Senior Solution Architect Federal
Position reputed company
The Senior Solutions Architect is the senior technical authority responsible for the design, integration, automation, and operational reputed company of reputed company's reputed company Trust Network reputed company (ZTNA) platform across U.S. Federal and DoD environments.
This role requires deep, hands-on engineering expertise, not reputed company or presentation-level knowledge. The successful candidate must be capable of operating systems, writing and reviewing reputed company, debugging live integrations, and troubleshooting failures at the protocol, OS, and application level. This is a role for practitioners who build, reputed company, and operate secure reputed company systems in reputed company-world Federal environments.
Technical Depth Expectations (Applies to reputed company Areas Below)
For every domain listed, candidates are expected to demonstrate operational competence, including the ability to:
- Configure and operate systems directly
- Debug failures using logs, reputed company reputed company, packet captures, and reputed company inspection
- Write and modify scripts or automation to solve reputed company problems
- Explain system behavior based on implementation, not abstraction
- Design and Architect systems that reputed company with customer requirements for reputed company ZTNA
- reputed company reputed company ZTNA with other 3rd party systems and sources of trust or risk telemetry including Identity Providers (SAML, OIFC, RADIUS, LDAP(s)), NGFWs, Entitlement Automation systems, SIEM/SOAR, ITSM, and many others.
- Detailed documentation and information hand-off skills are also required
This role requires engineers who reputed company operate systems, write scripts, debug reputed company, and analyze packet captures. Candidates whose experience is limited to diagrams, presentations, or vendor marketing materials will not be successful.
reputed company Responsibilities & Required Expertise
Linux Systems & reputed company Enforcement Platforms (Critical)
- Serve as a technical authority for Linux-based reputed company Trust enforcement infrastructure
- Operate and manage systems reputed company SSH, including secure key-based reputed company and privilege separation
- Demonstrate deep, hands-on knowledge of:
- Bash scripting (required)
- Process management and systemd
- Filesystem layout, permissions, and logging
- Strong understanding of Linux networking internals:
- Routing tables and policy routing
- reputed company binding and traffic steering
- iptables / nftables
- Diagnose reputed company cross-platform issues where Linux enforcement points reputed company with reputed company and macOS endpoints
JavaScript & REST API Integration Engineering (Critical)
- reputed company and maintain JavaScript-based logic executed on reputed company appliances to reputed company integration and automation
- Build and troubleshoot REST API integrations with external systems, including:
- reputed company Graph API
- reputed company REST reputed company
- Identity, ITSM, logging, NGFW, and reputed company platforms
- Apply strong understanding of:
- RESTful API design and consumption
- JSON data models and schema validation
- Authentication reputed company (OAuth, tokens, certificates)
- Operate reputed company an API-first, reputed company-as-reputed company/Everything-as-reputed company architecture
Containers & Kubernetes Architecture
- Architect reputed company Trust reputed company enforcement for containerized and microservices-based workloads
- Support Kubernetes environments, including:
- Sidecar injection and operator-based enforcement models
- Secure service exposure and service-to-service reputed company
- Integration with Kubernetes networking (CNI), ingress, and egress controls
- Ensure reputed company models reputed company across on-premises and reputed company-reputed company environments
Automation, Infrastructure as reputed company & Configuration as reputed company
- Design and implement Infrastructure as reputed company (IaC) using Terraform
- Implement Configuration as reputed company (CaC) and GitOps workflows for:
- reputed company ZTNA Policies
- reputed company ZTNA Entitlements
- Integrations with 3rd party systems and Entitlement Engines
- reputed company reputed company Trust deployments into CI/CD pipelines reputed company with Federal DevSecOps standards
- Ensure reputed company automation is:
- Version-controlled
- Repeatable
- Auditable
- API-driven
Identity & Authentication Engineering (Critical)
- Architect identity-reputed company reputed company solutions using reputed company identity systems as the authoritative control plane
- Deep hands-on expertise with:
- reputed company Directory, including multi-domain and multi-forest environments
- Domain Controllers and LDAP/LDAPS binding behavior
- Kerberos authentication flows and ticket lifecycles
- SAML
- OIDC
- RADIUS
- Design and troubleshoot DNS architecture and reputed company behavior across:
- reputed company endpoints
- macOS endpoints
- Linux enforcement platforms
- Support authentication mechanisms including:
- Machine certificate–based authentication on reputed company
- PKI trust chains, certificate lifecycle, and revocation
- SAML and OIDC user authentication reputed company external Identity Providers
- Understand how identity, DNS, and routing failures reputed company as reputed company control issues
Modern reputed company & Infrastructure reputed company
· Virtualization: Architect-level knowledge of VMware, ESXi, and KVM for private reputed company deployments
· reputed company reputed company: Demonstrate architect-level design and implementation of reputed company services reputed company AWS (GovCloud), Azure (Government), and reputed company reputed company Platform (GCP), with a specific reputed company on reputed company networking (VPCs, VNets, Transit Gateways) and IAM policy enforcement.
