VETS, Inc., is looking to add a mid-level (3-5 years experience) Information Systems Security Engineer (ISSE) to our growing team at Scott AFB, IL. This is a full time, permanent position with full benefits working onsite at SAFB. Due to contractual requirements, this position requires US Citizenship and an active/current DoD Security clearance. The successful candidate will: Apply hands-on security engineering skills across a complex mix of on-premise and cloud DoD systems Work alongside dedicated GRC, operations, and architecture teams to implement real security controls Develop deep expertise in STIG compliance, vulnerability management, and PAM security Build your technical toolkit across STIGviewer, SCAP, Tenable, and CyberArk Grow toward senior engineering roles with strong mentorship and technical challenge Responsibilities Implement and document STIG configurations across assigned systems and platforms Conduct Security Impact Analyses (SIAs) for proposed system changes Execute automated configuration validation using SCAP Compliance Checker Manage vulnerability tracking and remediation workflows in Tenable SC Assess cloud infrastructure security posture using Tenable Cloud Security Support CyberArk PAM configuration and privileged access management Develop and maintain security configuration baselines Author technical security control implementation guides Support the Cybersecurity Architect with technical security implementations Qualifications Required: Active Secret or TS clearance 35 years of experience in security engineering or system hardening Hands-on experience with STIGviewer and SCAP Compliance Checker Working experience with Tenable SC or equivalent vulnerability management tools Knowledge of secure configuration management principles DoD 8140.03M DCWF Basic tier certification CEH DoD 8140 Interim Education Options Desired Certification: DoD 8140.03M DCWF Intermediate tier certification one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ Bachelors degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering Experience with CyberArk PAM administration Familiarity with Tenable Cloud Security or equivalent cloud assessment tooling Exposure to DoD cloud environments (IL2IL6)
09/16/2026
VETS, Inc., is looking to add a mid-level (3-5 years experience) Information Systems Security Engineer (ISSE) to our growing team at Scott AFB, IL. This is a full time, permanent position with full benefits working onsite at SAFB. Due to contractual requirements, this position requires US Citizenship and an active/current DoD Security clearance. The successful candidate will: Apply hands-on security engineering skills across a complex mix of on-premise and cloud DoD systems Work alongside dedicated GRC, operations, and architecture teams to implement real security controls Develop deep expertise in STIG compliance, vulnerability management, and PAM security Build your technical toolkit across STIGviewer, SCAP, Tenable, and CyberArk Grow toward senior engineering roles with strong mentorship and technical challenge Responsibilities Implement and document STIG configurations across assigned systems and platforms Conduct Security Impact Analyses (SIAs) for proposed system changes Execute automated configuration validation using SCAP Compliance Checker Manage vulnerability tracking and remediation workflows in Tenable SC Assess cloud infrastructure security posture using Tenable Cloud Security Support CyberArk PAM configuration and privileged access management Develop and maintain security configuration baselines Author technical security control implementation guides Support the Cybersecurity Architect with technical security implementations Qualifications Required: Active Secret or TS clearance 35 years of experience in security engineering or system hardening Hands-on experience with STIGviewer and SCAP Compliance Checker Working experience with Tenable SC or equivalent vulnerability management tools Knowledge of secure configuration management principles DoD 8140.03M DCWF Basic tier certification CEH DoD 8140 Interim Education Options Desired Certification: DoD 8140.03M DCWF Intermediate tier certification one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ Bachelors degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering Experience with CyberArk PAM administration Familiarity with Tenable Cloud Security or equivalent cloud assessment tooling Exposure to DoD cloud environments (IL2IL6)
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/15/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/15/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
09/15/2026
Full time
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
