Job Description Job Description In Person Only interview. This job is Hybrid Mechanicsville, VA 23116 Our direct client has an opening for an Senior Network Security Engineer (807471). This position is up to 12 months, with the option of extension, 9120 Lockwood Boulevard Mechanicsville, VA 23116. Please send rates and a resume. Corp to Corp or w2 allowed. Requirements: Enterprise Networking - Required 8 Years. Enterprise Security - Required 5 Years. Azure Networking - Required 3 Years. WAF/NGFW - Required 3 Years. Supporting environments with 300+ Network Devices - Desired 3 Years. Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor - Required. Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) - Required. Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def - Required. Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates - Required. Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles - Required. Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS - Required. Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP - Required. Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages - Required. Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers - Required. Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700) - Required.
09/24/2026
Full time
Job Description Job Description In Person Only interview. This job is Hybrid Mechanicsville, VA 23116 Our direct client has an opening for an Senior Network Security Engineer (807471). This position is up to 12 months, with the option of extension, 9120 Lockwood Boulevard Mechanicsville, VA 23116. Please send rates and a resume. Corp to Corp or w2 allowed. Requirements: Enterprise Networking - Required 8 Years. Enterprise Security - Required 5 Years. Azure Networking - Required 3 Years. WAF/NGFW - Required 3 Years. Supporting environments with 300+ Network Devices - Desired 3 Years. Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor - Required. Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) - Required. Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def - Required. Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates - Required. Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles - Required. Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS - Required. Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP - Required. Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages - Required. Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers - Required. Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700) - Required.
Solution Architect / Principal Consultant (NW / DC / Security) DETAILS Location: Remote Position Type: 6M+ Contract (w/ likely extensions) Hourly / Salary: to $90W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Solution Architect / Principal Engineer for a 6M+ Contract (w/ likely extensions) that is remote. The Solution Architect / Principal Engineer will lead the design and delivery of enterprise-scale network and security solutions for a large Fortune 10 environment. The Solution Architect / Principal Engineer will own technical strategy across data center, WAN/LAN, cloud, and hybrid infrastructures, guiding multiple concurrent initiatives while ensuring solutions align with business objectives, security standards, and enterprise architecture requirements. The Solution Architect / Principal Engineer will serve as the technical leader and escalation point for complex networking and security challenges, driving architecture decisions, overseeing engineering teams, and providing governance from design through deployment. The ideal Solution Architect / Principal Engineer will possess deep networking expertise, broad cross-domain architecture knowledge, and the ability to influence stakeholders while delivering large-scale transformation and modernization initiatives. Enterprise Network / Security Architecture - Leading Design of Scalable / Resilient / Secure Infrastructure Solutions Across Data Center / Campus / Cloud / Hybrid Environments Aligning with Long-Term Business / Technology Strategies Technical Leadership / Solution Governance - Providing Architectural Oversight Across Multiple Concurrent Initiatives via Design Standards / Technical Validation / Governance of Solution Delivery Stakeholder Engagement / Solution Alignment - Partnering with Infrastructure / Security / Cloud / Business Teams Translating Complex Requirements into Actionable Technical Solutions Building Consensus Across Technical / Executive Stakeholders Engineering Leadership / Mentorship - Guiding / Mentoring Network / Security Engineers via Delegation / Technical Reviews / Quality Assurance and Adherence to Architectural Standards Architecture Documentation / Design Reviews - Developing / Presenting High-Level / Detailed Solution Designs / Technical Roadmaps / Implementation Plans Leading Architecture Reviews / Executive Briefings Strategic Advisory / Escalation Leadership - Serving as Senior Escalation Point for Complex Infrastructure / Security Challenges via Risk Identification / Strategic Recommendations / Enterprise Technology Leadership JOB REQUIREMENTS Enterprise Infrastructure / Architecture Experience (9+ years) - Enterprise Infrastructure Experience Network Architect / Security Architect / Solution Architect / Principal Consultant (5+ years) Enterprise Network Architecture (expertise) - Designing / Implementing Enterprise Networking Solutions Across Data Center / Campus / WAN / LAN / SD-WAN / Hybrid Cloud Environments Network Security Architecture (strong architecture-level knowledge) - Next-Generation Firewalls / Network Segmentation / Zero Trust / Identity Integration / Security Policy Governance Architecture Documentation / Executive Advisory - Developing / Presenting High-Level Designs (HLDs) / Low-Level Designs (LLDs) / Technical Roadmaps / Executive Architecture Recommendations Program Leadership / Multi-Project