement automation systems, SIEM/SOAR, and ITSM.
  • Design deployment architectures that meet customer requirements for availability, scale, and least privilege access enforcement.
  • Debug failures using logs, shell access, packet captures, and code inspection down to the protocol, OS, and application level.
  • Write and maintain scripts and automation (Bash, PowerShell, JavaScript, REST APIs) to support deployment and sustainment.
  • Harden deployments to STIG, SCAP, and applicable Federal compliance baselines.
  • Serve as the escalation point for complex deployment and sustainment issues.
  • Sustain and maintain deployed environments: patching, upgrades, health monitoring, and incident response.
  • Produce detailed as-built documentation, runbooks, and operational handoff materials.
  • Mentor Associate and mid-level Delivery Engineers and review their work.

Required Qualifications
  • 8 to 12 years in networking, security, systems, platform, or automation engineering roles, with hands-on delivery experience.
  • Demonstrated mastery of Linux systems administration.
  • Hands-on scripting and automation with Bash, PowerShell, and JavaScript.
  • Working knowledge of REST APIs for integration and automation.
  • Strong experience with identity systems: Active Directory, DNS, PKI, SAML, OIDC, RADIUS, and LDAP.
  • Experience deploying to public cloud (AWS, Azure, Google Cloud Platform) and virtualization platforms (VMware vSphere, Microsoft Hyper-V)..
  • Familiarity with networking, transport, and cryptographic protocols such as TLS, IPsec, AES, PKI, and RSA.
  • Experience supporting Federal or other high-assurance environments.
  • Familiarity with STIG and SCAP hardening; process frameworks such as ITIL or ITSM a plus.
  • Excellent written and verbal communication for documentation and customer handoff.
  • Bachelor's degree in engineering, information technology, or a related discipline, or equivalent related experience.

Desired Qualifications
  • CCNP, CCIE, RHCE, CISSP, CCNA, Security +, MCSE or equivalent certifications.
  • Prior experience deploying ZTNA, software-defined perimeter (SDP), or VPN-replacement technologies.
  • Experience with infrastructure as code and configuration as code (Terraform, Ansible).

Clearance
  • Active U.S. security clearance, or the ability to obtain and maintain one. Top Secret a plus.

Travel
  • Willingness to travel to customer sites as project and customer needs require. Travel can exceed 50% depending on the deployment.
  • This is a remote opportunity, though we are ideally looking for someone from the following locations:
    • Scott Air Force Base, in St. Clair County, Illinois
    • Gunter Air Force Base, Montgomery, Alabama
    • Kirland Air Force Base, Albuquerque, New Mexico
    • Maryland/DC/VA area
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91091699
  • Position Id: a9dbbad3464e41892ca184153dee28ab
  • Posted 2 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

McLean, Virginia

Today

Full-time

USD 76,000.00 - 141,000.00 per year

Washington, District of Columbia

Today

Easy Apply

Full-time

$150000 - $200000

Springfield, Virginia

Today

Full-time

Arlington, Virginia

Today

Full-time

USD 175,000.00 - 240,000.00 per year

Search all similar jobs