Company Detail

CELESTIAL INNOVATIONS GROUP LLC
Member Since,
Login to View contact details
Login

About Company

Job Openings

  • Helpdesk Technician - Tier II  

    - Washington
    Job DescriptionJob DescriptionLocation: Washington, DCClearance: Publi... Read More
    Job DescriptionJob DescriptionLocation: Washington, DC
    Clearance: Public Trust
    Employment Type: Full-Time

    Must be located in the DC Metro Area as this role requires onsite and remote support. 

    Company DescriptionCelestial Innovations Group (CIG) is a fast-moving, mission driven technology firm working at the intersection of innovation, national security, and digital transformation. We support forward-thinking government agencies with cutting edge capabilities in cybersecurity, cloud, AI/ML, and IT modernization. At CIG, we don’t just check boxes. We solve real-world problems that matter.

    We’re building a culture where smart, curious, and driven people thrive. This is a place where your voice matters, your work has impact, and your growth is part of the mission. If you're looking for a team that values trust, clarity, and the power of innovation, this is where you want to be.

    OverviewThe Tier II Help Desk Computer Specialist provides advanced troubleshooting, escalated issue resolution, and direct support of desktops, systems, and networks within a federal environment. This role requires deeper technical knowledge and hands-on problem solving.

    Key ResponsibilitiesServe as an escalation point for Tier I Help Desk requests, resolving complex technical issues related to desktop, laptop, and tablet systems.Install and configure desktop, laptop, and tablet computers, peripherals, and approved software products for networked, standalone, LAN, and WAN environments.Troubleshoot, diagnose, and resolve hardware, software, and operating system failures for desktops, laptops, and tablets, ensuring timely and effective resolution.Implement, maintain, test, and administer standardized hardware, software, and network configurations across USCP’s distributed computing environment.Perform workstation imaging, patching, configuration, and deployment, including large-scale installations and upgrades across multiple devices.Provide information, guidance, and instruction to users on the proper use of desktop, laptop, and tablet devices, software applications, and system capabilities.Support Microsoft Windows 10/11, Microsoft Office 365 (Email, Teams, OneDrive), and general Exchange/Outlook functions.Troubleshoot issues involving Active Directory, Group Policy, workstation security settings, DNS, DHCP, and network connectivity.Support VPN, remote access, and multi-factor authentication for users including those located outside the Washington, DC Metro area.Contact and communicate effectively with customers via phone, email, Teams, and in person, providing prompt technical solutions.Prepare computer equipment for reuse, refresh, or disposal in accordance with Capital Equipment Refresh Program (CERP) standards and property management procedures.Coordinate the disassembly, movement, and reinstallation of IT equipment in support of office relocations.Document all work performed, including opening and closing tickets within ServiceNow, and contribute updates to knowledge base articles.Assist with equipment inventory, lifecycle management, enterprise printing support, and printer server administration.Collaborate with Tier III and engineering teams to resolve systemic issues and ensure compliance with federal security protocols and configuration standards.Lift and transport IT equipment up to 50 lbs. as required.

    Required QualificationsMust possess an industry-recognized certification such as CompTIA A+, MCSE, or equivalent.Minimum 3 years of experience administering and supporting Windows 10/11 in desktop support or IT infrastructure environments.Experience installing desktops, laptops, tablets, peripherals, and software in LAN, WAN, and standaloneenvironments.Ability to detect, diagnose, and resolve hardware and software failures across desktop, portable, and mobile platforms.Strong experience with Microsoft Windows 10/11, Office 365 (Email, Teams, OneDrive), and general Exchange/Outlook support.Experience using ServiceNow or similar trouble-ticketing systems for ticket management.Strong communication skills with the ability to effectively interact with customers, peers, technical staff, and Government personnel both verbally and in writing.Ability to analyze and assess service requests and provide prompt and accurate technical solutions.Demonstrated proficiency with operating systems, business applications, imaging tools, and hardware platforms.Ability to provide technical support by phone for users located outside the Washington, DC Metro area.Experience performing software and hardware upgrades, system refreshes, and multi-device deployments.Ability to support enterprise printing environments and printer server management.Possess a valid driver’s license and ability to lift up to 50 lbs.Ability to obtain and maintain the required government clearance. Read Less
  • Job DescriptionJob DescriptionPosition Overview Celestial Innovations... Read More
    Job DescriptionJob Description
    Position Overview Celestial Innovations Group (CIG) is seeking an experienced Palo Alto Networks Professional Services Consultant to support our growing federal and government client portfolio. In this role, you will serve as a trusted security advisor and hands-on technical lead, designing and implementing cutting-edge network and cloud security solutions for civilian, defense, and intelligence community agencies. You will work closely with CIG's delivery team and government stakeholders to ensure that security architectures meet the stringent requirements of federal compliance frameworks including FedRAMP, FISMA, NIST SP 800-53, and CMMC.

    Must be located in the DC Metro Area as this role requires onsite and remote support. 

