Job DescriptionJob Description ABOUT LVT LVT is redefining how businesses operate in the physical world, moving beyond traditional security solutions to deliver AI-driven, actionable intelligence that makes sites smarter, safer, and more secure. Since pioneering our first mobile, solar-powered units, our commitment to scrappy, hands-on innovation has made us an established leader and one of the fastest-growing companies in intelligent site technology. We are building the next generation of solutions-from our physical units in the field to a powerful Agentic AI platform-that allows our customers to gain unprecedented visibility and control over safety, compliance, and operations. This is your chance to join a cutting-edge team that isn't just watching the world change, but actively building the technology that is changing it. We're a team that's focused on growth and innovation, and we're proud that our crew, products, and leadership are being recognized for it. A Top-Tier Growth Company: Named one of the Financial Times' Fastest Growing Companies 2025 and on the Inc. 5000 Rocky Mountain Regional list for 2025. Innovative Leadership: Our CEO, Ryan Porter, was named an EY Entrepreneur of the Year 2025, and our CTO, Steve Lindsey, was inducted into the Silicon Slopes CTO Hall of Fame in 2024. Product & Software Excellence: We were named one of The Software Report's Top 100 Software Companies of 2023 and are a winner of the Security Today Govies Award for 2025. ABOUT THIS ROLE As the Manager of IT Infrastructure, you will lead the engineering crew responsible for the backbone of LVT's internal operations. You will champion the scaling, reliability, and security of our corporate networks, identity management systems, and enterprise SaaS portfolio. Balancing strategic vision with technical mentorship, you will foster a culture of automation and engineering excellence to ensure our infrastructure scales ahead of our rapid business growth. This role is based 100% in-office out of our Headquarters in American Fork, Utah. ROLE RESPONSIBILITIES Team Leadership: Lead, mentor, and grow a high-performing team of IT engineers across network, identity, SaaS, and end-user systems, directly owning hiring, onboarding, and performance management. Operational Excellence: Establish a strong engineering culture rooted in ownership, robust documentation, and automation, while managing the team's agile operating cadence (planning, prioritization, and on-call escalation). Strategic Roadmap: Define and execute the corporate IT infrastructure roadmap in close alignment with Security, Engineering, and Business Operations to proactively support headcount and footprint growth. Metrics & Governance: Define, track, and report on enterprise SLAs and KPIs-including uptime, MTTR, incident response, and provisioning accuracy-to executive leadership. Financial & Vendor Ownership: Manage the IT infrastructure capex/opex budget, lead vendor contract negotiations, and continuously rationalize the enterprise SaaS portfolio for maximum licensing efficiency. Network & Connectivity Architecture: Oversee the technical direction and lifecycle management of LVT's corporate networks (LAN, Wi-Fi, WAN/SD-WAN, and Zero-Trust Network Access) across HQ and remote sites. Identity & Access Strategy: Drive LVT's Identity and Access Management (IAM) program, enforcing least-privilege models, RBAC, and automated joiner/mover/leaver workflows. Compliance & Risk Mitigation: Serve as the primary control owner for IT infrastructure supporting SOC 2 compliance, ensuring audit readiness, change management rigor, and prompt vulnerability remediation. OUR IDEAL CANDIDATE Proven Leadership: 8+ years of progressive IT infrastructure experience, with at least 2 years of direct people management experience developing mid-to-senior level engineers. Scaling Experience: Proven track record of scaling IT infrastructure and teams within high-growth corporate environments. Technical Fluency: Deep technical competency across modern enterprise networking (firewalls, switching, Wi-Fi, VPN/ZTNA, SD-WAN) to confidently evaluate architecture designs and manage risk. IAM Expertise: Robust operational knowledge of modern identity platforms (e.g., Okta, Microsoft Entra ID) including conditional access, SSO, MFA, and SCIM provisioning. SaaS Portfolio Governance: Strong experience managing, integrating, and securing a comprehensive enterprise SaaS and tooling ecosystem (productivity suites, ITSM, MDM). Compliance Mindset: Practical experience acting as a control owner for formal security frameworks (such as SOC 2), including evidence collection and audit defense. Strategic Communication: Exceptional communication and stakeholder management skills, with the ability to translate complex technical trade-offs into business impact for executive audiences. Preferred Qualifications: Relevant industry certifications (e.g., CISSP, CISM, Okta Certified Administrator, CCNP) and familiarity with cloud platform infrastructure (AWS, Azure, or GCP) are highly desirable BENEFITS We believe you do your best work when your whole life is supported. We invest in our crew's health, families, and financial futures with a benefits package designed to support you inside and outside the office. Full-time benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO. LVT IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. All candidates must pass a drug screening and background check upon employment. Some roles may also require passing a federal background check and fingerprinting. Must be authorized to work in the U.S. If reasonable accommodation is needed to participate in the job application or interview process, and/or to perform essential job functions, please reach out to your recruiter.
