1

Zero Trust Engineer Jobs in Virginia (NOW HIRING)

As Sr. Zero Trust Engineer III , you'll help design and implement identity-centric security for complex cloud and hybrid environments. You will use Microsoft Azure security technologies, automation ...

New

Sr. Zero Trust Engineer III (6794)

Arlington, VA · On-site

$150K - $190K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

As Sr. Zero Trust Engineer III , you'll help design and implement identity-centric security for complex cloud and hybrid environments. You will use Microsoft Azure security technologies, automation ...

New

Zero Trust Analyst

Arlington, VA · On-site

$110K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Coordinate with engineering, cloud, identity, and compliance teams to map controls and architecture to Zero Trust objectives.Develop briefing materials, assessment findings, and implementation ...

Zero Trust Analyst

Arlington, VA · Hybrid

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Coordinate with engineering, cloud, identity, and compliance teams to map controls and architecture to Zero Trust objectives. * Develop briefing materials, assessment findings, and implementation ...

Zero Trust Architect

Mclean, VA

$77K - $176K/yr

  • Medical

  • Life

  • Retirement

  • PTO

What if you could use your cyber engineering skills to design and build secure systems for the U.S. Government? We're looking for a Cybersecurity Engineer with Zero Trust (ZT) experience who can ...

Zero Trust Architect

Mclean, VA · On-site

$77K - $176K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Zero Trust Architect The Opportunity: Everyone knows security needs to be "baked in" to system ... Government? We're looking for a Cybersecurity Engineer with Zero T rus t (ZT) experience who can ...

Zero Trust Architect

Mclean, VA · On-site +1

$77K - $176K/yr

  • Medical

  • Life

  • Retirement

  • PTO

What if you could use your cyber engineering skills to design and build secure systems for the U.S. Government? We're looking for a Cybersecurity Engineer with Zero Trust (ZT) experience who can ...

next page

Showing results 1-20

Zero Trust Engineer information

See Virginia salary details

$28.7K

$125.9K

$280.1K

How much do zero trust engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for zero trust engineer in Virginia is $125,875.00, according to ZipRecruiter salary data. Most workers in this role earn between $61,755.00 and $156,091.00 per year, depending on experience, location, and employer.

What is a Zero Trust engineer?

A Zero Trust Engineer is a cybersecurity professional who designs, implements, and manages security frameworks based on the Zero Trust model. Unlike traditional security approaches that trust users or devices inside a network by default, Zero Trust requires continuous verification of every user, device, and application, regardless of location. Zero Trust Engineers work to minimize security risks by ensuring that access is granted based on strict identity verification and least-privilege principles. Their responsibilities often include deploying multi-factor authentication, network segmentation, and monitoring for suspicious activity. This role is critical as organizations increasingly move to cloud environments and remote work setups.

What are the key skills and qualifications needed to thrive as a Zero Trust engineer?

To thrive as a Zero Trust Engineer, you need deep knowledge of cybersecurity principles, network segmentation, identity and access management, and typically a degree in computer science or a related field. Familiarity with tools like Zscaler, Okta, Palo Alto Networks, and relevant certifications such as CISSP or Zero Trust Architect are highly valuable. Strong analytical thinking, problem-solving abilities, and effective communication set outstanding candidates apart in this role. These skills ensure secure, scalable implementation of Zero Trust architectures, protecting organizations from evolving cyber threats.

What are some typical challenges a Zero Trust engineer faces when implementing security frameworks in established organizations?

A Zero Trust Engineer often encounters challenges such as integrating Zero Trust principles into legacy systems that were not designed with this architecture in mind. Balancing security requirements with end-user experience can also be difficult, as stricter controls may initially disrupt established workflows. Additionally, gaining buy-in from various stakeholders and coordinating with IT, network, and application teams to achieve a unified security posture requires strong communication and project management skills. Overcoming these obstacles is critical to successfully transitioning to a Zero Trust model.

What is the difference between Zero Trust Engineer vs Security Engineer?

AspectZero Trust EngineerSecurity Engineer
CertificationsCCSP, CISSP, CompTIA Security+CISSP, CEH, Security+
Work EnvironmentFocus on implementing Zero Trust architecture, network segmentation, identity verificationBroader security measures, incident response, vulnerability management
Industry UsagePrimarily in organizations adopting Zero Trust modelsWidespread across various industries for overall security

Zero Trust Engineers specialize in designing and implementing Zero Trust security frameworks, emphasizing strict identity verification and minimal trust assumptions. Security Engineers have a broader role, covering various security practices beyond Zero Trust. While both roles require similar certifications and work in security-focused environments, Zero Trust Engineers focus specifically on Zero Trust architecture, whereas Security Engineers handle a wider range of security concerns.