Job Description Job Description About Us Founded in 1998, Advantage Microsystems provides complete, outsourced IT departments for nonprofits and businesses with 100 to 1,000 employees across the Bay Area. Our clients are mission-driven organizations - nonprofits, behavioral health providers, and professional services firms - who rely on us as their full technology team. Our approach is built on three pillars: Service, Security, and Strategy. We don't just keep the lights on; we help clients build toward something. We're a well-established firm with strong team dynamics, a culture of mutual respect, and zero tolerance for micromanagement. We hire responsible people and trust them to do their jobs. Advantage Microsystems is seeking an exceptional engineer to serve as a technical anchor for our clients and a collaborative force on our team. This is a role for someone who has already operated as an L3 or lead engineer - and who combines deep technical expertise with the presence and communication skills to serve as a fractional IT leader for our clients. You'll own complex architecture and escalations, but you'll also build IT roadmaps, develop technology budgets, and lead quarterly business reviews with executive stakeholders. If you can hold your own in a server room and a boardroom, we'd love to talk. We promote to this level from within whenever possible - this is a rare external search driven by our current growth. Why Advantage Microsystems? Tenure - Our average employee tenure is 9.5 years. We think that speaks for itself. Compensation - Our people are well compensated with pay and benefits, because employee retention is extremely important to us. Ownership and Impact - You'll have real ownership over client outcomes, architecture decisions, and technical standards. You'll be working within a strong team and well-developed systems, with experienced colleagues and a CIO who want your expertise and judgment in the mix. Culture - Our team is great. We have each other's backs, we have fun with our work, and our clients love us. We're all learning and growing together, so input and suggestions from our engineering staff directly shape how we operate. Lifestyle - We were a work-from-home company before COVID and we'll continue to be one. That said, this role involves periodic onsite client visits - reliable transportation is a must. Transparency - As part of the interview process, you'll have the opportunity to speak directly with other AM employees and get a real feel for what it's like to work here. What You'll Be Doing You'll serve as a principal technical resource across a portfolio of clients, contributing to their technology strategy and owning complex projects and escalations end-to-end. This is a collaborative role - you'll work closely with fellow engineers, L1/L2 technicians, and AM's CIO to deliver outcomes that matter. Most client engagements happen remotely, with onsite visits scheduled in advance for project work, executive meetings, and major cutovers. Client Leadership and Strategy Serve as a fractional IT leader for assigned clients - owning technology roadmaps, annual budgets, and quarterly business reviews with executive stakeholders Translate complex technical concepts and risk into clear business language for non-technical audiences Lead client-facing conversations on compliance, security posture, and IT investment priorities Translate business requirements into technical architecture and multi-quarter project plans Architecture and Project Delivery Design and lead implementation of complex projects: Microsoft 365 / Entra tenant design, Conditional Access and Zero Trust rollouts, Intune MDM/MAM deployments, server and network refreshes, cloud migrations, and M&A integrations Own the technical standards and reference architectures our team deploys against Lead security and compliance initiatives - SOC 2, CMMC/NIST 800-171, HIPAA - including policy development, control implementation, and audit support Escalation and Technical Ownership Serve as the final escalation point for the most complex client issues - the engineer who owns the problem when nobody else can solve it Lead post-incident reviews and drive the remediation work that prevents repeat issues Own the deep-dive troubleshooting on identity, hybrid cloud, networking, and security problems Team Collaboration and Mentorship Collaborate with fellow engineers and contribute to a culture of shared knowledge and continuous improvement Mentor L1 and L2 technicians through technical coaching and project shadowing Contribute to hiring, technical interviews, and onboarding of new engineers Drive continuous improvement of our internal documentation, runbooks, and tooling What You Should Bring Required Technical Depth Microsoft 365 / Entra ID - tenant architecture, hybrid identity, Conditional Access, Intune (MDM and MAM-WE), Defender suite, Purview/compliance, Exchange Online, SharePoint/OneDrive governance Identity and Access - Active Directory, Entra Connect, SSO/SAML/OIDC, privileged access management, phishing-resistant MFA (FIDO2, passkeys) Security Architecture - Zero Trust principles, endpoint