1

Zero Trust Engineer Jobs (NOW HIRING)

$112K - $257K/yr

Zero Trust Engineer The Opportunity: Do you enjoy the thrill of the hunt? Are you motivated by the head-to-head challenge of gaining access to well-protected networks? As a network exploitation ...

Zero Trust Architecture Team Lead

Arlington, VA · On-site +1

$63.50 - $87.25/hr

Cyber Engineer Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance ... The Zero Trust Architecture Team Lead is a critical SME role in the gap analysis, roadmap, and ...

Zero Trust Architecture Team Lead

Arlington, VA · On-site +1

$63.75 - $87.25/hr

Cyber Engineer Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance ... The Zero Trust Architecture Team Lead is a critical SME role in the gap analysis, roadmap, and ...

Zero Trust Architecture Team Lead

Arlington, VA · On-site

$63.50 - $87.25/hr

Utilize engineering principles and maturity models, translating findings into prioritized, architecture-driven recommendations. * Develop and evolve the Zero Trust roadmap with a focus on capability ...

Zero trust Security Engineering Work Location: 1-2 days in Culpeper VA Work Model: Hybrid Duration: 1 year contract Skills -Zero trust, CASB , SASE, CASB, ZTNA, SWG Responsibilities: • Design ...

next page

Showing results 1-20

Zero Trust Engineer information

See salary details

$29.5K

$129.4K

$288K

How much do zero trust engineer jobs pay per year?

As of Jun 21, 2026, the average yearly pay for zero trust engineer in the United States is $129,430.00, according to ZipRecruiter salary data. Most workers in this role earn between $63,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Zero Trust Engineer, and why are they important?

To thrive as a Zero Trust Engineer, you need deep knowledge of cybersecurity principles, network segmentation, identity and access management, and typically a degree in computer science or a related field. Familiarity with tools like Zscaler, Okta, Palo Alto Networks, and relevant certifications such as CISSP or Zero Trust Architect are highly valuable. Strong analytical thinking, problem-solving abilities, and effective communication set outstanding candidates apart in this role. These skills ensure secure, scalable implementation of Zero Trust architectures, protecting organizations from evolving cyber threats.

What engineers make $500,000?

Senior cybersecurity engineers, including Zero Trust Engineers with extensive experience, specialized skills, and relevant certifications, can earn $500,000 or more annually, especially in high-demand industries or senior leadership roles. Compensation often depends on factors like location, company size, and individual expertise in security architecture and cloud environments.

What is the difference between Zero Trust Engineer vs Security Engineer?

AspectZero Trust EngineerSecurity Engineer
CertificationsCCSP, CISSP, CompTIA Security+CISSP, CEH, Security+
Work EnvironmentFocus on implementing Zero Trust architecture, network segmentation, identity verificationBroader security measures, incident response, vulnerability management
Industry UsagePrimarily in organizations adopting Zero Trust modelsWidespread across various industries for overall security

Zero Trust Engineers specialize in designing and implementing Zero Trust security frameworks, emphasizing strict identity verification and minimal trust assumptions. Security Engineers have a broader role, covering various security practices beyond Zero Trust. While both roles require similar certifications and work in security-focused environments, Zero Trust Engineers focus specifically on Zero Trust architecture, whereas Security Engineers handle a wider range of security concerns.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically considered an entry-level position in cybersecurity, often requiring foundational knowledge of security tools, network protocols, and incident response. However, some SOC roles may require prior experience or certifications like CompTIA Security+ or CISSP, depending on the complexity of the environment.

What is a Zero Trust Engineer?

A Zero Trust Engineer is a cybersecurity professional who designs, implements, and manages security frameworks based on the Zero Trust model. Unlike traditional security approaches that trust users or devices inside a network by default, Zero Trust requires continuous verification of every user, device, and application, regardless of location. Zero Trust Engineers work to minimize security risks by ensuring that access is granted based on strict identity verification and least-privilege principles. Their responsibilities often include deploying multi-factor authentication, network segmentation, and monitoring for suspicious activity. This role is critical as organizations increasingly move to cloud environments and remote work setups.

What job makes $10,000 a month without a degree?

A Zero Trust Engineer can potentially earn $10,000 or more per month by specializing in cybersecurity, network security, and implementing zero trust architectures. Success in this role depends on skills, certifications, and experience, rather than formal degrees, and often involves working in high-demand environments with advanced technical knowledge. However, reaching this income level typically requires significant expertise and industry recognition.

What are some typical challenges a Zero Trust Engineer faces when implementing security frameworks in established organizations?

A Zero Trust Engineer often encounters challenges such as integrating Zero Trust principles into legacy systems that were not designed with this architecture in mind. Balancing security requirements with end-user experience can also be difficult, as stricter controls may initially disrupt established workflows. Additionally, gaining buy-in from various stakeholders and coordinating with IT, network, and application teams to achieve a unified security posture requires strong communication and project management skills. Overcoming these obstacles is critical to successfully transitioning to a Zero Trust model.

Can you make $500,000 a year in cyber security?