What job categories do people searching Zero Trust Engineer jobs in Virginia look for?

The top searched job categories for Zero Trust Engineer jobs in Virginia are:

Infographic showing various Zero Trust Engineer job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, and 5% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $125,875 per year, or $60.5 per hour.

Sr. Zero Trust Engineer III (6794)

MetroStar

Arlington, VA • Hybrid

$150K - $190K/yr

Full-time

Posted 3 days ago

New


Job description

As Sr. Zero Trust Engineer III, you'll help design and implement identity-centric security for complex cloud and hybrid environments. You will use Microsoft Azure security technologies, automation, and recognized Zero Trust frameworks to reduce risk, strengthen access controls, and improve continuous monitoring across the enterprise.

We know that you can't have great technology services without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers.

If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below!

What you'll do:

  • Zero Trust Architecture: Design, implement, and maintain Zero Trust security architectures that align with NIST SP 800-207, CISA Zero Trust guidance, and applicable organizational cybersecurity requirements across cloud, hybrid, and on-premises environments.
  • Identity & Access Management (IAM): Implement and manage identity-centric security controls using Microsoft Entra ID (Azure Active Directory), Role-Based Access Control (RBAC), Conditional Access, Privileged Identity Management (PIM), Multi-Factor Authentication (MFA), and identity governance solutions.
  • Cloud Security Engineering: Design and implement security controls for Azure environments using Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Key Vault, Network Security Groups (NSGs), Azure Firewall, and Private Endpoints to protect critical enterprise workloads.
  • Microsegmentation & Network Security: Develop and enforce network segmentation strategies using Zero Trust principles to reduce attack surfaces and secure communication between users, devices, applications, and services across enterprise environments.
  • Security Automation & Compliance: Develop automation using PowerShell, Python, Azure CLI, Terraform, or Bicep to deploy security controls, enforce policy compliance, automate remediation activities, and improve operational efficiency.
  • Continuous Monitoring & Threat Detection: Configure and optimize Microsoft Sentinel, Microsoft Defender XDR, Azure Monitor, and Log Analytics to provide continuous monitoring, threat detection, incident response, and security reporting.
  • Security Assessments & Risk Management: Conduct Zero Trust maturity assessments, architecture reviews, and security gap analyses while developing remediation strategies that improve security posture and support compliance objectives.
  • DevSecOps Integration: Collaborate with DevSecOps teams to integrate Zero Trust security controls into CI/CD pipelines, Infrastructure as Code (IaC), and cloud-native application development processes.
  • Stakeholder Collaboration: Partner with client stakeholders, cloud architects, cybersecurity teams, system engineers, and program leadership to develop Zero Trust implementation roadmaps, provide technical guidance, and ensure security solutions align with organizational objectives.

What you'll need to succeed:

  • Active Top Secret security clearance.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical discipline.
  • 10+ years of experience in cybersecurity, cloud security engineering, systems engineering, or enterprise security architecture.
  • 5+ years of experience designing, implementing, and supporting Zero Trust architectures within Microsoft Azure and hybrid cloud environments.
  • Strong knowledge of Zero Trust principles and frameworks, including NIST SP 800-207, CISA Zero Trust Maturity Model and other recognized Zero Trust guidance.
  • Experience implementing Microsoft security technologies, including Microsoft Entra ID (Azure Active Directory), Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Microsoft Intune, Conditional Access, Privileged Identity Management (PIM), and Azure Key Vault.
  • Hands-on experience with Infrastructure as Code (Terraform, ARM Templates, or Bicep), cloud automation, and CI/CD platforms such as GitLab, GitHub, Jenkins, or Azure DevOps.
  • Proficiency with PowerShell, Python, Azure CLI, or other scripting languages used for security automation and cloud administration.
  • Strong understanding of Azure networking, identity management, encryption, PKI, network segmentation, secure access, and cloud-native security services.
  • Experience supporting large enterprise, public sector, or regulated environments and implementing security controls aligned with NIST RMF, FedRAMP, applicable security baselines, and security authorization requirements.
  • Excellent analytical, communication, and stakeholder engagement skills with the ability to present technical recommendations to engineering teams, cybersecurity leadership, and client stakeholders.

SALARY RANGE: $150,000.00 - $190,000.00

The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including: 

  • The candidate's professional background and relevant work experience
  • The specific responsibilities of the role and organizational needs
  • Internal equity and alignment with current team compensation
  • This role is also eligible for additional compensation, subject to the terms and policies of MetroStar, which may include:
    • Performance-based bonuses
    • Company-paid training and/or certifications
    • Referral bonuses