09/22/2026
Full time
Job DescriptionJob Description ABOUT LVT LVT is redefining how businesses operate in the physical world, moving beyond traditional security solutions to deliver AI-driven, actionable intelligence that makes sites smarter, safer, and more secure. Since pioneering our first mobile, solar-powered units, our commitment to scrappy, hands-on innovation has made us an established leader and one of the fastest-growing companies in intelligent site technology. We are building the next generation of solutions-from our physical units in the field to a powerful Agentic AI platform-that allows our customers to gain unprecedented visibility and control over safety, compliance, and operations. This is your chance to join a cutting-edge team that isn't just watching the world change, but actively building the technology that is changing it. We're a team that's focused on growth and innovation, and we're proud that our crew, products, and leadership are being recognized for it. A Top-Tier Growth Company: Named one of the Financial Times' Fastest Growing Companies 2025 and on the Inc. 5000 Rocky Mountain Regional list for 2025. Innovative Leadership: Our CEO, Ryan Porter, was named an EY Entrepreneur of the Year 2025, and our CTO, Steve Lindsey, was inducted into the Silicon Slopes CTO Hall of Fame in 2024. Product & Software Excellence: We were named one of The Software Report's Top 100 Software Companies of 2023 and are a winner of the Security Today Govies Award for 2025. ABOUT THIS ROLE As the Manager of IT Infrastructure, you will lead the engineering crew responsible for the backbone of LVT's internal operations. You will champion the scaling, reliability, and security of our corporate networks, identity management systems, and enterprise SaaS portfolio. Balancing strategic vision with technical mentorship, you will foster a culture of automation and engineering excellence to ensure our infrastructure scales ahead of our rapid business growth. This role is based 100% in-office out of our Headquarters in American Fork, Utah. ROLE RESPONSIBILITIES Team Leadership: Lead, mentor, and grow a high-performing team of IT engineers across network, identity, SaaS, and end-user systems, directly owning hiring, onboarding, and performance management. Operational Excellence: Establish a strong engineering culture rooted in ownership, robust documentation, and automation, while managing the team's agile operating cadence (planning, prioritization, and on-call escalation). Strategic Roadmap: Define and execute the corporate IT infrastructure roadmap in close alignment with Security, Engineering, and Business Operations to proactively support headcount and footprint growth. Metrics & Governance: Define, track, and report on enterprise SLAs and KPIs-including uptime, MTTR, incident response, and provisioning accuracy-to executive leadership. Financial & Vendor Ownership: Manage the IT infrastructure capex/opex budget, lead vendor contract negotiations, and continuously rationalize the enterprise SaaS portfolio for maximum licensing efficiency. Network & Connectivity Architecture: Oversee the technical direction and lifecycle management of LVT's corporate networks (LAN, Wi-Fi, WAN/SD-WAN, and Zero-Trust Network Access) across HQ and remote sites. Identity & Access Strategy: Drive LVT's Identity and Access Management (IAM) program, enforcing least-privilege models, RBAC, and automated joiner/mover/leaver workflows. Compliance & Risk Mitigation: Serve as the primary control owner for IT infrastructure supporting SOC 2 compliance, ensuring audit readiness, change management rigor, and prompt vulnerability remediation. OUR IDEAL CANDIDATE Proven Leadership: 8+ years of progressive IT infrastructure experience, with at least 2 years of direct people management experience developing mid-to-senior level engineers. Scaling Experience: Proven track record of scaling IT infrastructure and teams within high-growth corporate environments. Technical Fluency: Deep technical competency across modern enterprise networking (firewalls, switching, Wi-Fi, VPN/ZTNA, SD-WAN) to confidently evaluate architecture designs and manage risk. IAM Expertise: Robust operational knowledge of modern identity platforms (e.g., Okta, Microsoft Entra ID) including conditional access, SSO, MFA, and SCIM provisioning. SaaS Portfolio Governance: Strong experience managing, integrating, and securing a comprehensive enterprise SaaS and tooling ecosystem (productivity suites, ITSM, MDM). Compliance Mindset: Practical experience acting as a control owner for formal security frameworks (such as SOC 2), including evidence collection and audit defense. Strategic Communication: Exceptional communication and stakeholder management skills, with the ability to translate complex technical trade-offs into business impact for executive audiences. Preferred Qualifications: Relevant industry certifications (e.g., CISSP, CISM, Okta Certified Administrator, CCNP) and familiarity with cloud platform infrastructure (AWS, Azure, or GCP) are highly desirable BENEFITS We believe you do your best work when your whole life is supported. We invest in our crew's health, families, and financial futures with a benefits package designed to support you inside and outside the office. Full-time benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO. LVT IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. All candidates must pass a drug screening and background check upon employment. Some roles may also require passing a federal background check and fingerprinting. Must be authorized to work in the U.S. If reasonable accommodation is needed to participate in the job application or interview process, and/or to perform essential job functions, please reach out to your recruiter.
Job DescriptionJob Description ABOUT LVT LVT is redefining how businesses operate in the physical world, moving beyond traditional security solutions to deliver AI-driven, actionable intelligence that makes sites smarter, safer, and more secure. Since pioneering our first mobile, solar-powered units, our commitment to scrappy, hands-on innovation has made us an established leader and one of the fastest-growing companies in intelligent site technology. We are building the next generation of solutions-from our physical units in the field to a powerful Agentic AI platform-that allows our customers to gain unprecedented visibility and control over safety, compliance, and operations. This is your chance to join a cutting-edge team that isn't just watching the world change, but actively building the technology that is changing it. We're a team that's focused on growth and innovation, and we're proud that our crew, products, and leadership are being recognized for it. A Top-Tier Growth Company: Named one of the Financial Times' Fastest Growing Companies 2025 and on the Inc. 5000 Rocky Mountain Regional list for 2025. Innovative Leadership: Our CEO, Ryan Porter, was named an EY Entrepreneur of the Year 2025, and our CTO, Steve Lindsey, was inducted into the Silicon Slopes CTO Hall of Fame in 2024. Product & Software Excellence: We were named one of The Software Report's Top 100 Software Companies of 2023 and are a winner of the Security Today Govies Award for 2025. ABOUT THIS ROLE As the Manager of IT Infrastructure, you will lead the engineering crew responsible for the backbone of LVT's internal operations. You will champion the scaling, reliability, and security of our corporate networks, identity management systems, and enterprise SaaS portfolio. Balancing strategic vision with technical mentorship, you will foster a culture of automation and engineering excellence to ensure our infrastructure scales ahead of our rapid business growth. This role is based 100% in-office out of our Headquarters in American Fork, Utah. ROLE RESPONSIBILITIES Team Leadership: Lead, mentor, and grow a high-performing team of IT engineers across network, identity, SaaS, and end-user systems, directly owning hiring, onboarding, and performance management. Operational Excellence: Establish a strong engineering culture rooted in ownership, robust documentation, and automation, while managing the team's agile operating cadence (planning, prioritization, and on-call escalation). Strategic Roadmap: Define and execute the corporate IT infrastructure roadmap in close alignment with Security, Engineering, and Business Operations to proactively support headcount and footprint growth. Metrics & Governance: Define, track, and report on enterprise SLAs and KPIs-including uptime, MTTR, incident response, and provisioning accuracy-to executive leadership. Financial & Vendor Ownership: Manage the IT infrastructure capex/opex budget, lead vendor contract negotiations, and continuously rationalize the enterprise SaaS portfolio for maximum licensing efficiency. Network & Connectivity Architecture: Oversee the technical direction and lifecycle management of LVT's corporate networks (LAN, Wi-Fi, WAN/SD-WAN, and Zero-Trust Network Access) across HQ and remote sites. Identity & Access Strategy: Drive LVT's Identity and Access Management (IAM) program, enforcing least-privilege models, RBAC, and automated joiner/mover/leaver workflows. Compliance & Risk Mitigation: Serve as the primary control owner for IT infrastructure supporting SOC 2 compliance, ensuring audit readiness, change management rigor, and prompt vulnerability remediation. OUR IDEAL CANDIDATE Proven Leadership: 8+ years of progressive IT infrastructure experience, with at least 2 years of direct people management experience developing mid-to-senior level engineers. Scaling Experience: Proven track record of scaling IT infrastructure and teams within high-growth corporate environments. Technical Fluency: Deep technical competency across modern enterprise networking (firewalls, switching, Wi-Fi, VPN/ZTNA, SD-WAN) to confidently evaluate architecture designs and manage risk. IAM Expertise: Robust operational knowledge of modern identity platforms (e.g., Okta, Microsoft Entra ID) including conditional access, SSO, MFA, and SCIM provisioning. SaaS Portfolio Governance: Strong experience managing, integrating, and securing a comprehensive enterprise SaaS and tooling ecosystem (productivity suites, ITSM, MDM). Compliance Mindset: Practical experience acting as a control owner for formal security frameworks (such as SOC 2), including evidence collection and audit defense. Strategic Communication: Exceptional communication and stakeholder management skills, with the ability to translate complex technical trade-offs into business impact for executive audiences. Preferred Qualifications: Relevant industry certifications (e.g., CISSP, CISM, Okta Certified Administrator, CCNP) and familiarity with cloud platform infrastructure (AWS, Azure, or GCP) are highly desirable BENEFITS We believe you do your best work when your whole life is supported. We invest in our crew's health, families, and financial futures with a benefits package designed to support you inside and outside the office. Full-time benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO. LVT IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. All candidates must pass a drug screening and background check upon employment. Some roles may also require passing a federal background check and fingerprinting. Must be authorized to work in the U.S. If reasonable accommodation is needed to participate in the job application or interview process, and/or to perform essential job functions, please reach out to your recruiter.
09/22/2026
Full time
Job DescriptionJob Description ABOUT LVT LVT is redefining how businesses operate in the physical world, moving beyond traditional security solutions to deliver AI-driven, actionable intelligence that makes sites smarter, safer, and more secure. Since pioneering our first mobile, solar-powered units, our commitment to scrappy, hands-on innovation has made us an established leader and one of the fastest-growing companies in intelligent site technology. We are building the next generation of solutions-from our physical units in the field to a powerful Agentic AI platform-that allows our customers to gain unprecedented visibility and control over safety, compliance, and operations. This is your chance to join a cutting-edge team that isn't just watching the world change, but actively building the technology that is changing it. We're a team that's focused on growth and innovation, and we're proud that our crew, products, and leadership are being recognized for it. A Top-Tier Growth Company: Named one of the Financial Times' Fastest Growing Companies 2025 and on the Inc. 5000 Rocky Mountain Regional list for 2025. Innovative Leadership: Our CEO, Ryan Porter, was named an EY Entrepreneur of the Year 2025, and our CTO, Steve Lindsey, was inducted into the Silicon Slopes CTO Hall of Fame in 2024. Product & Software Excellence: We were named one of The Software Report's Top 100 Software Companies of 2023 and are a winner of the Security Today Govies Award for 2025. ABOUT THIS ROLE As the Manager of IT Infrastructure, you will lead the engineering crew responsible for the backbone of LVT's internal operations. You will champion the scaling, reliability, and security of our corporate networks, identity management systems, and enterprise SaaS portfolio. Balancing strategic vision with technical mentorship, you will foster a culture of automation and engineering excellence to ensure our infrastructure scales ahead of our rapid business growth. This role is based 100% in-office out of our Headquarters in American Fork, Utah. ROLE RESPONSIBILITIES Team Leadership: Lead, mentor, and grow a high-performing team of IT engineers across network, identity, SaaS, and end-user systems, directly owning hiring, onboarding, and performance management. Operational Excellence: Establish a strong engineering culture rooted in ownership, robust documentation, and automation, while managing the team's agile operating cadence (planning, prioritization, and on-call escalation). Strategic Roadmap: Define and execute the corporate IT infrastructure roadmap in close alignment with Security, Engineering, and Business Operations to proactively support headcount and footprint growth. Metrics & Governance: Define, track, and report on enterprise SLAs and KPIs-including uptime, MTTR, incident response, and provisioning accuracy-to executive leadership. Financial & Vendor Ownership: Manage the IT infrastructure capex/opex budget, lead vendor contract negotiations, and continuously rationalize the enterprise SaaS portfolio for maximum licensing efficiency. Network & Connectivity Architecture: Oversee the technical direction and lifecycle management of LVT's corporate networks (LAN, Wi-Fi, WAN/SD-WAN, and Zero-Trust Network Access) across HQ and remote sites. Identity & Access Strategy: Drive LVT's Identity and Access Management (IAM) program, enforcing least-privilege models, RBAC, and automated joiner/mover/leaver workflows. Compliance & Risk Mitigation: Serve as the primary control owner for IT infrastructure supporting SOC 2 compliance, ensuring audit readiness, change management rigor, and prompt vulnerability remediation. OUR IDEAL CANDIDATE Proven Leadership: 8+ years of progressive IT infrastructure experience, with at least 2 years of direct people management experience developing mid-to-senior level engineers. Scaling Experience: Proven track record of scaling IT infrastructure and teams within high-growth corporate environments. Technical Fluency: Deep technical competency across modern enterprise networking (firewalls, switching, Wi-Fi, VPN/ZTNA, SD-WAN) to confidently evaluate architecture designs and manage risk. IAM Expertise: Robust operational knowledge of modern identity platforms (e.g., Okta, Microsoft Entra ID) including conditional access, SSO, MFA, and SCIM provisioning. SaaS Portfolio Governance: Strong experience managing, integrating, and securing a comprehensive enterprise SaaS and tooling ecosystem (productivity suites, ITSM, MDM). Compliance Mindset: Practical experience acting as a control owner for formal security frameworks (such as SOC 2), including evidence collection and audit defense. Strategic Communication: Exceptional communication and stakeholder management skills, with the ability to translate complex technical trade-offs into business impact for executive audiences. Preferred Qualifications: Relevant industry certifications (e.g., CISSP, CISM, Okta Certified Administrator, CCNP) and familiarity with cloud platform infrastructure (AWS, Azure, or GCP) are highly desirable BENEFITS We believe you do your best work when your whole life is supported. We invest in our crew's health, families, and financial futures with a benefits package designed to support you inside and outside the office. Full-time benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO. LVT IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. All candidates must pass a drug screening and background check upon employment. Some roles may also require passing a federal background check and fingerprinting. Must be authorized to work in the U.S. If reasonable accommodation is needed to participate in the job application or interview process, and/or to perform essential job functions, please reach out to your recruiter.