protection (EDR/XDR), application allowlisting, email security, vulnerability management, incident response Networking - firewall administration (Meraki, Fortinet, SonicWall, or similar), VLAN design, VPN and SD-WAN, TCP/IP, DNS, DHCP, routing fundamentals Server and Virtualization - Windows Server (current versions), VMware or Hyper-V, storage (SAN/NAS), backup and DR architecture (Datto, Veeam, or similar) Cloud Platforms - Azure (required); AWS or GCP exposure a plus MSP Tooling - RMM platforms (Datto RMM, Kaseya, NinjaOne, or similar), PSA platforms (ConnectWise Manage, Autotask, HaloPSA, or similar), documentation systems (IT Glue, Hudu) Compliance Frameworks - working knowledge of at least one of SOC 2, CMMC/NIST 800-171, HIPAA, or PCI Scripting and Automation - PowerShell at a production level; Graph API, Power Automate, or similar a plus Experience 8+ years in IT with at least 3 years in a lead engineer or equivalent hands-on technical capacity Prior MSP experience strongly preferred - you understand the cadence of multi-client work Demonstrated history of owning projects end-to-end, from discovery through handoff Experience developing IT roadmaps and technology budgets and presenting them to business stakeholders Experience mentoring junior technicians and contributing to team growth Relevant certifications are valued: Microsoft (MS-102, SC-300, AZ-104, AZ-305), CISSP, CISM, CCNP, or equivalent Who You Are Comfortable leading executive conversations and translating technical risk into business language Strong written communication - you document what you do and explain decisions clearly Collaborative by nature - you make the people around you better and you build on the work of your team Background supporting or operating within small businesses, with strong multitasking skills and comfort in dynamic, lean environments. Takes pride in excellent work; thorough, detail-oriented, and follows through Maintains composure under pressure and handles concurrent priorities well Genuinely enjoys mentoring and sees team growth as part of the job Benefits Base compensation: $100,000-$140,000 depending on experience and certifications Paid vacation: 15 days/year to start, increasing to 20 days after 3 years and 25 days after 5 years Paid sick time: 40 hours per annual year 9 paid holidays plus your birthday off Company-paid health insurance (Blue Shield PPO or Kaiser - your choice), dental, and vision; dependent coverage available at a significant company subsidy Life and short/long-term disability insurance Employee Assistance Program (EAP) Employee Anniversary Recognition Program Company-funded training materials and professional certification exams Mileage and vehicle wear-and-tear reimbursement for all client visits 401k with company matching (after 90 days) Virtual lab environment for self-directed learning and experimentation We are an equal opportunity employer. This position is open to local Bay Area candidates only - no relocation benefits are available. Candidates must be authorized to work in the United States.
09/15/2026
Full time
Job Description Job Description About Us Founded in 1998, Advantage Microsystems provides complete, outsourced IT departments for nonprofits and businesses with 100 to 1,000 employees across the Bay Area. Our clients are mission-driven organizations - nonprofits, behavioral health providers, and professional services firms - who rely on us as their full technology team. Our approach is built on three pillars: Service, Security, and Strategy. We don't just keep the lights on; we help clients build toward something. We're a well-established firm with strong team dynamics, a culture of mutual respect, and zero tolerance for micromanagement. We hire responsible people and trust them to do their jobs. Advantage Microsystems is seeking an exceptional engineer to serve as a technical anchor for our clients and a collaborative force on our team. This is a role for someone who has already operated as an L3 or lead engineer - and who combines deep technical expertise with the presence and communication skills to serve as a fractional IT leader for our clients. You'll own complex architecture and escalations, but you'll also build IT roadmaps, develop technology budgets, and lead quarterly business reviews with executive stakeholders. If you can hold your own in a server room and a boardroom, we'd love to talk. We promote to this level from within whenever possible - this is a rare external search driven by our current growth. Why Advantage Microsystems? Tenure - Our average employee tenure is 9.5 years. We think that speaks for itself. Compensation - Our people are well compensated with pay and benefits, because employee retention is extremely important to us. Ownership and Impact - You'll have real ownership over client outcomes, architecture decisions, and technical standards. You'll be working within a strong team and