
Zero Trust Policy Engineer
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in United States.
β’ Develop and sustain Zero Trust access policies encompassing identity, device posture, network segments, applications, and data resources.
β’ Convert mission requirements, risk assessments, and threat intelligence into adaptive access control rules.
β’ Establish policy logic, enforcement patterns, and authorization decision workflows in accordance with Zero Trust principles.
β’ Partner with IAM, network, cloud, and application teams to implement and verify policy execution points.
β’ Correlate identity attributes, device health signals, behavioral indicators, and contextual factors to inform access decisions.
β’ Assist in planning for microsegmentation, policy development, and rule refinement.
β’ Aid in the creation of Zero Trust governance frameworks, documentation standards, and policy control baselines.
β’ Engage in architecture and design discussions to ensure comprehensive Zero Trust policy coverage across enterprise systems.
β’ Perform policy impact assessments, test enforcement modifications, and support troubleshooting during rollout phases.
β’ Analyze access activity logs, policy violations, and behavioral signals to improve policies.
β’ Contribute to the development of Zero Trust playbooks, implementation roadmaps, and knowledge sharing across teams.
β’ Facilitate alignment with DoD cybersecurity requirements, mission resiliency objectives, and continuous monitoring frameworks.
β’ Must possess an active Top Secret clearance, validated by a Tier 5 background investigation.
β’ Bachelorβs degree in Cybersecurity, Information Assurance, Information Technology, Public Policy with an IT emphasis, or a related discipline.
β’ At least 7 years of experience in cybersecurity, access control management, Zero Trust operations, or enterprise security policy design.
β’ Proven experience in developing or maintaining enterprise access policies across identity, network, or application domains.
β’ Skilled in translating risk indicators, threat intelligence, and mission requirements into enforcement rules.
β’ Familiarity with Zero Trust principles or implementing access controls within federal or DoD environments.
β’ Experience collaborating with IAM, network, cybersecurity, and cloud engineering teams on policy integration.
β’ Strong comprehension of Zero Trust access principles, least-privilege enforcement, and conditional access.
β’ Knowledgeable about identity-based policies, device posture evaluation, and segmentation logic.
β’ Acquainted with policy enforcement points in cloud, network, and application environments.
β’ Understanding of DoD cybersecurity mandates and Zero Trust implementation guidelines.
β’ Security+ certification is required.
β’ Preferred experience with identity governance tools, policy engines, or attribute-based access control (ABAC).
β’ Preferred familiarity with Zero Trust network access (ZTNA), microsegmentation tools, or automation frameworks.
β’ Preferred experience with behavioral analytics or identity risk scoring tools.
β’ Strong analytical abilities for the development and refinement of detailed access policies.
β’ Excellent communication skills for effective collaboration across both technical and non-technical teams.
β’ Capability to evaluate risk, interpret threat intelligence, and translate findings into actionable controls.
β’ High attention to detail for maintaining precise, auditable policy structures.
β’ Ability to balance security, usability, and mission-critical operational requirements.
β’ Proficient documentation skills for creating policy artifacts, standards, and playbooks.
β’ Regular full-time employment.
β’ Equal employment opportunity and affirmative action protections.
β’ Consideration for other available positions that require similar skills, education, and experience.
Fortinet
Fortinet
Fortinet
Get handpicked remote jobs straight to your inbox weekly.