Job Description Job Description ZERO TRUST PROJECT LEAD POSITION DESCRIPTION General Description Zermount Inc. is seeking a Zero Trust (ZT) Technical Project Lead with demonstrated experience in providing enterprise support services while leveraging industry-standard service management best practices. We are looking for a team lead that is able to withstand even the most complex environments for our ZT enterprise initiative. The Project Lead will lead, plan, and manage Information Technology (IT) projects as well as provide leadership and guiding technical staff. They will integrate business and technical aspects of projects that are a part of the implementation of ZT principles across all pillars of ZT (identity, device, network, application and workload and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The Project Lead will also assess business implications, monitor progress in meeting deadlines, standards, and customer cost targets. They will establish goals and plans that meet project objectives and have expert technical knowledge. In addition, they will direct and control activities for a client, having overall responsibility for financial management, methods, and staffing to ensure all technical requirements are met. This position also includes client reporting and interfacing with senior management to communicate a program's progress and achievements. Decision-making and domain knowledge may have a critical impact on project implementation. The Project Lead will supervise others. Duties & Responsibilities: The ZT Project Lead will lead the Zermount ZT Team to ensure we are designing and implementing solutions and services that secure federal networks and provide leadership required to meet the objectives of EO 14028 and other Federal requirements. Additionally, the ZT Project Lead will provide support and services to include: Analyze, plan, and develop scheduled project plans. Responsible for program Integrated Master Scheduler (IMS) updates, health, and accuracy. Responsible for quality management and control. Provide SME support and technical guidance to information system stakeholders on the implementation of ZTA requirements and participate in design reviews upon request. Ensure alignment of the ZTA program to organizational strategies and deliver anticipated benefits of ZT as outlined in EO 14028, the CISA ZT Maturity Model, and the NIST SP 800-207. Creating month status reports (progression week 1 through week 4 buildup). Perform risk management to include: (1) managing risk across the ZTA program as the landscape evolves; and (2) integrating ZTA into the existing TSA and DHS Cybersecurity Risk Management framework and CISA's ZT maturity model with the goal of the solution reaching the optimal state of maturity. Draft Program Management Report (PMR). Responsible for streamlining and automating enterprise-level performance reporting for all components within ZT, aligned with existing and planned reporting and analytics structures and tools, such as the Continuous Diagnostics and Mitigation (CDM) dashboards, FISMA reporting, and Information Security Continuous Monitoring (ISCM) dashboards Establishing and implementing training processes for all technical personnel. Assisting the TSA in its ultimate goal of meeting or exceeding the "managed and measurable" IG CIGIE FISMA maturity metrics as amended, for all applicable security functions for ZT. Develop, implement, and maintain enterprise-wide performance metrics and measures for the ZT initiative Determine and define clear deliverables, roles, and responsibilities for all resources. Create performance measures for all resources. Managing, updating and maintaining all ZTA program governance documents including but not limited to the ZTA roadmap; which articulates the programs vision, scope, and direction Responsible for development of all management artifacts (PMP, IMP, CP, RMP, QAP, etc.). Ensure program integration and operational processes and procedures. Establishing and maintaining relationships among all stakeholders. Design Dashboard/Briefings to measure program performance, schedule, etc. Responsible for mapping ZTA capabilities outlined throughout this PWS, existing capabilities within the department, and new capabilities the Contractor recommends be added to the Pillars of Zero Trust (currently 5 Pillars) as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, executive orders, and standards. The Contractor must also map new ZTA capabilities that the Government approves Mentor Team Leads Review and ensure all deliverables are submitted in accordance with the SOW and in a timely manner. Cross task area support as required. Qualifications: A minimum of 10 years of IT cybersecurity management experience including 3 years of direct support for the US Government OR a relevant Bachelor's degree in IT, computer science, business or engineering and 10+ years of IT cybersecurity management experience including 3 years of direct support for the US Government. Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers. Understanding and experience with Agile Principles, processes and methodologies. Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures. Excellent communication, collaboration, and problem-solving skills. Ability to work independently and as part of a team. Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact. Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact. Zero Trust Specific Qualifications: System Maturity Model Expertise in the implementation, strategy, roadmap, and analysis with regard to TSA systems and the TSA Enterprise and meet the requirements outlined in M-21-31, M-22-09, EO 14028, and NIST SP 800-207. Working experience associated with implementing all of the Zero Trust requirements based off of the CISA Zero Trust Maturity Model 2.0 and any upcoming versions. SME level knowledge within at least one of the five Zero Trust Maturity Model pillars as defined by the CISA Maturity Model. Possess a deep understanding and proficiency in the principles, technologies, and best practices associated with the pillars. Provide strategic guidance and expertise in implementing Zero Trust within their assigned pillar, ensuring alignment with industry standards and organizational objectives. Deep understanding of the criteria needed to meet the Federal Governments intended, optimal, maturity level. Ability to develop a Zero Trust Maturity Roadmap to achieve optimal maturity level. Education: Minimum of a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, IT, cyber security, or a related field. Relevant years of experience may be used in substitution for situations where the candidate does not have a Bachelor's degree in the required field. Clearance level: Minimum of an active Secret Clearance. Work Location: Hybrid - Primarily Remote. Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., will be occasionally required. Hours of Operation: Business Hours: 8:00 am EST - 4:30 pm EST.
