Illumio Zero Trust Segmentation Platform Engineer - TS/SCI CI Poly
Illumio Zero Trust Segmentation Platform Engineer
General Description
We are looking for a skilled Illumio Zero Trust Segmentation Platform Engineer to support the architecting and implementation of Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls. This role will assist in the design, deployment, configurations and optimization of Illumio Core and Illumio Edge across on-premises, virtualized and cloud environments.
The Zero Trust Segmentation Platform Engineer will develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications. Integrate Illumio with SIEM, SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines. Conduct traffic flow analysis using Illumio VEN telemetry and assist in building policy recommendations to reduce attack surface and limit east-west movement. Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure. Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes. Perform lifecycle management, including upgrades, health checks, certificate operations, and policy governance. Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies. Contribute to architectural standards, documentation, and enterprise security playbooks.
About the Federal Region
GuidePoint Security is the trusted partner that defense and civilian government agencies rely on to lead their cybersecurity efforts and protect their organizations. We help solve their most complex security challenges, mature security architectures, and proactively reduce risk. Our purpose-built solutions ensure compliance, safeguard critical assets, and align security with organizational objectives. Backed by deep expertise, strong partnerships, and advanced technologies, we deliver scalable, adaptive capabilities that evolve with the threat landscape so Federal agencies can lead with confidence and protect what’s next.
Roles and Responsibilities
Assist in the design, deployment, configuration, and optimization of Illumio Core and Illumio Edge across on-premises, virtualized, and cloud environments.
Architect and implement Zero Trust Segmentation policies, including application dependency mapping, labeling frameworks, enforcement boundaries, and zone-based controls.
Develop Illumio workflows, runbooks, dashboards, and segmentation models for enterprise workloads and critical applications.
Integrate Illumio with SIEM/SOAR, CMDB, C2C, vulnerability scanners, cloud-native controls, and enterprise automation pipelines.
Conduct traffic flow analysis using Illumio VEN telemetry and build policy recommendations to reduce attack surface and limit east-west movement.
Troubleshoot system performance, VEN installation issues, policy conflicts, and platform health across distributed infrastructure.
Partner with application owners to onboard workloads, validate segmentation plans, and support change management processes.
Perform lifecycle management: upgrades, health checks, certificate operations, and policy governance.
Collaborate with security architects to align Illumio policy models with broader Zero Trust and NIST 800-207 strategies.
Contribute to architectural standards, documentation, and enterprise security playbooks.
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Required Experience and Education
Active TS/SCI clearance; willingness to take a polygraph exam
5+ years in cybersecurity, cloud security, or infrastructure engineering.
3+ years of expertise in Linux/Windows systems, virtualization (VMware, Hyper-V), and cloud environments (AWS, Azure, or GCP).
2+ years of experience developing and deploying solutions for highly regulated mission-critical environments (finance, healthcare, federal, or energy).
1+ year experience with infrastructure automation tools (Ansible, Terraform, or similar).
1+ year experience with REST APIs, scripting (Python, Bash, PowerShell), or automation frameworks.
Associate’s degree and 5+ years of experience supporting IT projects and activities, Bachelor’s degree and 3+ years of experience supporting IT projects and activities, or Master’s degree and 1+ years of experience supporting IT projects and activities
Ability to obtain a DoD 8570.01-M Cybersecurity Service Provider - Infrastructure Support (CSSP-IS) Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND certification within 30 days of offer accept
Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX (formerly CASP+), CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP certification within 45 days of CSSP-IS date (or offer accept if candidate already has CSSP-IS Cert).
Preferred Experience and Education
Experience deploying and managing Illumio Adaptive Security Platform (ASP) in enterprise environments
Experience with CMDB systems such as ServiceNow, SIEM and SOAR tools, or vulnerability management platforms
Knowledge of Zero Trust principles, micro-segmentation, and lateral movement mitigation
Ability to translate policies into technical controls
Possession of strong analytical and problem-solving skills
Illumio certifications such as Illumio Platform Associate, Illumio Platform Specialist, Illumio Platform Expert, or Illumio Platform On-Prem PCE Administrator
Travel Requirements
100% onsite requirement to Reston, VA OR D.C. location
Physical Requirements
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
If you have additional physical requirements/changes, please discuss with HR first
“Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information.”