    Key Responsibilities Strengthen and grow the CIG Palo Alto Networks services organization, acting as a technical lead and mentor to fellow engineers.  Lead end-to-end design, deployment, and configuration of Palo Alto Networks solutions (NGFW, Panorama, Prisma Access, Prisma Cloud) within secure government environments. Architect Zero Trust Network Access (ZTNA) frameworks aligned with federal mandates (OMB M-22-09, EO 14028) using Prisma Access and SD-WAN. Configure and tune next-generation firewall (NGFW) policies, App-ID, User-ID, and Threat Prevention profiles to enforce least-privilege access and protect critical assets. Implement Prisma Cloud to provide cloud security posture management (CSPM), cloud workload protection (CWP), and compliance monitoring against NIST, CIS, and DoD STIGs. Conduct security assessments, gap analyses, and architecture reviews, delivering actionable findings and remediation roadmaps to stakeholders. Develop and maintain security documentation including system security plans (SSPs), standard operating procedures (SOPs), and Authority to Operate (ATO) support artifacts. Provide mentorship and knowledge transfer to client IT and security teams, building internal capability and ensuring long-term solution sustainability. Collaborate with CIG's business development and account management teams to identify expansion opportunities, support proposal development, and contribute to solution scoping and estimation. Engage with Palo Alto Networks federal sales and engineering teams to coordinate pre-sales support, licensing, and product roadmap alignment. Stay current with the Palo Alto Networks portfolio, emerging threat landscape, and industry best practices, contributing to CIG's internal knowledge base and capability development. 
    Required Qualifications Active (or ability to achieve) PCNSE (Palo Alto Certified Network Security Engineer) certification. Active (or ability to achieve) PCCSE (Palo Alto Certified Cloud Security Engineer) certification. Active Palo Alto Networks Prisma Access Specialization. 5+ years of hands-on experience designing and implementing enterprise network security solutions with Palo Alto Networks technologies. Deep expertise in Panorama centralized management, policy orchestration, and log management. Proficiency in Prisma Access architecture including GlobalProtect, service connections, remote network onboarding, and security policy enforcement. Strong working knowledge of cloud security principles across AWS, Microsoft Azure, and/or Google Cloud Platform. Demonstrated experience working within federal environments and familiarity with NIST SP 800-53, FedRAMP, FISMA, CMMC, and DoD STIG requirements. Excellent communication skills with the ability to convey complex technical concepts to both technical teams and executive-level stakeholders. Must be eligible to obtain and maintain a Public Trust or Secret clearance; existing clearance preferred. 
    Preferred Qualifications Active DoD Secret or TS/SCI clearance. Experience with Xacta, eMASS, or other GRC platforms supporting ATO processes. Professional certifications in cloud platforms: AWS Solutions Architect, Azure Security Engineer, or Google Professional Cloud Security Engineer. Familiarity with CDM (Continuous Diagnostics and Mitigation) program requirements. Experience with network automation and infrastructure-as-code tools such as Terraform, Ansible, or Palo Alto Panorama APIs. Prior experience in a VAR, systems integrator, or managed security services provider (MSSP) environment. 
    Technical Competencies Network Security PA-Series NGFW (hardware & VM) Panorama policy & device management GlobalProtect VPN & ZTNA Threat Prevention, WildFire, URL Filtering BGP, OSPF, SD-WAN routing Cloud & SASE Prisma Access (SASE) architecture & deployment Prisma Cloud CSPM / CWP / CIEM AWS, Azure, GCP security services Container & Kubernetes security CI/CD pipeline security integration 
    What CIG Offers Competitive compensation commensurate with experience and certifications. Access to the latest Palo Alto Networks technologies, lab environments, and training resources. Opportunities to work on high-impact federal missions with direct national security implications. A collaborative, mission-driven culture where innovation and excellence are recognized and rewarded. Support for ongoing professional development including Palo Alto Networks and broader cybersecurity certifications. Flexible remote/hybrid work arrangements based on project requirements.  Read Less
  • Zero Trust Engineer (Mid-Level)  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Dental insuranceHealth in... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Dental insuranceHealth insurancePaid time offTraining & developmentVision insurance
    POSITION SUMMARY
    Celestial Innovations Group (CIG) is seeking a Mid Zero Trust Engineer to support federal agency clients in the design, implementation, and sustainment of Zero Trust Architecture (ZTA) programs. This role is framework-agnostic and vendor-informed: the ideal candidate understands that Zero Trust is a security philosophy and architectural strategy, not a single product or platform. The engineer will apply that expertise across one or more leading vendor ecosystems to deliver compliant, mission-ready ZTA solutions aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model.

    Must be located in the DC Metro Area as this role requires onsite and remote support.