09/21/2026
Full time
Job Description Job Description ZERO TRUST PROJECT LEAD POSITION DESCRIPTION General Description Zermount Inc. is seeking a Zero Trust (ZT) Technical Project Lead with demonstrated experience in providing enterprise support services while leveraging industry-standard service management best practices. We are looking for a team lead that is able to withstand even the most complex environments for our ZT enterprise initiative. The Project Lead will lead, plan, and manage Information Technology (IT) projects as well as provide leadership and guiding technical staff. They will integrate business and technical aspects of projects that are a part of the implementation of ZT principles across all pillars of ZT (identity, device, network, application and workload and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The Project Lead will also assess business implications, monitor progress in meeting deadlines, standards, and customer cost targets. They will establish goals and plans that meet project objectives and have expert technical knowledge. In addition, they will direct and control activities for a client, having overall responsibility for financial management, methods, and staffing to ensure all technical requirements are met. This position also includes client reporting and interfacing with senior management to communicate a program's progress and achievements. Decision-making and domain knowledge may have a critical impact on project implementation. The Project Lead will supervise others. Duties & Responsibilities: The ZT Project Lead will lead the Zermount ZT Team to ensure we are designing and implementing solutions and services that secure federal networks and provide leadership required to meet the objectives of EO 14028 and other Federal requirements. Additionally, the ZT Project Lead will provide support and services to include: Analyze, plan, and develop scheduled project plans. Responsible for program Integrated Master Scheduler (IMS) updates, health, and accuracy. Responsible for quality management and control. Provide SME support and technical guidance to information system stakeholders on the implementation of ZTA requirements and participate in design reviews upon request. Ensure alignment of the ZTA program to organizational strategies and deliver anticipated benefits of ZT as outlined in EO 14028, the CISA ZT Maturity Model, and the NIST SP 800-207. Creating month status reports (progression week 1 through week 4 buildup). Perform risk management to include: (1) managing risk across the ZTA program as the landscape evolves; and (2) integrating ZTA into the existing TSA and DHS Cybersecurity Risk Management framework and CISA's ZT maturity model with the goal of the solution reaching the optimal state of maturity. Draft Program Management Report (PMR). Responsible for streamlining and automating enterprise-level performance reporting for all components within ZT, aligned with existing and planned reporting and analytics structures and tools, such as the Continuous Diagnostics and Mitigation (CDM) dashboards, FISMA reporting, and Information Security Continuous Monitoring (ISCM) dashboards Establishing and implementing training processes for all technical personnel. Assisting the TSA in its ultimate goal of meeting or exceeding the "managed and measurable" IG CIGIE FISMA maturity metrics as amended, for all applicable security functions for ZT. Develop, implement, and maintain enterprise-wide performance metrics and measures for the ZT initiative Determine and define clear deliverables, roles, and responsibilities for all resources. Create performance measures for all resources. Managing, updating and maintaining all ZTA program governance documents including but not limited to the ZTA roadmap; which articulates the programs vision, scope, and direction Responsible for development of all management artifacts (PMP, IMP, CP, RMP, QAP, etc.). Ensure program integration and operational processes and procedures. Establishing and maintaining relationships among all stakeholders. Design Dashboard/Briefings to measure program performance, schedule, etc. Responsible for mapping ZTA capabilities outlined throughout this PWS, existing capabilities within the department, and new capabilities the Contractor recommends be added to the Pillars of Zero Trust (currently 5 Pillars) as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, executive orders, and standards. The Contractor must also map new ZTA capabilities that the Government approves Mentor Team Leads Review and ensure all deliverables are submitted in accordance with the SOW and in a timely manner. Cross task area support as required. Qualifications: A minimum of 10 years of IT cybersecurity management experience including 3 years of direct support for the US Government OR a relevant Bachelor's degree in IT, computer science, business or engineering and 10+ years of IT cybersecurity management experience including 3 years of direct support for the US Government. Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers. Understanding and experience with Agile Principles, processes and methodologies. Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures. Excellent communication, collaboration, and problem-solving skills. Ability to work independently and as part of a team. Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact. Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact. Zero Trust Specific Qualifications: System Maturity Model Expertise in the implementation, strategy, roadmap, and analysis with regard to TSA systems and the TSA Enterprise and meet the requirements outlined in M-21-31, M-22-09, EO 14028, and NIST SP 800-207. Working experience associated with implementing all of the Zero Trust requirements based off of the CISA Zero Trust Maturity Model 2.0 and any upcoming versions. SME level knowledge within at least one of the five Zero Trust Maturity Model pillars as defined by the CISA Maturity Model. Possess a deep understanding and proficiency in the principles, technologies, and best practices associated with the pillars. Provide strategic guidance and expertise in implementing Zero Trust within their assigned pillar, ensuring alignment with industry standards and organizational objectives. Deep understanding of the criteria needed to meet the Federal Governments intended, optimal, maturity level. Ability to develop a Zero Trust Maturity Roadmap to achieve optimal maturity level. Education: Minimum of a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, IT, cyber security, or a related field. Relevant years of experience may be used in substitution for situations where the candidate does not have a Bachelor's degree in the required field. Clearance level: Minimum of an active Secret Clearance. Work Location: Hybrid - Primarily Remote. Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., will be occasionally required. Hours of Operation: Business Hours: 8:00 am EST - 4:30 pm EST.
