SonicJobs Logo
Left arrow iconBack to search

Senior Deployment Engineer, AppGate ZTNA (Federal)

Gormat
Posted a month ago, valid for 11 days
Location

Washington, DC, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • AppGate is seeking a Senior Deployment Engineer with 8 to 12 years of experience in networking, security, systems, or automation engineering roles.
  • The role involves deploying, installing, configuring, and sustaining the AppGate ZTNA platform in U.S. Federal and DoD environments, with a focus on hands-on engineering rather than advisory tasks.
  • Key responsibilities include leading end-to-end deployments, integrating with identity systems, debugging issues, and mentoring junior engineers.
  • Candidates should have a strong background in Linux systems administration, scripting, and experience with public cloud deployments, as well as familiarity with STIG and SCAP compliance.
  • The position offers a competitive salary and requires an active U.S. security clearance or the ability to obtain one, with travel potentially exceeding 50% based on project needs.

*** This is a direct hire for AppGate. 

The Senior Deployment Engineer is the hands-on technical lead for deploying, installing, configuring, and sustaining the AppGate ZTNA platform across U.S. Federal and DoD environments. The work is engineering, not advisory: standing up controllers and gateways, integrating with customer identity and telemetry systems, hardening to STIG and SCAP baselines, and troubleshooting live issues at the protocol, OS, and application level. The Senior Deployment Engineer owns delivery from project kickoff through operational handoff and mentors junior engineers on the team.

Key Responsibilities

  • Lead end-to-end AppGate ZTNA deployments: install and configure controllers, gateways, and clients across on-premises, cloud, and disconnected environments.
  • Integrate AppGate with customer identity providers and sources of trust and risk telemetry, including SAML, OIDC, RADIUS, LDAP(s), Active Directory, NGFWs, entitlement automation systems, SIEM/SOAR, and ITSM.
  • Design deployment architectures that meet customer requirements for availability, scale, and least privilege access enforcement.
  • Debug failures using logs, shell access, packet captures, and code inspection down to the protocol, OS, and application level.
  • Write and maintain scripts and automation (Bash, PowerShell, JavaScript, REST APIs) to support deployment and sustainment.
  • Harden deployments to STIG, SCAP, and applicable Federal compliance baselines.
  • Serve as the escalation point for complex deployment and sustainment issues.
  • Sustain and maintain deployed environments: patching, upgrades, health monitoring, and incident response.
  • Produce detailed as-built documentation, runbooks, and operational handoff materials.
  • Mentor Associate and mid-level Delivery Engineers and review their work.

Required Qualifications

  • 8 to 12 years in networking, security, systems, platform, or automation engineering roles, with hands-on delivery experience.
  • Demonstrated mastery of Linux systems administration.
  • Hands-on scripting and automation with Bash, PowerShell, and JavaScript.
  • Working knowledge of REST APIs for integration and automation.
  • Strong experience with identity systems: Active Directory, DNS, PKI, SAML, OIDC, RADIUS, and LDAP.
  • Experience deploying to public cloud (AWS, Azure, GCP) and virtualization platforms (VMware vSphere, Microsoft Hyper-V)..
  • Familiarity with networking, transport, and cryptographic protocols such as TLS, IPsec, AES, PKI, and RSA.
  • Experience supporting Federal or other high-assurance environments.
  • Familiarity with STIG and SCAP hardening; process frameworks such as ITIL or ITSM a plus.
  • Excellent written and verbal communication for documentation and customer handoff.
  • Bachelor's degree in engineering, information technology, or a related discipline, or equivalent related experience.

Desired Qualifications

  • CCNP, CCIE, RHCE, CISSP, CCNA, Security +, MCSE or equivalent certifications.
  • Prior experience deploying ZTNA, software-defined perimeter (SDP), or VPN-replacement technologies.
  • Experience with infrastructure as code and configuration as code (Terraform, Ansible).

Clearance

  • Active U.S. security clearance, or the ability to obtain and maintain one. Top Secret a plus.

Travel

  • Willingness to travel to customer sites as project and customer needs require. Travel can exceed 50% depending on the deployment.
  • This is a remote opportunity, though we are ideally looking for someone from the following locations:
    • Scott Air Force Base, in St. Clair County, Illinois
    • Gunter Air Force Base, Montgomery, Alabama
    • Kirland Air Force Base, Albuquerque, New Mexico
    • Maryland/DC/VA area



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.