Management - Leading Multiple Large-Scale Infrastructure / Security Initiatives Simultaneously Managing Priorities / Dependencies / Risks / Stakeholder Expectations Enterprise Networking Technologies (hands-on) - Industry-Leading Networking Platforms (Cisco / Arista / Palo Alto and Similar Technologies) Cloud Networking / Security - Applying Strong Understanding of Cloud Networking and Security Principles Across AWS / Azure / Hybrid Cloud Environments Technical Leadership / Governance - Providing Design Oversight / Mentorship / Implementation Governance / Quality Assurance for Engineering Teams Senior Escalation / Strategic Problem Solving - Serving as Senior Escalation Point for Complex Network / Security / Infrastructure Challenges Within Large Enterprise Environments Executive Communication / Influence - Excellent Communication / Presentation Skills Influencing Technical Teams / Business Stakeholders / Executive Leadership Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
09/24/2026
Full time
Solution Architect / Principal Consultant (NW / DC / Security) DETAILS Location: Remote Position Type: 6M+ Contract (w/ likely extensions) Hourly / Salary: to $90W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Solution Architect / Principal Engineer for a 6M+ Contract (w/ likely extensions) that is remote. The Solution Architect / Principal Engineer will lead the design and delivery of enterprise-scale network and security solutions for a large Fortune 10 environment. The Solution Architect / Principal Engineer will own technical strategy across data center, WAN/LAN, cloud, and hybrid infrastructures, guiding multiple concurrent initiatives while ensuring solutions align with business objectives, security standards, and enterprise architecture requirements. The Solution Architect / Principal Engineer will serve as the technical leader and escalation point for complex networking and security challenges, driving architecture decisions, overseeing engineering teams, and providing governance from design through deployment. The ideal Solution Architect / Principal Engineer will possess deep networking expertise, broad cross-domain architecture knowledge, and the ability to influence stakeholders while delivering large-scale transformation and modernization initiatives. Enterprise Network / Security Architecture - Leading Design of Scalable / Resilient / Secure Infrastructure Solutions Across Data Center / Campus / Cloud / Hybrid Environments Aligning with Long-Term Business / Technology Strategies Technical Leadership / Solution Governance - Providing Architectural Oversight Across Multiple Concurrent Initiatives via Design Standards / Technical Validation / Governance of Solution Delivery Stakeholder Engagement / Solution Alignment - Partnering with Infrastructure / Security / Cloud / Business Teams Translating Complex Requirements into Actionable Technical Solutions Building Consensus Across Technical / Executive Stakeholders Engineering Leadership / Mentorship - Guiding / Mentoring Network / Security Engineers via Delegation / Technical Reviews / Quality Assurance and Adherence to Architectural Standards Architecture Documentation / Design Reviews - Developing / Presenting High-Level / Detailed Solution Designs / Technical Roadmaps / Implementation Plans Leading Architecture Reviews / Executive Briefings Strategic Advisory / Escalation Leadership - Serving as Senior Escalation Point for Complex Infrastructure / Security Challenges via Risk Identification / Strategic Recommendations / Enterprise Technology Leadership JOB REQUIREMENTS Enterprise Infrastructure / Architecture Experience (9+ years) - Enterprise Infrastructure Experience Network Architect / Security Architect / Solution Architect / Principal Consultant (5+ years) Enterprise Network Architecture (expertise) - Designing / Implementing Enterprise Networking Solutions Across Data Center / Campus / WAN / LAN / SD-WAN / Hybrid Cloud Environments Network Security Architecture (strong architecture-level knowledge) - Next-Generation Firewalls / Network Segmentation / Zero Trust / Identity Integration / Security Policy Governance Architecture Documentation / Executive Advisory - Developing / Presenting High-Level Designs (HLDs) / Low-Level Designs (LLDs) / Technical Roadmaps / Executive Architecture Recommendations Program Leadership / Multi-Project Management - Leading Multiple Large-Scale Infrastructure / Security Initiatives Simultaneously Managing Priorities / Dependencies / Risks / Stakeholder Expectations Enterprise Networking Technologies (hands-on) - Industry-Leading Networking Platforms (Cisco / Arista / Palo Alto and Similar Technologies) Cloud Networking / Security - Applying Strong Understanding of Cloud Networking and Security Principles Across AWS / Azure / Hybrid Cloud Environments Technical Leadership / Governance - Providing Design Oversight / Mentorship / Implementation Governance / Quality Assurance for Engineering Teams Senior Escalation / Strategic Problem Solving - Serving as Senior Escalation Point for Complex Network / Security / Infrastructure Challenges Within Large Enterprise Environments Executive Communication / Influence - Excellent Communication / Presentation Skills Influencing Technical Teams / Business Stakeholders / Executive Leadership Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
09/24/2026
Full time
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
09/24/2026
Full time
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/24/2026
Full time
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
09/24/2026
Full time