Job Description Job Description Senior Network Security Engineer Type: Staff Augmentation (W2 employee of Innovation Consulting) Location: San Jose, CA (Onsite - Monday through Friday, 8:30 AM-5:00 PM PST) Estimated Duration: Approximately 6 months (August 2026 - February 2027) Salary: $225K - $270K per year, DOE About the Role Innovation Consulting LLC is partnered with California's largest investor-owned water utility to recruit a Senior Network Security Engineer for a six-month onsite engagement in San Jose, CA, running from August 2026 through February 2027. This network security engineer role supports the design, configuration, and implementation of Zero Trust networking, starting with VPN access using Palo Alto Networks technologies. The position advances the organization's Zero Trust Architecture (ZTA) initiatives, strengthens network security controls across on-premises and cloud environments, improves network visibility and access management, and supports infrastructure modernization. The ideal candidate is a hands-on, security-focused network security engineer comfortable working closely with cybersecurity and infrastructure teams in a regulated, audit-conscious environment. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client for the duration of the contract. Key Responsibilities Zero Trust & VPN Engineering • Design and configure Palo Alto Networks VPN solutions to support Zero Trust principles • Implement least-privilege VPN access so users can reach only the systems required for their role • Define and enforce user- and group-based access policies rather than broad network access • Partner with cybersecurity leadership to align VPN controls with Zero Trust strategy Network Security & Visibility • Support network segmentation and secure access to sensitive systems, including admin and infrastructure services • Ensure configurations are fully auditable and defensible for future compliance reviews • Apply cloud networking security, segmentation, and access controls Forensics & Access Context • Use AlienVault and Palo Alto to analyze VPN traffic and user activity and identify systems and applications accessed by approximately 100 VPN users for this engagement • Support forensic investigations related to VPN access • Build a VPN access context from traffic analysis and assign users to the correct VPN groups as part of the Zero Trust initiative Collaboration & Communication • Work closely with the IT Architecture and Cybersecurity teams • Clearly communicate technical findings, access models, and design decisions • Participate in design reviews, scoping discussions, and implementation planning Work Model and On-Site Requirements • Fully onsite in San Jose, CA - this position is not eligible for remote work • Standard business hours: 8:30 AM - 5:00 PM PST, Monday through Friday • Relocation required if not within commutable distance of San Jose, CA Qualifications Required • U.S. Citizenship required • Ability to work onsite in San Jose, CA • Senior-level experience in network security engineering • Strong hands-on experience with Palo Alto Networks firewalls and VPN • Demonstrated understanding of Zero Trust networking concepts • Experience implementing identity-based and role-based access controls • Hands-on experience using SIEM (AlienVault preferred) for logging, analysis, and forensic investigations • Strong troubleshooting and analytical skills, with the ability to communicate effectively with highly technical teams Preferred • Experience in regulated, audit-conscious environments (e.g., utilities / critical infrastructure) • Palo Alto Networks Certified Network Security Administrator (PCNSA) or Palo Alto Networks Certified Network Security Engineer (PCNSE) certification • Familiarity with SASE and cloud-delivered Zero Trust access Compensation & Employment Employment Type: Staff Augmentation. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client. Salary: $225K - $270K per year, DOE. Contract Duration: Approximately 6 months (August 2026 - February 2027). Benefits: Comprehensive benefits package including medical, dental, and vision, 401(k) with safe-harbor matching, HRA, and PTO. No waiting period - benefits are available immediately and accrual items begin accruing immediately. Innovation Consulting LLC is an equal opportunity employer and recruiter. We review candidates without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other protected characteristic.
09/21/2026
Full time
Job Description Job Description Senior Network Security Engineer Type: Staff Augmentation (W2 employee of Innovation Consulting) Location: San Jose, CA (Onsite - Monday through Friday, 8:30 AM-5:00 PM PST) Estimated Duration: Approximately 6 months (August 2026 - February 2027) Salary: $225K - $270K per year, DOE About the Role Innovation Consulting LLC is partnered with California's largest investor-owned water utility to recruit a Senior Network Security Engineer for a six-month onsite engagement in San Jose, CA, running from August 2026 through February 2027. This network security engineer role supports the design, configuration, and implementation of Zero Trust networking, starting with VPN access using Palo Alto Networks technologies. The position advances the organization's Zero Trust Architecture (ZTA) initiatives, strengthens network security controls across on-premises and cloud environments, improves network visibility and access management, and supports infrastructure modernization. The ideal candidate is a hands-on, security-focused network security engineer comfortable working closely with cybersecurity and infrastructure teams in a regulated, audit-conscious environment. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client for the duration of the contract. Key Responsibilities Zero Trust & VPN Engineering • Design and configure Palo Alto Networks VPN solutions to support Zero Trust principles • Implement least-privilege VPN access so users can reach only the systems required for their role • Define and enforce user- and group-based access policies rather than broad network access • Partner with cybersecurity leadership to align VPN controls with Zero Trust strategy Network Security & Visibility • Support network segmentation and secure access to sensitive systems, including admin and infrastructure services • Ensure configurations are fully auditable and defensible for future compliance reviews • Apply cloud networking security, segmentation, and access controls Forensics & Access Context • Use AlienVault and Palo Alto to analyze VPN traffic and user activity and identify systems and applications accessed by approximately 100 VPN users for this engagement • Support forensic investigations related to VPN access • Build a VPN access context from traffic analysis and assign users to the correct VPN groups as part of the Zero Trust initiative Collaboration & Communication • Work closely with the IT Architecture and Cybersecurity teams • Clearly communicate technical findings, access models, and design decisions • Participate in design reviews, scoping discussions, and implementation planning Work Model and On-Site Requirements • Fully onsite in San Jose, CA - this position is not eligible for remote work • Standard business hours: 8:30 AM - 5:00 PM PST, Monday through Friday • Relocation required if not within commutable distance of San Jose, CA Qualifications Required • U.S. Citizenship required • Ability to work onsite in San Jose, CA • Senior-level experience in network security engineering • Strong hands-on experience with Palo Alto Networks firewalls and VPN • Demonstrated understanding of Zero Trust networking concepts • Experience implementing identity-based and role-based access controls • Hands-on experience using SIEM (AlienVault preferred) for logging, analysis, and forensic investigations • Strong troubleshooting and analytical skills, with the ability to communicate effectively with highly technical teams Preferred • Experience in regulated, audit-conscious environments (e.g., utilities / critical infrastructure) • Palo Alto Networks Certified Network Security Administrator (PCNSA) or Palo Alto Networks Certified Network Security Engineer (PCNSE) certification • Familiarity with SASE and cloud-delivered Zero Trust access Compensation & Employment Employment Type: Staff Augmentation. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client. Salary: $225K - $270K per year, DOE. Contract Duration: Approximately 6 months (August 2026 - February 2027). Benefits: Comprehensive benefits package including medical, dental, and vision, 401(k) with safe-harbor matching, HRA, and PTO. No waiting period - benefits are available immediately and accrual items begin accruing immediately. Innovation Consulting LLC is an equal opportunity employer and recruiter. We review candidates without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other protected characteristic.