    KEY RESPONSIBILITIES
    Architecture and Strategy
    Lead Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clientsDesign and document ZTA solutions spanning all five pillars: Identity, Device, Network, Application/Workload, and DataTranslate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plansDevelop architecture artifacts including conceptual, logical, and physical ZTA diagrams using DODAF, TOGAF, or equivalent frameworksSupport integration of ZTA principles into existing enterprise architectures, hybrid cloud environments, and multi-tenant federal networksImplementation and Engineering
    Deploy and configure Zero Trust solutions across one or more vendor platforms (see Vendor Ecosystem section below)Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access ManagementConfigure microsegmentation, Zero Trust Network Access (ZTNA), software-defined perimeters, and DNS security controlsDeploy Endpoint Detection and Response (EDR) tooling and enforce device compliance policies at enterprise scaleIntegrate data protection controls including classification, labeling, DLP, and encryption aligned to ZTA data pillar requirementsCompliance and Authorization
    Align ZTA implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and DHS CDM program requirementsSupport the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenanceDocument ZTA controls for system security packages, POA&Ms, and security assessment reportsClient Engagement and Collaboration
    Serve as a trusted ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterpartsProduce executive-level briefings, technical white papers, and implementation status reportsCollaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams to ensure cohesive ZTA integration
    VENDOR ECOSYSTEM EXPERIENCE
    CIG's ZTA practice is solution-agnostic at the architectural level. Engineers are expected to bring deep expertise in at least one of the following vendor platforms, with cross-platform fluency strongly preferred:

    Vendor / Framework & Relevant Capabilities
    Palo Alto Networks (Prisma): Prisma Access (ZTNA 2.0), Prisma Cloud, Cortex XDR/XSIAM, NGFW policy, SD-WAN integration, threat prevention across all ZTA pillars
    Zscaler: Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), cloud proxy architecture, VPN replacement, SSL inspection
    Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center
    CISA ZT Maturity Model: Five-pillar maturity assessment (Traditional, Initial, Advanced, Optimal), cross-cutting capability mapping, agency self-assessment support, roadmap alignment to federal reporting requirements

    REQUIRED QUALIFICATIONS
    Experience
    5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles2+ years of hands-on experience designing or implementing Zero Trust Architecture in an enterprise or federal environmentDemonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity ModelExperience supporting federal government clients or DoD/civilian agency environments
    Technical Skills
    Proficiency in at least one of the following: Palo Alto Prisma, Zscaler, or Microsoft Zero Trust stackIdentity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, PAM toolingNetwork security: microsegmentation, ZTNA, DNS security, SD-WAN, next-generation firewall policyEndpoint security: EDR/XDR deployment and management, device compliance policy enforcementCloud environments: Azure, AWS, or hybrid cloud architectures with ZTA overlayFamiliarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)
    PREFERRED QUALIFICATIONS
    Active certifications in one or more ZTA vendor platforms: PCCSE, PCNSE, Zscaler ZCCA-IA or ZCCA-PA, Microsoft SC-100 (Cybersecurity Architect Expert)Additional certifications: CISSP, CISM, CompTIA Security+, Cloud+ or relevant AWS/Azure security certificationsFamiliarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparationExperience with ServiceNow, Salesforce, or IT service management tooling in a federal contextMulti-vendor ZTA integration experience (e.g., combining Palo Alto and Zscaler capabilities within a single architecture)Familiarity with post-quantum cryptography standards (FIPS 203/204/205) and their ZTA implications

    Flexible work from home options available.

    Read Less
  • Senior Product Manager GRC Automation  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Dental insuranceHealth in... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Dental insuranceHealth insuranceOpportunity for advancementPaid time offTraining & developmentVision insurance
    Summary
    Our Federal client in Washington, DC is seeking a highly experienced Senior Product Manager to lead the definition, implementation, and management of processes related to compliance, policy, outreach, and privacy. This role is central to automating Governance, Risk, and Compliance (GRC) functions.

    Must be located in the DC Metro Area as this role requires onsite and remote support.


    Key Responsibilities
    Strategy & Requirements: Elicit and synthesize requirements from both technical and non-technical stakeholders to inform the product strategy and prioritization of GRC initiatives.Policy Enablement: Enhance the organizational understanding and accessibility of policy and process requirements.Product Definition: Translate regulatory requirements, policies, and stakeholder needs into precise product/process requirements and user stories.Roadmapping: Develop and execute product roadmaps for GRC automation tools, driving quantifiable improvements in efficiency and risk mitigation.Backlog Management: Own and prioritize the team's backlog, ensuring a balance between immediate operational needs and long-term strategic objectives.Continuous Compliance: Collaborate closely with engineering and delivery teams to integrate security and privacy controls directly into Agile and DevOps workflows, facilitating continuous compliance.Stakeholder Engagement: Maintain transparent communication, alignment, and visibility on the product roadmap and outcomes across all stakeholder groups.Process Improvement: Measure the impact of process changes and leverage data and feedback to drive continuous improvement in processes and services.
    Qualifications
    Experience: Minimum of 5 years in Product Management, with at least 2 years specifically focused on working with security, compliance, or risk management teams.Product Management Skills: Proven track record of gathering requirements, managing product backlogs, and successfully delivering product roadmaps.Automation: Demonstrated success in streamlining and automating business processes using technology solutions.Federal Compliance: Strong working knowledge of federal security compliance frameworks (e.g., FISMA, NIST, FedRAMP).Security & Privacy: Deep understanding of Federal information security principles and privacy regulations.Methodology: Experience with Agile development methodologies and close collaboration with engineering and DevOps teams.Communication: Exceptional communication skills with the ability to effectively translate complex security concepts for diverse audiences.Collaboration: A history of successful cross-functional collaboration and effective stakeholder management.