well-developed systems, with experienced colleagues and a CIO who want your expertise and judgment in the mix. Culture - Our team is great. We have each other's backs, we have fun with our work, and our clients love us. We're all learning and growing together, so input and suggestions from our engineering staff directly shape how we operate. Lifestyle - We were a work-from-home company before COVID and we'll continue to be one. That said, this role involves periodic onsite client visits - reliable transportation is a must. Transparency - As part of the interview process, you'll have the opportunity to speak directly with other AM employees and get a real feel for what it's like to work here. What You'll Be Doing You'll serve as a principal technical resource across a portfolio of clients, contributing to their technology strategy and owning complex projects and escalations end-to-end. This is a collaborative role - you'll work closely with fellow engineers, L1/L2 technicians, and AM's CIO to deliver outcomes that matter. Most client engagements happen remotely, with onsite visits scheduled in advance for project work, executive meetings, and major cutovers. Client Leadership and Strategy Serve as a fractional IT leader for assigned clients - owning technology roadmaps, annual budgets, and quarterly business reviews with executive stakeholders Translate complex technical concepts and risk into clear business language for non-technical audiences Lead client-facing conversations on compliance, security posture, and IT investment priorities Translate business requirements into technical architecture and multi-quarter project plans Architecture and Project Delivery Design and lead implementation of complex projects: Microsoft 365 / Entra tenant design, Conditional Access and Zero Trust rollouts, Intune MDM/MAM deployments, server and network refreshes, cloud migrations, and M&A integrations Own the technical standards and reference architectures our team deploys against Lead security and compliance initiatives - SOC 2, CMMC/NIST 800-171, HIPAA - including policy development, control implementation, and audit support Escalation and Technical Ownership Serve as the final escalation point for the most complex client issues - the engineer who owns the problem when nobody else can solve it Lead post-incident reviews and drive the remediation work that prevents repeat issues Own the deep-dive troubleshooting on identity, hybrid cloud, networking, and security problems Team Collaboration and Mentorship Collaborate with fellow engineers and contribute to a culture of shared knowledge and continuous improvement Mentor L1 and L2 technicians through technical coaching and project shadowing Contribute to hiring, technical interviews, and onboarding of new engineers Drive continuous improvement of our internal documentation, runbooks, and tooling What You Should Bring Required Technical Depth Microsoft 365 / Entra ID - tenant architecture, hybrid identity, Conditional Access, Intune (MDM and MAM-WE), Defender suite, Purview/compliance, Exchange Online, SharePoint/OneDrive governance Identity and Access - Active Directory, Entra Connect, SSO/SAML/OIDC, privileged access management, phishing-resistant MFA (FIDO2, passkeys) Security Architecture - Zero Trust principles, endpoint protection (EDR/XDR), application allowlisting, email security, vulnerability management, incident response Networking - firewall administration (Meraki, Fortinet, SonicWall, or similar), VLAN design, VPN and SD-WAN, TCP/IP, DNS, DHCP, routing fundamentals Server and Virtualization - Windows Server (current versions), VMware or Hyper-V, storage (SAN/NAS), backup and DR architecture (Datto, Veeam, or similar) Cloud Platforms - Azure (required); AWS or GCP exposure a plus MSP Tooling - RMM platforms (Datto RMM, Kaseya, NinjaOne, or similar), PSA platforms (ConnectWise Manage, Autotask, HaloPSA, or similar), documentation systems (IT Glue, Hudu) Compliance Frameworks - working knowledge of at least one of SOC 2, CMMC/NIST 800-171, HIPAA, or PCI Scripting and Automation - PowerShell at a production level; Graph API, Power Automate, or similar a plus Experience 8+ years in IT with at least 3 years in a lead engineer or equivalent hands-on technical capacity Prior MSP experience strongly preferred - you understand the cadence of multi-client work Demonstrated history of owning projects end-to-end, from discovery through handoff Experience developing IT roadmaps and technology budgets and presenting them to business stakeholders Experience mentoring junior technicians and contributing to team growth Relevant certifications are valued: Microsoft (MS-102, SC-300, AZ-104, AZ-305), CISSP, CISM, CCNP, or equivalent Who You Are Comfortable leading executive conversations and translating technical risk into business language Strong written communication - you document what you do and explain decisions clearly