*** This is a direct hire for AppGate. The Senior Deployment Engineer is the hands-on technical lead for deploying, installing, configuring, and sustaining the AppGate ZTNA platform across U.S. Federal and DoD environments. The work is engineering, not advisory: standing up controllers and gateways, integrating with customer identity and telemetry systems, hardening to STIG and SCAP baselines, and troubleshooting live issues at the protocol, OS, and application level. The Senior Deployment Engineer owns delivery from project kickoff through operational handoff and mentors junior engineers on the team. Key Responsibilities Lead end-to-end AppGate ZTNA deployments: install and configure controllers, gateways, and clients across on-premises, cloud, and disconnected environments. Integrate AppGate with customer identity providers and sources of trust and risk telemetry, including SAML, OIDC, RADIUS, LDAP(s), Active Directory, NGFWs, entitlement automation systems, SIEM/SOAR, and ITSM. Design deployment architectures that meet customer requirements for availability, scale, and least privilege access enforcement. Debug failures using logs, shell access, packet captures, and code inspection down to the protocol, OS, and application level. Write and maintain scripts and automation (Bash, PowerShell, JavaScript, REST APIs) to support deployment and sustainment. Harden deployments to STIG, SCAP, and applicable Federal compliance baselines. Serve as the escalation point for complex deployment and sustainment issues. Sustain and maintain deployed environments: patching, upgrades, health monitoring, and incident response. Produce detailed as-built documentation, runbooks, and operational handoff materials. Mentor Associate and mid-level Delivery Engineers and review their work. Required Qualifications 8 to 12 years in networking, security, systems, platform, or automation engineering roles, with hands-on delivery experience. Demonstrated mastery of Linux systems administration. Hands-on scripting and automation with Bash, PowerShell, and JavaScript. Working knowledge of REST APIs for integration and automation. Strong experience with identity systems: Active Directory, DNS, PKI, SAML, OIDC, RADIUS, and LDAP. Experience deploying to public cloud (AWS, Azure, GCP) and virtualization platforms (VMware vSphere, Microsoft Hyper-V).. Familiarity with networking, transport, and cryptographic protocols such as TLS, IPsec, AES, PKI, and RSA. Experience supporting Federal or other high-assurance environments. Familiarity with STIG and SCAP hardening; process frameworks such as ITIL or ITSM a plus. Excellent written and verbal communication for documentation and customer handoff. Bachelor's degree in engineering, information technology, or a related discipline, or equivalent related experience. Desired Qualifications CCNP, CCIE, RHCE, CISSP, CCNA, Security +, MCSE or equivalent certifications. Prior experience deploying ZTNA, software-defined perimeter (SDP), or VPN-replacement technologies. Experience with infrastructure as code and configuration as code (Terraform, Ansible). Clearance Active U.S. security clearance, or the ability to obtain and maintain one. Top Secret a plus. Travel Willingness to travel to customer sites as project and customer needs require. Travel can exceed 50% depending on the deployment. This is a remote opportunity, though we are ideally looking for someone from the following locations: Scott Air Force Base, in St. Clair County, Illinois Gunter Air Force Base, Montgomery, Alabama Kirland Air Force Base, Albuquerque, New Mexico Maryland/DC/VA area
What you'll do
- Lead end-to-end AppGate ZTNA deployments: install, configure, and integrate controllers, gateways, and clients across on-prem, cloud, and air-gapped environments
- Integrate ZTNA platform with customer identity providers (AD, LDAP, SAML, OIDC, RADIUS) and risk telemetry systems (SIEM/SOAR, NGFWs, ITSM)
- Harden deployed systems to STIG and SCAP baselines and maintain compliance with applicable Federal security frameworks
- Debug live failures at the protocol, OS, and application layer using logs, packet captures, shell access, and code inspection
- Write and maintain automation scripts (Bash, PowerShell, JavaScript) and REST API integrations to support deployment and ongoing sustainment
- Own delivery from project kickoff through operational handoff — producing as-built documentation, runbooks, and transition materials
- Serve as technical escalation lead for complex deployment issues and mentor Associate and mid-level Delivery Engineers
Mission
Zero Trust Network Access (ZTNA) platform deployment and sustainment across U.S. Federal and DoD environments, including on-premises, cloud, and disconnected/OCONUS enclaves
Required skills
- Linux systems administration
- Bash scripting
- PowerShell scripting
- REST API integration and automation
- Active Directory / LDAP / SAML / OIDC / RADIUS identity integration
- Cloud deployment (AWS, Azure, or GCP)
- STIG and SCAP hardening
- Networking and cryptographic protocols (TLS, IPsec, PKI)