    Flexible work from home options available.

    Read Less
  • Cortex XSIAM Security Engineer  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Competitive salaryDental... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Competitive salaryDental insuranceHealth insurancePaid time offVision insurance
    Position Summary
    Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal and enterprise clients. This role is at the center of CIG's AI-driven Security Operations practice, enabling clients to modernize their SOC by consolidating SIEM, XDR, SOAR, UEBA, ASM, and TIP capabilities into a single, converged platform.

    The Cortex XSIAM Engineer will serve as a subject-matter expert (SME) throughout the full platform lifecycle: from requirements gathering and architecture design through deployment, integration, and continuous optimization driving measurable improvements in threat detection and incident response times for our government and commercial clients.

    Must be located in the DC Metro Area as this role requires onsite and remote support.


    Key Responsibilities
    Platform Deployment & Integration
    Lead end-to-end deployment of Cortex XSIAM for federal and enterprise clients, including data source onboarding, log ingestion, and normalization.Integrate XSIAM with existing security ecosystem tools including firewalls, endpoints, cloud platforms, identity providers, and ticketing systems.Configure data pipelines to ingest and normalize telemetry from diverse sources (endpoints, network, cloud, identity) into XSIAM's unified data model.Migrate clients from legacy SIEM platforms to Cortex XSIAM, ensuring continuity of detection coverage and compliance reporting.Detection Engineering & Analytics
    Build and tune correlation rules, behavioral analytics, and ML-based detection models within XSIAM to reduce false positive rates and improve detection fidelity.Develop and maintain XSIAM analytics leveraging XQL (Extended Query Language) to extract actionable insights from security telemetry.Map detection content to MITRE ATT&CK framework, ensuring coverage across all relevant tactics, techniques, and procedures (TTPs).Configure AI SmartScoring and technique-based incident grouping to reduce alert fatigue and prioritize analyst workload effectively.Automation & Playbook Development
    Design, build, and maintain SOAR automation playbooks within XSIAM to automate triage, enrichment, and remediation workflows.Leverage Cortex Marketplace content packs and develop custom integrations as needed to support client-specific security processes.Implement dev/prod playbook lifecycle management to ensure safe testing and controlled promotion of automation content.Continuously improve automation coverage, targeting measurable reductions in manual analyst workload.Incident Response & Threat Management
    Serve as escalation point for complex incident investigations, using XSIAM causality chains and full attack-story visualizations to support rapid remediation.Coordinate with client SOC teams during active incidents, leveraging XSIAM's embedded automation and enrichment capabilities.Support Attack Surface Management (ASM) functions to proactively identify and remediate client exposure.Utilize integrated Threat Intelligence Platform (TIP) capabilities, including Unit 42 threat feeds, to enrich alerts and inform response priorities.Client Engagement & Advisory
    Serve as a trusted technical advisor to federal and commercial clients on XSIAM capabilities, roadmap, and SOC modernization strategy.Produce SOC performance dashboards, compliance reports, and executive summaries within XSIAM to support client governance requirements.Conduct training and knowledge transfer sessions to build client SOC team proficiency on the XSIAM platform.Support CIG business development efforts by contributing to proposals, demos, and technical capability briefings for prospective clients.
    Required Qualifications
    3+ years of hands-on experience with Palo Alto Networks Cortex XDR or Cortex XSIAM in an enterprise or federal environment.Demonstrated experience deploying or administering SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent).Proficiency with XQL or comparable query languages for log analysis and threat hunting.Working knowledge of SOAR concepts and experience building security automation playbooks.Understanding of EDR, NDR, and UEBA technologies and how they feed into a converged SOC platform.Familiarity with MITRE ATT&CK framework and its application to detection engineering.Active Secret clearance (minimum); TS/SCI preferred for federal engagements.Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field, OR equivalent professional experience.
    Preferred Qualifications
    Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Cortex XSIAM-specific certification.Experience with federal compliance frameworks including NIST SP 800-53, RMF, DISA STIGs, and CDM program requirements.Familiarity with Zero Trust Architecture principles (NIST SP 800-207, CISA ZT Maturity Model) and how XSIAM supports ZTA adoption.Experience integrating Cortex XSIAM with Palo Alto Networks NGFW, Prisma Cloud, or Zscaler platforms.Knowledge of cloud security telemetry sources (AWS, Azure, GCP) and their ingestion into XSIAM.Exposure to Python or JavaScript for custom XSIAM integration development or automation scripting.Prior experience supporting federal SOC operations or DHS CDM program environments.CISSP, CEH, CompTIA Security+, or equivalent security certification.
    Technical Skills & Tools
    SOC Platforms
    Cortex XSIAM / XDRCortex XSOARSIEM platformsXQL query languageEDR / NDR / UEBASecurity Frameworks
    MITRE ATT&CKNIST SP 800-53 / RMFNIST SP 800-207 (Zero Trust Architecture)CISA Zero Trust Maturity ModelDISA STIGsIntegrations & Tools
    Palo Alto NGFW / PrismaZscaler ZIA / ZPAMicrosoft Sentinel / AzureServiceNow / Ticketing systemsAWS / Azure / GCP

    Flexible work from home options available.