Collaborative by nature - you make the people around you better and you build on the work of your team Background supporting or operating within small businesses, with strong multitasking skills and comfort in dynamic, lean environments. Takes pride in excellent work; thorough, detail-oriented, and follows through Maintains composure under pressure and handles concurrent priorities well Genuinely enjoys mentoring and sees team growth as part of the job Benefits Base compensation: $100,000-$140,000 depending on experience and certifications Paid vacation: 15 days/year to start, increasing to 20 days after 3 years and 25 days after 5 years Paid sick time: 40 hours per annual year 9 paid holidays plus your birthday off Company-paid health insurance (Blue Shield PPO or Kaiser - your choice), dental, and vision; dependent coverage available at a significant company subsidy Life and short/long-term disability insurance Employee Assistance Program (EAP) Employee Anniversary Recognition Program Company-funded training materials and professional certification exams Mileage and vehicle wear-and-tear reimbursement for all client visits 401k with company matching (after 90 days) Virtual lab environment for self-directed learning and experimentation We are an equal opportunity employer. This position is open to local Bay Area candidates only - no relocation benefits are available. Candidates must be authorized to work in the United States.
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
09/15/2026
Full time
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
09/13/2026
Full time
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
Job Description Job Description About Us Founded in 1998, Advantage Microsystems provides complete, outsourced IT departments for nonprofits and businesses with 100 to 1,000 employees across the Bay Area. Our clients are mission-driven organizations - nonprofits, behavioral health providers, and professional services firms - who rely on us as their full technology team. Our approach is built on three pillars: Service, Security, and Strategy. We don't just keep the lights on; we help clients build toward something. We're a well-established firm with strong team dynamics, a culture of mutual respect, and zero tolerance for micromanagement. We hire responsible people and trust them to do their jobs. Advantage Microsystems is seeking an exceptional engineer to serve as a technical anchor for our clients and a collaborative force on our team. This is a role for someone who has already operated as an L3 or lead engineer - and who combines deep technical expertise with the presence and communication skills to serve as a fractional IT leader for our clients. You'll own complex architecture and escalations, but you'll also build IT roadmaps, develop technology budgets, and lead quarterly business reviews with executive stakeholders. If you can hold your own in a server room and a boardroom, we'd love to talk. We promote to this level from within whenever possible - this is a rare external search driven by our current growth. Why Advantage Microsystems? Tenure - Our average employee tenure is 9.5 years. We think that speaks for itself. Compensation - Our people are well compensated with pay and benefits, because employee retention is extremely important to us. Ownership and Impact - You'll have real ownership over client outcomes, architecture decisions, and technical standards. You'll be working within a strong team and well-developed systems, with experienced colleagues and a CIO who want your expertise and judgment in the mix. Culture - Our team is great. We have each other's backs, we have fun with our work, and our clients love us. We're all learning and growing together, so input and suggestions from our engineering staff directly shape how we operate. Lifestyle - We were a work-from-home company before COVID and we'll continue to be one. That said, this role involves periodic onsite client visits - reliable transportation is a must. Transparency - As part of the interview process, you'll have the opportunity to speak directly with other AM employees and get a real feel for what it's like to work here. What You'll Be Doing You'll serve as a principal technical resource across a portfolio of clients, contributing to their technology strategy and owning complex projects and escalations end-to-end. This is a collaborative role - you'll work closely with fellow engineers, L1/L2 technicians, and AM's CIO to deliver outcomes that matter. Most client engagements happen remotely, with onsite visits scheduled in advance for project work, executive meetings, and major cutovers. Client Leadership and Strategy Serve as a fractional IT leader for assigned clients - owning technology roadmaps, annual budgets, and quarterly business reviews with executive stakeholders Translate complex technical concepts and risk into clear business language for