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Lead Specialist to join our Federal Advisory practice. Responsibilities: Manage and coordinate the implementation, administration, and continuous tuning of AppGate SDP platform components in support of broader enterprise Zero Trust Network Access (ZTNA) objectives Architect, develop, and enforce dynamic, identity-centric security policies, granular micro segmentation rules, and context -aware trusted access models Translate complex organizational security requirements into scalable, effective ZTNA policies across the environment Lead technical workshops, requirements gathering, and workflow creation for securely and seamlessly onboarding mission application to the ZT Architecture Integrate ZTNA tools (AppGate) with broader security ecosystem components including IAM, PAM, and SIEM solutions to achieve end-to-end Zero Trust automation and continuous monitoring Mentor a team of engineers and analysts responsible for AppGate operations Develop comprehensive solution documentation, operational runbooks, and policy guidelines, which contributing to project tracking and reporting Interface with client stakeholders to ensure all ZTNA deployments and access policies rigorously align with compliance, security, and operational mission requirements Qualifications: A minimum of five years of experience with network security technology and diverse Zero Trust Network Access (ZTNA) solutions, including hands-on AppGate SDP implementation experience; U.S. Federal government consulting experience preferred Bachelor's degree from an accredited college/university Two years of leadership or managerial experience Broad, vendor-agnostic knowledge of ZTNA platforms and Software-Defined Perimeter (SDP) architectures Experience designing, implementing, and managing complex, context-based access policies and segmentation strategies at an enterprise scale Strong understanding of Zero Trust principles and deployment patterns, with familiarity with relevant DoD frameworks, NIST 800-207, and large-scale enterprise environments Experience integrating ZTNA solutions with comprehensive Identity and Access Management (IAM), Privileged Access Management (PAM), and ITSM systems Preferred certifications: CISSP, CCSP, GIAC, AppGate Ability to travel as required to support firm engagements Applicant must possess a U.S. Government Secret clearance KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
09/16/2026
Full time
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Lead Specialist to join our Federal Advisory practice. Responsibilities: Manage and coordinate the implementation, administration, and continuous tuning of AppGate SDP platform components in support of broader enterprise Zero Trust Network Access (ZTNA) objectives Architect, develop, and enforce dynamic, identity-centric security policies, granular micro segmentation rules, and context -aware trusted access models Translate complex organizational security requirements into scalable, effective ZTNA policies across the environment Lead technical workshops, requirements gathering, and workflow creation for securely and seamlessly onboarding mission application to the ZT Architecture Integrate ZTNA tools (AppGate) with broader security ecosystem components including IAM, PAM, and SIEM solutions to achieve end-to-end Zero Trust automation and continuous monitoring Mentor a team of engineers and analysts responsible for AppGate operations Develop comprehensive solution documentation, operational runbooks, and policy guidelines, which contributing to project tracking and reporting Interface with client stakeholders to ensure all ZTNA deployments and access policies rigorously align with compliance, security, and operational mission requirements Qualifications: A minimum of five years of experience with network security technology and diverse Zero Trust Network Access (ZTNA) solutions, including hands-on AppGate SDP implementation experience; U.S. Federal government consulting experience preferred Bachelor's degree from an accredited college/university Two years of leadership or managerial experience Broad, vendor-agnostic knowledge of ZTNA platforms and Software-Defined Perimeter (SDP) architectures Experience designing, implementing, and managing complex, context-based access policies and segmentation strategies at an enterprise scale Strong understanding of Zero Trust principles and deployment patterns, with familiarity with relevant DoD frameworks, NIST 800-207, and large-scale enterprise environments Experience integrating ZTNA solutions with comprehensive Identity and Access Management (IAM), Privileged Access Management (PAM), and ITSM systems Preferred certifications: CISSP, CCSP, GIAC, AppGate Ability to travel as required to support firm engagements Applicant must possess a U.S. Government Secret clearance KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
09/15/2026
Full time
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/15/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Staff / Principal Platform Engineer Location: New York City Hybrid Department: AI Platform & Infrastructure Team Reports to: Vangie Shue - Principal Engineering Manager About AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution and Cyber Advisory Services. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate Cyber Advisory Services harden your security posture and ensure business continuity. AppGate safeguards Fortune 500 enterprises and government agencies worldwide. Learn more at About the Role As we expand our platform, we are standing up a new AI Platform & Infrastructure team: the engine room of AppGate's AI strategy. This team owns the infrastructure layer that every next-generation security capability is built on, from network observability to AI-driven threat detection and the secure operation of emerging Agentic AI systems. We're looking for a Staff or Principal Platform Engineer to build and operate the foundational platform behind AppGate's AI products. You combine deep DevOps and cloud infrastructure expertise with hands-on experience operationalizing AI/ML systems, and you treat observability as a first-class engineering discipline. This is a rare opportunity to join a small, private, high-impact company where your work directly shapes the architecture, reliability and core platform that defines the future of security. You'll own the platform spanning APIs, cloud and self-managed solutions and AI/ML infrastructure, and you'll make it fast, reliable and observable at scale. This is a high-leverage, hands-on role for a senior engineer who sets technical direction and still ships. Key Responsibilities Build the Platform: design, build and operate the cloud infrastructure, services and pipelines that AppGate's AI and cloud products run on. Strong experience with self-managed technologies (kafka, elasticsearch) and Kubernetes are a must. Infrastructure as Code & Deployment Orchestration: Terraform and Helm for cloud provisioning, service deployment and configuration management. Implement Observability: instrument APIs, cloud services and AI/ML infrastructure with metrics, logging, tracing and alerting, and define SLOs and operational health metrics that teams trust. Data Platform: real-time and batch data ingestion pipelines, feature stores and data quality. Integrations: third-party connectors, APIs and platform integrations. Operationalize AI/ML: build model serving and inference pipelines, experiment tracking and the MLOps tooling for deployment, versioning, drift monitoring and lifecycle management. Engineer for reliability & automation: apply SRE practices to reduce toil, improve resilience and keep latency and uptime within target across the platform. Automate everything - deliver infrastructure-as-code, CI/CD and self-service tooling so product teams ship safely and quickly. Set technical direction: define platform standards, architecture and best practices, and raise the engineering bar through design reviews and mentorship. Collaborate cross-functionally: partner with data scientists, product teams and leadership to align platform investment with AppGate's strategic vision. Required Qualifications Experience: extensive platform, infrastructure or SRE engineering experience, with a track record of operating production systems at scale. Staff-level candidates typically bring 8+ years and Principal-level candidates 12+ years, though we hire on demonstrated impact. DevOps depth: strong command of infrastructure-as-code (Terraform or equivalent), CI/CD, containers and orchestration (Docker, Kubernetes), and cloud platforms (AWS). Observability expertise: hands-on experience implementing observability across APIs, cloud services and distributed systems using tools such as Prometheus, Grafana, OpenTelemetry, the ELK stack or comparable, including SLO and error-budget practice. Data platform skills: familiarity with real-time and batch ingestion pipelines, feature stores and data quality at production scale. Engineering craft: fluency in a primary backend language (Python, Go or similar) and a strong bias toward automation, testing and reliable, maintainable systems. Leadership: a record of setting technical direction, leading complex initiatives across teams, mentoring senior engineers, while still being very hands-on. Mindset: pragmatic, rigorous and ownership-driven. You thrive in a small, fast-moving environment and enjoy building foundations others depend on. Preferred Qualifications AI/ML infrastructure: experience building or operating model serving, inference pipelines and MLOps tooling such as MLflow, Kubeflow, SageMaker or equivalent, including model deployment, versioning and drift monitoring. Networking & Zero Trust fundamentals: working knowledge of the network and routing layer beneath modern access solutions - TCP/IP, TLS, tunneling/overlay networks, packet routing and filtering, DNS and firewalling - and familiarity with Zero Trust Network Access (ZTNA) or adjacent domains (VPN, SDP, SASE, software-defined networking). You can reason about traffic paths, latency and throughput end-to-end, and instrument the network as a first-class observability signal. Compensation Staff: 185k-225k base Principal: 215k-270k base We offer performance bonuses and considerable equity. AppGate is An Equal Opportunity/Affirmative Action Employer and a federal contractor subject to the Rehabilitation Act of 1973 and the Vietnam Era Veterans Readjustment Assistance Act of 1974 as amended, and their corresponding regulations. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. Further, AppGate is an affirmative action employer committed to taking positive steps to employ, advance in employment and otherwise afford equal employment opportunity to protected veterans and individuals with disabilities. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.