    Read Less
  • Job DescriptionJob DescriptionBenefits:401(k)Competitive salaryDental... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Competitive salaryDental insuranceHealth insurancePaid time offTraining & developmentVision insurance

    Position Overview
    Celestial Innovations Group (CIG) is seeking an experienced Palo Alto Networks Professional Services Consultant to support our growing federal and government client portfolio. In this role, you will serve as a trusted security advisor and hands-on technical lead, designing and implementing cutting-edge network and cloud security solutions for civilian, defense, and intelligence community agencies. You will work closely with CIG's delivery team and government stakeholders to ensure that security architectures meet the stringent requirements of federal compliance frameworks including FedRAMP, FISMA, NIST SP 800-53, and CMMC.

    Must be located in the DC Metro Area as this role requires onsite and remote support.


    Key Responsibilities
    Strengthen and grow the CIG Palo Alto Networks services organization, acting as a technical lead and mentor to fellow engineers. Lead end-to-end design, deployment, and configuration of Palo Alto Networks solutions (NGFW, Panorama, Prisma Access, Prisma Cloud) within secure government environments.Architect Zero Trust Network Access (ZTNA) frameworks aligned with federal mandates (OMB M-22-09, EO 14028) using Prisma Access and SD-WAN.Configure and tune next-generation firewall (NGFW) policies, App-ID, User-ID, and Threat Prevention profiles to enforce least-privilege access and protect critical assets.Implement Prisma Cloud to provide cloud security posture management (CSPM), cloud workload protection (CWP), and compliance monitoring against NIST, CIS, and DoD STIGs.Conduct security assessments, gap analyses, and architecture reviews, delivering actionable findings and remediation roadmaps to stakeholders.Develop and maintain security documentation including system security plans (SSPs), standard operating procedures (SOPs), and Authority to Operate (ATO) support artifacts.Provide mentorship and knowledge transfer to client IT and security teams, building internal capability and ensuring long-term solution sustainability.Collaborate with CIG's business development and account management teams to identify expansion opportunities, support proposal development, and contribute to solution scoping and estimation.Engage with Palo Alto Networks federal sales and engineering teams to coordinate pre-sales support, licensing, and product roadmap alignment.Stay current with the Palo Alto Networks portfolio, emerging threat landscape, and industry best practices, contributing to CIG's internal knowledge base and capability development.
    Required Qualifications
    Active (or ability to achieve) PCNSE (Palo Alto Certified Network Security Engineer) certification.Active (or ability to achieve) PCCSE (Palo Alto Certified Cloud Security Engineer) certification.Active Palo Alto Networks Prisma Access Specialization.5+ years of hands-on experience designing and implementing enterprise network security solutions with Palo Alto Networks technologies.Deep expertise in Panorama centralized management, policy orchestration, and log management.Proficiency in Prisma Access architecture including GlobalProtect, service connections, remote network onboarding, and security policy enforcement.Strong working knowledge of cloud security principles across AWS, Microsoft Azure, and/or Google Cloud Platform.Demonstrated experience working within federal environments and familiarity with NIST SP 800-53, FedRAMP, FISMA, CMMC, and DoD STIG requirements.Excellent communication skills with the ability to convey complex technical concepts to both technical teams and executive-level stakeholders.Must be eligible to obtain and maintain a Public Trust or Secret clearance; existing clearance preferred.
    Preferred Qualifications
    Active DoD Secret or TS/SCI clearance.Experience with Xacta, eMASS, or other GRC platforms supporting ATO processes.Professional certifications in cloud platforms: AWS Solutions Architect, Azure Security Engineer, or Google Professional Cloud Security Engineer.Familiarity with CDM (Continuous Diagnostics and Mitigation) program requirements.Experience with network automation and infrastructure-as-code tools such as Terraform, Ansible, or Palo Alto Panorama APIs.Prior experience in a VAR, systems integrator, or managed security services provider (MSSP) environment.
    Technical Competencies
    Network SecurityPA-Series NGFW (hardware & VM)Panorama policy & device managementGlobalProtect VPN & ZTNAThreat Prevention, WildFire, URL FilteringBGP, OSPF, SD-WAN routingCloud & SASEPrisma Access (SASE) architecture & deploymentPrisma Cloud CSPM / CWP / CIEMAWS, Azure, GCP security servicesContainer & Kubernetes securityCI/CD pipeline security integration
    What CIG Offers
    Competitive compensation commensurate with experience and certifications.Access to the latest Palo Alto Networks technologies, lab environments, and training resources.Opportunities to work on high-impact federal missions with direct national security implications.A collaborative, mission-driven culture where innovation and excellence are recognized and rewarded.Support for ongoing professional development including Palo Alto Networks and broader cybersecurity certifications.Flexible remote/hybrid work arrangements based on project requirements.

    Flexible work from home options available.