non-technical audiences Lead client-facing conversations on compliance, security posture, and IT investment priorities Translate business requirements into technical architecture and multi-quarter project plans Architecture and Project Delivery Design and lead implementation of complex projects: Microsoft 365 / Entra tenant design, Conditional Access and Zero Trust rollouts, Intune MDM/MAM deployments, server and network refreshes, cloud migrations, and M&A integrations Own the technical standards and reference architectures our team deploys against Lead security and compliance initiatives - SOC 2, CMMC/NIST 800-171, HIPAA - including policy development, control implementation, and audit support Escalation and Technical Ownership Serve as the final escalation point for the most complex client issues - the engineer who owns the problem when nobody else can solve it Lead post-incident reviews and drive the remediation work that prevents repeat issues Own the deep-dive troubleshooting on identity, hybrid cloud, networking, and security problems Team Collaboration and Mentorship Collaborate with fellow engineers and contribute to a culture of shared knowledge and continuous improvement Mentor L1 and L2 technicians through technical coaching and project shadowing Contribute to hiring, technical interviews, and onboarding of new engineers Drive continuous improvement of our internal documentation, runbooks, and tooling What You Should Bring Required Technical Depth Microsoft 365 / Entra ID - tenant architecture, hybrid identity, Conditional Access, Intune (MDM and MAM-WE), Defender suite, Purview/compliance, Exchange Online, SharePoint/OneDrive governance Identity and Access - Active Directory, Entra Connect, SSO/SAML/OIDC, privileged access management, phishing-resistant MFA (FIDO2, passkeys) Security Architecture - Zero Trust principles, endpoint protection (EDR/XDR), application allowlisting, email security, vulnerability management, incident response Networking - firewall administration (Meraki, Fortinet, SonicWall, or similar), VLAN design, VPN and SD-WAN, TCP/IP, DNS, DHCP, routing fundamentals Server and Virtualization - Windows Server (current versions), VMware or Hyper-V, storage (SAN/NAS), backup and DR architecture (Datto, Veeam, or similar) Cloud Platforms - Azure (required); AWS or GCP exposure a plus MSP Tooling - RMM platforms (Datto RMM, Kaseya, NinjaOne, or similar), PSA platforms (ConnectWise Manage, Autotask, HaloPSA, or similar), documentation systems (IT Glue, Hudu) Compliance Frameworks - working knowledge of at least one of SOC 2, CMMC/NIST 800-171, HIPAA, or PCI Scripting and Automation - PowerShell at a production level; Graph API, Power Automate, or similar a plus Experience 8+ years in IT with at least 3 years in a lead engineer or equivalent hands-on technical capacity Prior MSP experience strongly preferred - you understand the cadence of multi-client work Demonstrated history of owning projects end-to-end, from discovery through handoff Experience developing IT roadmaps and technology budgets and presenting them to business stakeholders Experience mentoring junior technicians and contributing to team growth Relevant certifications are valued: Microsoft (MS-102, SC-300, AZ-104, AZ-305), CISSP, CISM, CCNP, or equivalent Who You Are Comfortable leading executive conversations and translating technical risk into business language Strong written communication - you document what you do and explain decisions clearly Collaborative by nature - you make the people around you better and you build on the work of your team Background supporting or operating within small businesses, with strong multitasking skills and comfort in dynamic, lean environments. Takes pride in excellent work; thorough, detail-oriented, and follows through Maintains composure under pressure and handles concurrent priorities well Genuinely enjoys mentoring and sees team growth as part of the job Benefits Base compensation: $100,000-$140,000 depending on experience and certifications Paid vacation: 15 days/year to start, increasing to 20 days after 3 years and 25 days after 5 years Paid sick time: 40 hours per annual year 9 paid holidays plus your birthday off Company-paid health insurance (Blue Shield PPO or Kaiser - your choice), dental, and vision; dependent coverage available at a significant company subsidy Life and short/long-term disability insurance Employee Assistance Program (EAP) Employee Anniversary Recognition Program Company-funded training materials and professional certification exams Mileage and vehicle wear-and-tear reimbursement for all client visits 401k with company matching (after 90 days) Virtual lab environment for self-directed learning and experimentation We are an equal opportunity employer. This position is open to local Bay Area candidates only - no relocation benefits are available. Candidates must be authorized to work in the United States.