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct hire opportunity. Hybrid schedule with potential for fully remote if the hired candidate doesn't live within a reasonable commute of the data center. Compensation is competitive including: base, bonus, equity, 401k, unlimited pto, tuition reimbursement and much more! Role: The Network Security Engineer will help identify, research and evaluate security solutions and emerging technologies that align with the company's strategic direction. This person should have a strong knowledge of security, including HTTP compliance, application level security, and end-point protections. The engineer will be tasked with deploying new security technologies as well as maintaining current security infrastructure. A strong troubleshooting background is needed, as well as knowledge in APIs. Candidates should also have a strong ability to interface with other parts of the business and be able to coordinate work with multiple teams. Skills: Network routing and switching Firewall concepts and functions WAF and IPS F5: ASM, DNS, APM, AFM. Knowledge of iRules. Proxy and user access VPN access, both site-to-site and end user. GSLB, and server load balancing TLS knowledge and experience Knowledge of HTTP protocol Tier 3 operational support Preferred Experience: Routing: BGP, OSPF and EIGRP Firewall: ASA, PaloAlto and Juniper SRX Router and Switch: Cisco CCNP level knowledge Experience in reverse proxy solutions (Kemp/NGINX/HA Proxy) Experience in user proxy technologies Experience with Cloud Based DDoS and WAF solutions. Experience with NAC implementations (ClearPass, ISE) Familiarity with REST APIs and automation Anticipated base salary in the 150-180k range, + bonus
09/24/2026
Full time
Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct hire opportunity. Hybrid schedule with potential for fully remote if the hired candidate doesn't live within a reasonable commute of the data center. Compensation is competitive including: base, bonus, equity, 401k, unlimited pto, tuition reimbursement and much more! Role: The Network Security Engineer will help identify, research and evaluate security solutions and emerging technologies that align with the company's strategic direction. This person should have a strong knowledge of security, including HTTP compliance, application level security, and end-point protections. The engineer will be tasked with deploying new security technologies as well as maintaining current security infrastructure. A strong troubleshooting background is needed, as well as knowledge in APIs. Candidates should also have a strong ability to interface with other parts of the business and be able to coordinate work with multiple teams. Skills: Network routing and switching Firewall concepts and functions WAF and IPS F5: ASM, DNS, APM, AFM. Knowledge of iRules. Proxy and user access VPN access, both site-to-site and end user. GSLB, and server load balancing TLS knowledge and experience Knowledge of HTTP protocol Tier 3 operational support Preferred Experience: Routing: BGP, OSPF and EIGRP Firewall: ASA, PaloAlto and Juniper SRX Router and Switch: Cisco CCNP level knowledge Experience in reverse proxy solutions (Kemp/NGINX/HA Proxy) Experience in user proxy technologies Experience with Cloud Based DDoS and WAF solutions. Experience with NAC implementations (ClearPass, ISE) Familiarity with REST APIs and automation Anticipated base salary in the 150-180k range, + bonus
Job Description Job Description In Person Only interview. This job is Hybrid Mechanicsville, VA 23116 Our direct client has an opening for an Senior Network Security Engineer (807471) This position is up to 12 months, with the option of extension, 9120 Lockwood Boulevard Mechanicsville, VA 23116 Please send rates and a resume. Corp to Corp or w2 allowed. Enterprise Networking Required 8 Years Enterprise Security Required 5 Years Azure Networking Required 3 Years WAF/NGFW Required 3 Years Supporting environments with 300+ Network Devices Desired 3 Years Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor Required Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) Required Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def Required Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates Required Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles Required Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS Required Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP Required Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages Required Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers. Required Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), Required
09/24/2026
Full time
Job Description Job Description In Person Only interview. This job is Hybrid Mechanicsville, VA 23116 Our direct client has an opening for an Senior Network Security Engineer (807471) This position is up to 12 months, with the option of extension, 9120 Lockwood Boulevard Mechanicsville, VA 23116 Please send rates and a resume. Corp to Corp or w2 allowed. Enterprise Networking Required 8 Years Enterprise Security Required 5 Years Azure Networking Required 3 Years WAF/NGFW Required 3 Years Supporting environments with 300+ Network Devices Desired 3 Years Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor Required Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) Required Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def Required Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates Required Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles Required Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS Required Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP Required Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages Required Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers. Required Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), Required
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
09/24/2026
Full time