    Read Less
  • Senior Palo Alto Networks Engineer  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Competitive salaryDental... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Competitive salaryDental insuranceHealth insurancePaid time offTraining & developmentVision insurance

    Position Overview
    Celestial Innovations Group (CIG) is seeking an experienced Palo Alto Networks Professional Services Consultant to support our growing federal and government client portfolio. In this role, you will serve as a trusted security advisor and hands-on technical lead, designing and implementing cutting-edge network and cloud security solutions for civilian, defense, and intelligence community agencies. You will work closely with CIG's delivery team and government stakeholders to ensure that security architectures meet the stringent requirements of federal compliance frameworks including FedRAMP, FISMA, NIST SP 800-53, and CMMC.

    Must be located in the DC Metro Area as this role requires onsite and remote support.

    Key Responsibilities
    Strengthen and grow the CIG Palo Alto Networks services organization, acting as a technical lead and mentor to fellow engineers. Lead end-to-end design, deployment, and configuration of Palo Alto Networks solutions (NGFW, Panorama, Prisma Access, Prisma Cloud) within secure government environments.Architect Zero Trust Network Access (ZTNA) frameworks aligned with federal mandates (OMB M-22-09, EO 14028) using Prisma Access and SD-WAN.Configure and tune next-generation firewall (NGFW) policies, App-ID, User-ID, and Threat Prevention profiles to enforce least-privilege access and protect critical assets.Implement Prisma Cloud to provide cloud security posture management (CSPM), cloud workload protection (CWP), and compliance monitoring against NIST, CIS, and DoD STIGs.Conduct security assessments, gap analyses, and architecture reviews, delivering actionable findings and remediation roadmaps to stakeholders.Develop and maintain security documentation including system security plans (SSPs), standard operating procedures (SOPs), and Authority to Operate (ATO) support artifacts.Provide mentorship and knowledge transfer to client IT and security teams, building internal capability and ensuring long-term solution sustainability.Collaborate with CIG's business development and account management teams to identify expansion opportunities, support proposal development, and contribute to solution scoping and estimation.Engage with Palo Alto Networks federal sales and engineering teams to coordinate pre-sales support, licensing, and product roadmap alignment.Stay current with the Palo Alto Networks portfolio, emerging threat landscape, and industry best practices, contributing to CIG's internal knowledge base and capability development.
    Required Qualifications
    Active PCNSE (Palo Alto Certified Network Security Engineer) certification.Active PCCSE (Palo Alto Certified Cloud Security Engineer) certification.Active Palo Alto Networks Prisma Access Specialization.5+ years of hands-on experience designing and implementing enterprise network security solutions with Palo Alto Networks technologies.Deep expertise in Panorama centralized management, policy orchestration, and log management.Proficiency in Prisma Access architecture including GlobalProtect, service connections, remote network onboarding, and security policy enforcement.Strong working knowledge of cloud security principles across AWS, Microsoft Azure, and/or Google Cloud Platform.Demonstrated experience working within federal environments and familiarity with NIST SP 800-53, FedRAMP, FISMA, CMMC, and DoD STIG requirements.Excellent communication skills with the ability to convey complex technical concepts to both technical teams and executive-level stakeholders.Must be eligible to obtain and maintain a Public Trust or Secret clearance; existing clearance preferred.
    Preferred Qualifications
    Active DoD Secret or TS/SCI clearance.Experience with Xacta, eMASS, or other GRC platforms supporting ATO processes.Professional certifications in cloud platforms: AWS Solutions Architect, Azure Security Engineer, or Google Professional Cloud Security Engineer.Familiarity with CDM (Continuous Diagnostics and Mitigation) program requirements.Experience with network automation and infrastructure-as-code tools such as Terraform, Ansible, or Palo Alto Panorama APIs.Prior experience in a VAR, systems integrator, or managed security services provider (MSSP) environment.
    Technical Competencies
    Network SecurityPA-Series NGFW (hardware & VM)Panorama policy & device managementGlobalProtect VPN & ZTNAThreat Prevention, WildFire, URL FilteringBGP, OSPF, SD-WAN routingCloud & SASEPrisma Access (SASE) architecture & deploymentPrisma Cloud CSPM / CWP / CIEMAWS, Azure, GCP security servicesContainer & Kubernetes securityCI/CD pipeline security integration
    What CIG Offers
    Competitive compensation commensurate with experience and certifications.Access to the latest Palo Alto Networks technologies, lab environments, and training resources.Opportunities to work on high-impact federal missions with direct national security implications.A collaborative, mission-driven culture where innovation and excellence are recognized and rewarded.Support for ongoing professional development including Palo Alto Networks and broader cybersecurity certifications.Flexible remote/hybrid work arrangements based on project requirements.

    Flexible work from home options available.

    Read Less
  • Server Adminstrator/Engineer  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Competitive salaryDental... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Competitive salaryDental insuranceHealth insuranceOpportunity for advancementPaid time offParental leaveVision insurance
    Position Summary
    Celestial Innovations Group (CIG) is seeking a skilled and motivated Server Administrator/Engineer to support the design, implementation, and maintenance of secure and resilient server infrastructure for enterprise-level environments. The ideal candidate will be experienced in both virtualized and non-virtualized server technologies, possess deep knowledge in system architecture, and be driven to innovate through automation and process improvement.