09/13/2026
Full time
Job Description Job Description About Us Founded in 1998, Advantage Microsystems provides complete, outsourced IT departments for nonprofits and businesses with 100 to 1,000 employees across the Bay Area. Our clients are mission-driven organizations - nonprofits, behavioral health providers, and professional services firms - who rely on us as their full technology team. Our approach is built on three pillars: Service, Security, and Strategy. We don't just keep the lights on; we help clients build toward something. We're a well-established firm with strong team dynamics, a culture of mutual respect, and zero tolerance for micromanagement. We hire responsible people and trust them to do their jobs. Advantage Microsystems is seeking an exceptional engineer to serve as a technical anchor for our clients and a collaborative force on our team. This is a role for someone who has already operated as an L3 or lead engineer - and who combines deep technical expertise with the presence and communication skills to serve as a fractional IT leader for our clients. You'll own complex architecture and escalations, but you'll also build IT roadmaps, develop technology budgets, and lead quarterly business reviews with executive stakeholders. If you can hold your own in a server room and a boardroom, we'd love to talk. We promote to this level from within whenever possible - this is a rare external search driven by our current growth. Why Advantage Microsystems? Tenure - Our average employee tenure is 9.5 years. We think that speaks for itself. Compensation - Our people are well compensated with pay and benefits, because employee retention is extremely important to us. Ownership and Impact - You'll have real ownership over client outcomes, architecture decisions, and technical standards. You'll be working within a strong team and well-developed systems, with experienced colleagues and a CIO who want your expertise and judgment in the mix. Culture - Our team is great. We have each other's backs, we have fun with our work, and our clients love us. We're all learning and growing together, so input and suggestions from our engineering staff directly shape how we operate. Lifestyle - We were a work-from-home company before COVID and we'll continue to be one. That said, this role involves periodic onsite client visits - reliable transportation is a must. Transparency - As part of the interview process, you'll have the opportunity to speak directly with other AM employees and get a real feel for what it's like to work here. What You'll Be Doing You'll serve as a principal technical resource across a portfolio of clients, contributing to their technology strategy and owning complex projects and escalations end-to-end. This is a collaborative role - you'll work closely with fellow engineers, L1/L2 technicians, and AM's CIO to deliver outcomes that matter. Most client engagements happen remotely, with onsite visits scheduled in advance for project work, executive meetings, and major cutovers. Client Leadership and Strategy Serve as a fractional IT leader for assigned clients - owning technology roadmaps, annual budgets, and quarterly business reviews with executive stakeholders Translate complex technical concepts and risk into clear business language for non-technical audiences Lead client-facing conversations on compliance, security posture, and IT investment priorities Translate business requirements into technical architecture and multi-quarter project plans Architecture and Project Delivery Design and lead implementation of complex projects: Microsoft 365 / Entra tenant design, Conditional Access and Zero Trust rollouts, Intune MDM/MAM deployments, server and network refreshes, cloud migrations, and M&A integrations Own the technical standards and reference architectures our team deploys against Lead security and compliance initiatives - SOC 2, CMMC/NIST 800-171, HIPAA - including policy development, control implementation, and audit support Escalation and Technical Ownership Serve as the final escalation point for the most complex client issues - the