Zero Trust Engineers with extensive experience, advanced certifications, and specialized skills in security architecture can potentially earn salaries approaching or exceeding $500,000 annually, especially in high-demand markets or senior leadership roles. Achieving this level often requires a combination of technical expertise, strategic responsibilities, and leadership positions within organizations. Most cybersecurity professionals earn less, but top-tier specialists and executives can reach high compensation levels.
More about Zero Trust Engineer jobs
What states have the most Zero Trust Engineer jobs? States with the most job openings for Zero Trust Engineer jobs include:
What job categories do people searching Zero Trust Engineer jobs look for? The top searched job categories for Zero Trust Engineer jobs are:
Infographic showing various Zero Trust Engineer job openings in the United States as of June 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $129,430 per year, or $62.2 per hour.
Senior Zero Trust Engineer with Security Clearance

Senior Zero Trust Engineer with Security Clearance

ECS

Falls Church, VA • On-site

$122K - $167K/yr

Other

Posted 17 days ago


Job description

Job Description Everforth ECS is seeking a Senior Zero Trust Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon contract award. The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP focuses on operational warfighting data and aims to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts. • The Senior Zero Trust Engineer serves as the technical authority for Zero Trust Architecture (ZTA) design and implementation across the WDP enterprise, leading the enforcement of identity-centric access controls, network micro-segmentation, and continuous verification capabilities across NIPRNet, SIPRNet, and JWICS environments in alignment with the DoW Zero Trust Strategy and Reference Architecture. In this role, the engineer drives measurable reductions in attack surface and lateral movement risk while embedding Zero Trust principles across DevSecOps pipelines, cloud-native platforms, and multi-enclave mission systems.
• Designs and leads implementation of enterprise Zero Trust security architectures supporting Department of War mission systems across unclassified and classified networks.
• Defines identity-centric access models integrating Active Directory, ICAM services, privileged access management platforms, certificate-based authentication, and continuous authorization workflows.
• Architects network micro-segmentation strategies using next-generation firewalls, software-defined perimeter technologies, Kubernetes network policies, and cloud-native security controls to eliminate implicit trust and restrict lateral movement.
• Directs encryption-in-transit and encrypted traffic inspection capabilities using secure gateways, TLS inspection, and data protection tooling to safeguard mission data flows.
• Guides integration of Zero Trust controls into DevSecOps pipelines, infrastructure platforms, and mission applications in coordination with cybersecurity engineering, system operations, and application teams.
• Oversees Zero Trust capability alignment with the DoW Zero Trust Strategy, DoW Zero Trust Reference Architecture, and NIST SP 800-207, ensuring all seven pillars of Zero Trust are addressed across User/ICAM, Device/Endpoint, and Visibility/Analytics domains.
• Produces authoritative architecture diagrams, technical standards, implementation roadmaps, and executive briefings stored within controlled repositories such as SharePoint.
• Supports audit, assessment, and authorization activities through defensible technical evidence and traceability.
• Delivers measurable improvements in access enforcement, attack surface reduction, and cyber resilience while advancing program values of mission assurance, defense-in-depth, and operational superiority.
• Performs other duties as assigned. Required Skills • Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance. • 10 or more years of progressive experience in cybersecurity engineering, with demonstrated specialization in Zero Trust Architecture design and implementation across enterprise-scale federal or defense programs.
• Active DoW/DoD IAM Level I baseline certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Demonstrated experience designing and implementing Zero Trust capabilities aligned to the DoW Zero Trust Reference Architecture (v2), the DoW Zero Trust Strategy, and NIST SP 800-207, including coverage across all seven Zero Trust pillars.
• Hands-on experience implementing Identity, Credential, and Access Management (ICAM) solutions, including Attribute-Based Access Control (ABAC), Role-Based Access Control (RBAC), Privileged Access Management (PAM), multi-factor authentication (MFA), PKI, and Identity Provider (IdP) federation.
• Demonstrated experience architecting network micro-segmentation strategies, including Software-Defined Networking (SDN), Kubernetes network policies, and next-generation firewall configurations to reduce lateral movement risk across multi-enclave environments.
• Experience integrating Zero Trust controls into DevSecOps delivery pipelines, cloud-native infrastructure platforms, and containerized application environments operating across NIPRNet, SIPRNet, and JWICS.
• Familiarity with Risk Management Framework (RMF) authorization activities, including the development of cybersecurity artifacts, security control assessments, and authorization package support in compliance with NIST SP 800-53.
• Experience producing and maintaining technical architecture documentation, Zero Trust implementation roadmaps, and executive-level briefings stored in program-controlled repositories.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management). Desired Skills • Active Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI) eligibility. • Active Certified Information Systems Security Professional (CISSP) certification, consistent with DoW key personnel cybersecurity qualification standards.
• Advanced DoW/DoD IAM certification at Level II or Level III (e.g., CASP+ CE, CISSP, CISA, or equivalent), demonstrating expanded qualifications beyond the baseline IAM Level I requirement.
• Experience supporting Zero Trust implementation across parallel Unclassified, Secret, and Top Secret enclaves simultaneously, including management of air-gapped architectures, enclave-specific compliance reporting, and cross-domain data transfer controls.
• Background supporting Continuous Monitoring (ConMon), Security Information and Event Management (SIEM), Extended Detection and Response (XDR), or User and Entity Behavior Analytics (UEBA) platforms as components of an integrated Zero Trust visibility and analytics capability. ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value: * Attracting and developing top talent and high-performing teams * Fostering a culture that is engaging, accountable, and mission-driven Meet the challenge. Make a difference with Everforth ECS!