    Must be located in the DC Metro Area as this role requires onsite and remote support.

    Key Responsibilities
    Design, document, and implement robust server solutions including replication strategies, backup procedures, and disaster recovery planning.Support and maintain server technologies across virtualized (e.g., VMware, Hyper-V) and non-virtualized environments.Configure, install, and upgrade new and existing systems, ensuring optimal performance and scalability.Perform in-depth system analysis, including I/O performance, architecture assessments, and workload optimization.Develop comprehensive system documentation, including configuration standards, operational procedures, and troubleshooting guides.Provide strategic recommendations for enhancements and additions to server infrastructure, based on performance monitoring and business needs.Execute operating system upgrades and implement system enhancements in accordance with best practices and change management policies.Create and execute test plans to validate that systems meet documented user requirements and function as intended.Improve system efficiency and reduce manual workload through process orchestration and automation tools.Develop and maintain procedures to ensure ongoing system reliability, availability, and compliance with enterprise standards.Consult with internal stakeholders on system engineering principles, standards, policies, and best practices.Research and analyze system design issues to support network performance troubleshooting and optimization efforts.Apply process improvement methodologies, such as Capability Maturity Model (CMM), to enhance operational effectiveness.Clearly present technical information, recommendations, and findings in both written reports and oral briefings for stakeholders at various levels.Provide necessary system data and documentation for audits and compliance reporting.

    Required Qualifications
    Proven experience in server administration and engineering roles in enterprise IT environmentsHands-on experience with virtualization platforms such as VMware vSphere, ESXi, or Microsoft Hyper-VStrong understanding of Linux and Windows server environmentsExperience designing and implementing redundant and fault-tolerant systemsProficiency in documentation development for system architectures and proceduresExperience with disaster recovery, backup solutions, and business continuity planningKnowledge of automation/orchestration tools (e.g., PowerShell, Bash, Ansible, Puppet)Familiarity with enterprise support tools (e.g., monitoring suites, ticketing systems, patch management platforms)Excellent communication skillsability to present complex technical information clearly to both technical and non-technical audiences

    Preferred Qualifications
    Experience supporting government or federal IT systemsKnowledge of ITIL, NIST 800-53, and other compliance frameworksFamiliarity with hybrid cloud environments (e.g., AWS GovCloud, Azure Government)Exposure to or experience implementing CMMI-level process improvements
    Read Less
  • Network Engineer  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Dental insuranceHealth in... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Dental insuranceHealth insurancePaid time offTraining & developmentVision insurance
    Location: Washington, DC
    Clearance: Public Trust
    Employment Type: Full-Time

    Must be located in the DC Metro Area as this role requires onsite and remote support.

    Company Description
    Celestial Innovations Group (CIG) is a fast-moving, mission driven technology firm working at the intersection of innovation, national security, and digital transformation. We support forward-thinking government agencies with cutting edge capabilities in cybersecurity, cloud, AI/ML, and IT modernization. At CIG, we dont just check boxes. We solve real-world problems that matter.

    Were building a culture where smart, curious, and driven people thrive. This is a place where your voice matters, your work has impact, and your growth is part of the mission. If you're looking for a team that values trust, clarity, and the power of innovation, this is where you want to be.

    Overview
    The Network Engineer provides mid-level support for enterprise network operations, infrastructure maintenance, and troubleshooting activities critical to government users and systems.

    Key Responsibilities
    Document all network infrastructure components, including switching and routing equipment, IP-addressable devices, cabling interconnects, and associated configurations.Configure, install, operate, maintain, and troubleshoot routers, switches, firewalls, wireless systems, and related network hardware in support of day-to-day operations.Review and analyze current network processes, procedures, and configurations; develop, recommend, and implement approved network process improvements.Develop and implement quality assurance and quality control plans for network maintenance and reliability.Review, analyze, update, and implement network disaster recovery plans to ensure resiliency.Research, design, and implement network security solutions, including vulnerability mitigation, firewall administration, and secure routing/switching architectures.Monitor, review, analyze, and performance-tune the network using enterprise monitoring tools, recommending and implementing optimizations to ensure peak performance.Recognize, track, report on, and mitigate network security vulnerabilities, providing data for audits and compliance activities.Apply standards, policies, and best practices in network engineering, documentation, and change management.Utilize expertise in network protocols, subnets, VLANs, firewalls, VPNs, and multicast technologies to configure and maintain secure and resilient network operations.Conduct design reviews and prepare conceptual designs, schedules, and cost estimates for new or modified network systems.Lead projects as an Engineering Lead or Project Manager to support development of secure, resilient network systems and enhancements.Generate, maintain, and update network documentation, diagrams, and standard operating procedures.Support incident, problem, and change management processes to meet contract SLAs and operational requirements.Collaborate with senior network engineers, security teams, and system administrators to plan and implement network improvements, upgrades, and lifecycle management activities.Assist with vendor coordination and hardware/software procurement in support of network operations and modernization efforts.