engineer who owns the problem when nobody else can solve it Lead post-incident reviews and drive the remediation work that prevents repeat issues Own the deep-dive troubleshooting on identity, hybrid cloud, networking, and security problems Team Collaboration and Mentorship Collaborate with fellow engineers and contribute to a culture of shared knowledge and continuous improvement Mentor L1 and L2 technicians through technical coaching and project shadowing Contribute to hiring, technical interviews, and onboarding of new engineers Drive continuous improvement of our internal documentation, runbooks, and tooling What You Should Bring Required Technical Depth Microsoft 365 / Entra ID - tenant architecture, hybrid identity, Conditional Access, Intune (MDM and MAM-WE), Defender suite, Purview/compliance, Exchange Online, SharePoint/OneDrive governance Identity and Access - Active Directory, Entra Connect, SSO/SAML/OIDC, privileged access management, phishing-resistant MFA (FIDO2, passkeys) Security Architecture - Zero Trust principles, endpoint protection (EDR/XDR), application allowlisting, email security, vulnerability management, incident response Networking - firewall administration (Meraki, Fortinet, SonicWall, or similar), VLAN design, VPN and SD-WAN, TCP/IP, DNS, DHCP, routing fundamentals Server and Virtualization - Windows Server (current versions), VMware or Hyper-V, storage (SAN/NAS), backup and DR architecture (Datto, Veeam, or similar) Cloud Platforms - Azure (required); AWS or GCP exposure a plus MSP Tooling - RMM platforms (Datto RMM, Kaseya, NinjaOne, or similar), PSA platforms (ConnectWise Manage, Autotask, HaloPSA, or similar), documentation systems (IT Glue, Hudu) Compliance Frameworks - working knowledge of at least one of SOC 2, CMMC/NIST 800-171, HIPAA, or PCI Scripting and Automation - PowerShell at a production level; Graph API, Power Automate, or similar a plus Experience 8+ years in IT with at least 3 years in a lead engineer or equivalent hands-on technical capacity Prior MSP experience strongly preferred - you understand the cadence of multi-client work Demonstrated history of owning projects end-to-end, from discovery through handoff Experience developing IT roadmaps and technology budgets and presenting them to business stakeholders Experience mentoring junior technicians and contributing to team growth Relevant certifications are valued: Microsoft (MS-102, SC-300, AZ-104, AZ-305), CISSP, CISM, CCNP, or equivalent Who You Are Comfortable leading executive conversations and translating technical risk into business language Strong written communication - you document what you do and explain decisions clearly Collaborative by nature - you make the people around you better and you build on the work of your team Background supporting or operating within small businesses, with strong multitasking skills and comfort in dynamic, lean environments. Takes pride in excellent work; thorough, detail-oriented, and follows through Maintains composure under pressure and handles concurrent priorities well Genuinely enjoys mentoring and sees team growth as part of the job Benefits Base compensation: $100,000-$140,000 depending on experience and certifications Paid vacation: 15 days/year to start, increasing to 20 days after 3 years and 25 days after 5 years Paid sick time: 40 hours per annual year 9 paid holidays plus your birthday off Company-paid health insurance (Blue Shield PPO or Kaiser - your choice), dental, and vision; dependent coverage available at a significant company subsidy Life and short/long-term disability insurance Employee Assistance Program (EAP) Employee Anniversary Recognition Program Company-funded training materials and professional certification exams Mileage and vehicle wear-and-tear reimbursement for all client visits 401k with company matching (after 90 days) Virtual lab environment for self-directed learning and experimentation We are an equal opportunity employer. This position is open to local Bay Area candidates only - no relocation benefits are available. Candidates must be authorized to work in the United States.