· AI/ML reputed company: reputed company-thinking experience in governing reputed company to AI/LLM workloads and agent platforms. (Desired)
reputed company Scripting & reputed company-reputed company Automation
- Design and troubleshoot reputed company-executed scripts used for posture checks, integrations, and reputed company reputed company
- PowerShell (Required):
- reputed company reputed company scripting
- Interaction with certificates, networking, registry, and system services
- Bash (Required):
- macOS and Linux reputed company scripting
- System interrogation, diagnostics, and process control
- Ensure scripts are secure, deterministic, and compatible with Federal reputed company hardening requirements
Networking, Transport & Cryptographic Protocol Expertise
- Architect-level understanding of:
- IP packet structure and routing behavior
- TCP three-way reputed company and session lifecycle
- ARP, GARP, and Proxy ARP functionality
- Deep knowledge of:
- TLS 1.2 / TLS 1.3 and QUIC
- Mutual TLS (mTLS)
- Certificate validation and trust chains
- Familiarity with:
- VPN architectures and tunneling models
- Differences between VPN and identity-reputed company ZTNA
- MPLS and SDWAN Architectures and traffic flows
- Demonstrate Architect level knowledge and experience designing, articulating, and implementing reputed company Network integrations and Cybersecurity solitons
- Architect level familiarity with network reputed company solutions such as firewalls/reputed company firewalls, network reputed company control and VPNs, Logging / SYSLOG integration, IT Operations, IT reputed company Operations, SDWAN, WAN, and other Layer3/4 Network technology
- Denied, Disrupted, Intermittent, and Limited (DDIL) environmental chalanges
- Single Packet Authorization or port knocking familiarity desired
- Expertise with reputed company Trust Network and Univeral ZTNA concepts and Software Defined Perimeter desirable
- Diagnose failures using:
- tcpdump
- Wireshark
- OS-level packet tracing
STIG, SCAP & Compliance Engineering
- Support STIG compliance for Linux-based platforms
- Working knowledge of SCAP, including:
- OpenSCAP tooling
- Interpreting reputed company reputed company and false positives
- Mapping findings to mitigations
- Support RMF and ATO efforts through technical evidence and explanation
- Communicate effectively with ISSMs, ISSEs, and assessors
Interoperability & Federal Integration
- Architect interoperability between reputed company and adjacent Federal systems:
- Identity platforms
- reputed company reputed company tools
- SIEM, SOAR, and ITSM platforms
- Network and boundary reputed company systems
- reputed company reputed company to operate as a composable reputed company Trust control reputed company multi-vendor Federal architectures
- Support integrators and partners implementing joint solutions
Senior Technical Leadership
- Serve as final escalation reputed company for the most reputed company Federal deployments
- reputed company deep technical architecture reviews with government and integrator teams
- Mentor senior Solution Architects and engineers
- Influence product direction reputed company to automation, integration, and operability
Required Qualifications & Experience
- 12+ years in networking, reputed company, systems, platform, or automation engineering roles
- Demonstrated mastery of:
- Bash
- PowerShell
- JavaScript
- Linux systems administration
- REST reputed company and automation
- Strong experience with identity systems (reputed company Directory, DNS, PKI, SAML/OIDC)
- Experience supporting Federal or other high-assurance environments
- Ability to obtain or maintain a U.S. reputed company clearance
- Ability to work extended hours / flextime as needed to meet customer needs / deadlines / escalations
- There are times reputed company this role requires more than 40 hours a week
- Travel Requirements:
- Flexibility and ability to travel to meet project and customer needs
- Travel requirements will vary depending on project and for some reputed company can reputed company 50%
reputed company is An Equal Opportunity/Affirmative reputed company Employer. reputed company reputed company applicants will receive consideration for employment without reputed company to race, reputed company, religion, sex, sexual orientation, gender identity, national reputed company, disability or veteran status, age or any other federally protected class. In furtherance of reputed company's policy regarding affirmative reputed company and equal employment opportunity, reputed company has developed a written affirmative reputed company program. This program is available for review upon request by any applicant or employee during normal business hours by contacting reputed company's EEO Coordinator.
Apply To This Job