    Required Qualifications
    Bachelors degree or equivalent experience.35 years of experience in network operations, network engineering, or network administration.Extensive experience with networking equipment, software, programming, and design, including switches, routers, firewalls, VPNs, wireless systems, and multicast technologies.Proficiency with Cisco networking technologies, standard network protocols, VLANs, subnets, firewall administration, and VPN solutions.Experience implementing network changes, patches, upgrades, and process improvements in secure or regulated IT environments.Demonstrated ability to analyze, troubleshoot, and resolve complex network infrastructure issues, including performance tuning and security vulnerability remediation.Experience contributing to or preparing network documentation, design artifacts, disaster recovery plans, and quality assurance processes.Certifications such as CCNA or Network+ preferred.Ability to obtain and maintain the required government clearance.


    Flexible work from home options available.

    Read Less
  • Helpdesk Technician - Tier III  

    - Washington
    Job DescriptionJob DescriptionBenefits:401(k)Dental insuranceHealth in... Read More
    Job DescriptionJob DescriptionBenefits:
    401(k)Dental insuranceHealth insurancePaid time offTraining & developmentVision insurance
    Location: Washington, DC
    Clearance: Public Trust
    Employment Type: Full-Time

    Must be located in the DC Metro Area as this role requires onsite and remote support.

    Company Description
    Celestial Innovations Group (CIG) is a fast-moving, mission driven technology firm working at the intersection of innovation, national security, and digital transformation. We support forward-thinking government agencies with cutting edge capabilities in cybersecurity, cloud, AI/ML, and IT modernization. At CIG, we dont just check boxes. We solve real-world problems that matter.

    Were building a culture where smart, curious, and driven people thrive. This is a place where your voice matters, your work has impact, and your growth is part of the mission. If you're looking for a team that values trust, clarity, and the power of innovation, this is where you want to be.

    Overview
    The Tier III Systems Administrator provides expert-level technical support, system administration, and problem resolution for enterprise IT environments supporting government missions. This role handles high-complexity issues, system maintenance, and infrastructure-level support.

    Key Responsibilities
    Serve as the Tier III escalation point for issues elevated from Tier II Help Desk personnel.Provide Tier III technical support to PC technicians, including troubleshooting, repairing, installing, and configuring printers, scanners, cameras, and all workstation-related hardware.Maintain and administer enterprise print servers, including configuration changes required during printer refreshes or infrastructure updates.Remotely deploy monthly system patches and security vulnerability updates to workstations using government-provided tools, including Microsoft SCCM and Windows SUS Services.Provide intermediate to advanced troubleshooting support across Microsoft Office products, Active Directory, Exchange, patch management tools, and workstation environments.Develop, maintain, test, and update approved workstation images for all authorized USCP workstation configurations across the enterprise, ensuring monthly updates and compliance.Administer Windows Server environments, Active Directory, DNS, DHCP, and Group Policies, ensuring stability, security, and performance.Support configuration, monitoring, and optimization of infrastructure components across servers, workstations, and enterprise systems.Conduct vulnerability remediation efforts, including scanning, analysis, remediation tracking, and reporting in coordination with cybersecurity teams.Manage and maintain service accounts, system utilities, and administrative tools for servers and workstation environments.Develop, update, and maintain PowerShell scripts for automation, configuration management, and administrative tasks.Troubleshoot escalated multi-system issues and perform root-cause analysis, recommending long-term solutions to prevent recurrence.Maintain documentation, configuration baselines, deployment procedures, and operational processes.Coordinate the development, testing, and on-schedule releases of customized images in collaboration with contractors and technical teams.Implement system improvements, migrations, and upgrades while ensuring alignment with federal security requirements, STIGs, and configuration standards.Work closely with cybersecurity, engineering, and program teams to support mission-critical systems and enterprise operations.

    Required Qualifications
    Must possess an industry-recognized certification such as CompTIA A+, MCSE, or equivalent.Minimum 5 years of experience administering Windows 10/11 in enterprise environments.Minimum 5 years of experience with SCCM (intermediate level or above) for managing servers, deploying patches, and maintaining workstation environments.Minimum 5 years of experience developing, testing, and deploying workstation images for government or private-sector organizations.Expert-level experience with Microsoft Windows 10/11, Office 365 (Email, Teams, OneDrive), and Exchange/Outlook support.Expert-level experience creating, maintaining, and updating PowerShell scripts for automation and administrative tasks.Experience troubleshooting and maintaining print servers, enterprise printing systems, and printer configurations.Ability to diagnose and resolve complex Tier III issues including patch management, security vulnerabilities, and multi-system failures.Ability to provide clients with security vulnerability remediation guidance, tracking, and reporting, including collaboration with other IT teams.Experience maintaining and managing service accounts, system utilities, and server-based software components.Experience conducting ad-hoc vulnerability scans and executing remediation activities across workstations.Strong understanding of Active Directory, GPO management, security hardening, and enterprise infrastructure services.Ability to obtain and maintain required government clearance.


    Flexible work from home options available.

    Read Less

Company Detail

  • Is Email Verified
    No
  • Total Employees
  • Established In
  • Current jobs

Google Map

For Jobseekers
For Employers
Contact Us
Astrid-Lindgren-Weg 12 38229 Salzgitter Germany