09/15/2026
Full time
Job Description Job Description Staff / Principal Platform Engineer Location: New York City Hybrid Department: AI Platform & Infrastructure Team Reports to: Vangie Shue - Principal Engineering Manager About AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution and Cyber Advisory Services. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate Cyber Advisory Services harden your security posture and ensure business continuity. AppGate safeguards Fortune 500 enterprises and government agencies worldwide. Learn more at About the Role As we expand our platform, we are standing up a new AI Platform & Infrastructure team: the engine room of AppGate's AI strategy. This team owns the infrastructure layer that every next-generation security capability is built on, from network observability to AI-driven threat detection and the secure operation of emerging Agentic AI systems. We're looking for a Staff or Principal Platform Engineer to build and operate the foundational platform behind AppGate's AI products. You combine deep DevOps and cloud infrastructure expertise with hands-on experience operationalizing AI/ML systems, and you treat observability as a first-class engineering discipline. This is a rare opportunity to join a small, private, high-impact company where your work directly shapes the architecture, reliability and core platform that defines the future of security. You'll own the platform spanning APIs, cloud and self-managed solutions and AI/ML infrastructure, and you'll make it fast, reliable and observable at scale. This is a high-leverage, hands-on role for a senior engineer who sets technical direction and still ships. Key Responsibilities Build the Platform: design, build and operate the cloud infrastructure, services and pipelines that AppGate's AI and cloud products run on. Strong experience with self-managed technologies (kafka, elasticsearch) and Kubernetes are a must. Infrastructure as Code & Deployment Orchestration: Terraform and Helm for cloud provisioning, service deployment and configuration management. Implement Observability: instrument APIs, cloud services and AI/ML infrastructure with metrics, logging, tracing and alerting, and define SLOs and operational health metrics that teams trust. Data Platform: real-time and batch data ingestion pipelines, feature stores and data quality. Integrations: third-party connectors, APIs and platform integrations. Operationalize AI/ML: build model serving and inference pipelines, experiment tracking and the MLOps tooling for deployment, versioning, drift monitoring and lifecycle management. Engineer for reliability & automation: apply SRE practices to reduce toil, improve resilience and keep latency and uptime within target across the platform. Automate everything - deliver infrastructure-as-code, CI/CD and self-service tooling so product teams ship safely and quickly. Set technical direction: define platform standards, architecture and best practices, and raise the engineering bar through design reviews and mentorship. Collaborate cross-functionally: partner with data scientists, product teams and leadership to align platform investment with AppGate's strategic vision. Required Qualifications Experience: extensive platform, infrastructure or SRE engineering experience, with a track record of operating production systems at scale. Staff-level candidates typically bring 8+ years and Principal-level candidates 12+ years, though we hire on demonstrated impact. DevOps depth: strong command of infrastructure-as-code (Terraform or equivalent), CI/CD, containers and orchestration (Docker, Kubernetes), and cloud platforms (AWS). Observability expertise: hands-on experience implementing observability across APIs, cloud services and distributed systems using tools such as Prometheus, Grafana, OpenTelemetry, the ELK stack or comparable, including SLO and error-budget practice. Data platform skills: familiarity with real-time and batch ingestion pipelines, feature stores and data quality at production scale. Engineering craft: fluency in a primary backend language (Python, Go or similar) and a strong bias toward automation, testing and reliable, maintainable systems. Leadership: a record of setting technical direction, leading complex initiatives across teams, mentoring senior engineers, while still being very hands-on. Mindset: pragmatic, rigorous and ownership-driven. You thrive in a small, fast-moving environment and enjoy building foundations others depend on. Preferred Qualifications AI/ML infrastructure: experience building or operating model serving, inference pipelines and MLOps tooling such as MLflow, Kubeflow, SageMaker or equivalent, including model deployment, versioning and drift monitoring. Networking & Zero Trust fundamentals: working knowledge of the network and routing layer beneath modern access solutions - TCP/IP, TLS, tunneling/overlay networks, packet routing and filtering, DNS and firewalling - and familiarity with Zero Trust Network Access (ZTNA) or adjacent domains (VPN, SDP, SASE, software-defined networking). You can reason about traffic paths, latency and throughput end-to-end, and instrument the network as a first-class observability signal. Compensation Staff: 185k-225k base Principal: 215k-270k base We offer performance bonuses and considerable equity. AppGate is An Equal Opportunity/Affirmative Action Employer and a federal contractor subject to the Rehabilitation Act of 1973 and the Vietnam Era Veterans Readjustment Assistance Act of 1974 as amended, and their corresponding regulations. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. Further, AppGate is an affirmative action employer committed to taking positive steps to employ, advance in employment and otherwise afford equal employment opportunity to protected veterans and individuals with disabilities. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.