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/24/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a seasoned Senior Network Security Engineer to join our dynamic security team. The ideal candidate will possess deep expertise in network security technologies, focusing on switching and routing systems within cloud-native and AI-focused infrastructure. You will thrive in a fast-paced, challenging environment, demonstrating adaptability, excellent multitasking skills, and the drive to tackle complex security issues independently while ensuring robust protection for our innovative technologies. RESPONSIBILITIES: Serve as a subject matter expert in network security, particularly firewalls, VPNs, IDS/IPS, routing protocols (e.g., BGP, OSPF), and switching technologies. Manage and update firewall configurations across our enterprise network to align with operational and security needs. Deploy new firewalls, switches, routers, and network security devices in response to evolving threats and demands. Develop and propose innovative network security solutions to address operational challenges in routing and switching environments. Enhance security processes through thorough documentation and change management. Act as the primary resolver for complex network security issues, including escalation support. Ensure network security systems, switches, and routers are up-to-date with patches, firmware, and maintenance. Monitor and respond to security events in cloud environments (e.g., AWS, GCP, Azure, Datacenter), with emphasis on network traffic analysis. BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. 4+ years of experience in network security engineering, with hands-on focus on switching and routing. Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred. Strong understanding of network security principles, protocols (e.g., TCP/IP, VLANs, ACLs), and best practices for secure routing and switching. Proficiency in at least one major cloud platform (AWS, GCP, or Azure) and its network security services (e.g., VPCs, Security Groups). Experience with network analysis tools such as Wireshark, tcpdump; and vendors including Cisco, Juniper, Palo Alto Networks. Familiarity with scripting languages (e.g., Python, Bash) for automation of network security tasks. PREFERRED SKILLS AND EXPERIENCE: Relevant network-specific certifications (e.g., CCNP Security, CCIE Security, JNCIP-SEC, PCNSE). Experience in multi-cloud environments and Infrastructure as Code tools like Terraform for network provisioning. Knowledge of DevSecOps practices tailored to network security integration. Experience building custom tools or integrations for enhancing network security operations. Interest in leveraging AI for network threat detection and automation. Contributions to open-source projects in network security or related tools. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
09/24/2026
Full time
Job Description Job Description SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a seasoned Senior Network Security Engineer to join our dynamic security team. The ideal candidate will possess deep expertise in network security technologies, focusing on switching and routing systems within cloud-native and AI-focused infrastructure. You will thrive in a fast-paced, challenging environment, demonstrating adaptability, excellent multitasking skills, and the drive to tackle complex security issues independently while ensuring robust protection for our innovative technologies. RESPONSIBILITIES: Serve as a subject matter expert in network security, particularly firewalls, VPNs, IDS/IPS, routing protocols (e.g., BGP, OSPF), and switching technologies. Manage and update firewall configurations across our enterprise network to align with operational and security needs. Deploy new firewalls, switches, routers, and network security devices in response to evolving threats and demands. Develop and propose innovative network security solutions to address operational challenges in routing and switching environments. Enhance security processes through thorough documentation and change management. Act as the primary resolver for complex network security issues, including escalation support. Ensure network security systems, switches, and routers are up-to-date with patches, firmware, and maintenance. Monitor and respond to security events in cloud environments (e.g., AWS, GCP, Azure, Datacenter), with emphasis on network traffic analysis. BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. 4+ years of experience in network security engineering, with hands-on focus on switching and routing. Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred. Strong understanding of network security principles, protocols (e.g., TCP/IP, VLANs, ACLs), and best practices for secure routing and switching. Proficiency in at least one major cloud platform (AWS, GCP, or Azure) and its network security services (e.g., VPCs, Security Groups). Experience with network analysis tools such as Wireshark, tcpdump; and vendors including Cisco, Juniper, Palo Alto Networks. Familiarity with scripting languages (e.g., Python, Bash) for automation of network security tasks. PREFERRED SKILLS AND EXPERIENCE: Relevant network-specific certifications (e.g., CCNP Security, CCIE Security, JNCIP-SEC, PCNSE). Experience in multi-cloud environments and Infrastructure as Code tools like Terraform for network provisioning. Knowledge of DevSecOps practices tailored to network security integration. Experience building custom tools or integrations for enhancing network security operations. Interest in leveraging AI for network threat detection and automation. Contributions to open-source projects in network security or related tools. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Job Description Job Description Senior Network Security Engineer Type: Staff Augmentation (W2 employee of Innovation Consulting) Location: San Jose, CA (Onsite - Monday through Friday, 8:30 AM-5:00 PM PST) Estimated Duration: Approximately 6 months (August 2026 - February 2027) Salary: $225K - $270K per year, DOE About the Role Innovation Consulting LLC is partnered with California's largest investor-owned water utility to recruit a Senior Network Security Engineer for a six-month onsite engagement in San Jose, CA, running from August 2026 through February 2027. This network security engineer role supports the design, configuration, and implementation of Zero Trust networking, starting with VPN access using Palo Alto Networks technologies. The position advances the organization's Zero Trust Architecture (ZTA) initiatives, strengthens network security controls across on-premises and cloud environments, improves network visibility and access management, and supports infrastructure modernization. The ideal candidate is a hands-on, security-focused network security engineer comfortable working closely with cybersecurity and infrastructure teams in a regulated, audit-conscious environment. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client for the duration of the contract. Key Responsibilities Zero Trust & VPN Engineering • Design and configure Palo Alto Networks VPN solutions to support Zero Trust principles • Implement least-privilege VPN access so users can reach only the systems required for their role • Define and enforce user- and group-based access policies rather than broad network access • Partner with cybersecurity leadership to align VPN controls with Zero Trust strategy Network Security & Visibility • Support network segmentation and secure access to sensitive systems, including admin and infrastructure services • Ensure configurations are fully auditable and defensible for future compliance reviews • Apply cloud networking security, segmentation, and access controls Forensics & Access Context • Use AlienVault and Palo Alto to analyze VPN traffic and user activity and identify systems and applications accessed by approximately 100 VPN users for this engagement • Support forensic investigations related to VPN access • Build a VPN access context from traffic analysis and assign users to the correct VPN groups as part of the Zero Trust initiative Collaboration & Communication • Work closely with the IT Architecture and Cybersecurity teams • Clearly communicate technical findings, access models, and design decisions • Participate in design reviews, scoping discussions, and implementation planning Work Model and On-Site Requirements • Fully onsite in San Jose, CA - this position is not eligible for remote work • Standard business hours: 8:30 AM - 5:00 PM PST, Monday through Friday • Relocation required if not within commutable distance of San Jose, CA Qualifications Required • U.S. Citizenship required • Ability to work onsite in San Jose, CA • Senior-level experience in network security engineering • Strong hands-on experience with Palo Alto Networks firewalls and VPN • Demonstrated understanding of Zero Trust networking concepts • Experience implementing identity-based and role-based access controls • Hands-on experience using SIEM (AlienVault preferred) for logging, analysis, and forensic investigations • Strong troubleshooting and analytical skills, with the ability to communicate effectively with highly technical teams Preferred • Experience in regulated, audit-conscious environments (e.g., utilities / critical infrastructure) • Palo Alto Networks Certified Network Security Administrator (PCNSA) or Palo Alto Networks Certified Network Security Engineer (PCNSE) certification • Familiarity with SASE and cloud-delivered Zero Trust access Compensation & Employment Employment Type: Staff Augmentation. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client. Salary: $225K - $270K per year, DOE. Contract Duration: Approximately 6 months (August 2026 - February 2027). Benefits: Comprehensive benefits package including medical, dental, and vision, 401(k) with safe-harbor matching, HRA, and PTO. No waiting period - benefits are available immediately and accrual items begin accruing immediately. Innovation Consulting LLC is an equal opportunity employer and recruiter. We review candidates without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other protected characteristic.
09/24/2026
Full time
Job Description Job Description Senior Network Security Engineer Type: Staff Augmentation (W2 employee of Innovation Consulting) Location: San Jose, CA (Onsite - Monday through Friday, 8:30 AM-5:00 PM PST) Estimated Duration: Approximately 6 months (August 2026 - February 2027) Salary: $225K - $270K per year, DOE About the Role Innovation Consulting LLC is partnered with California's largest investor-owned water utility to recruit a Senior Network Security Engineer for a six-month onsite engagement in San Jose, CA, running from August 2026 through February 2027. This network security engineer role supports the design, configuration, and implementation of Zero Trust networking, starting with VPN access using Palo Alto Networks technologies. The position advances the organization's Zero Trust Architecture (ZTA) initiatives, strengthens network security controls across on-premises and cloud environments, improves network visibility and access management, and supports infrastructure modernization. The ideal candidate is a hands-on, security-focused network security engineer comfortable working closely with cybersecurity and infrastructure teams in a regulated, audit-conscious environment. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client for the duration of the contract. Key Responsibilities Zero Trust & VPN Engineering • Design and configure Palo Alto Networks VPN solutions to support Zero Trust principles • Implement least-privilege VPN access so users can reach only the systems required for their role • Define and enforce user- and group-based access policies rather than broad network access • Partner with cybersecurity leadership to align VPN controls with Zero Trust strategy Network Security & Visibility • Support network segmentation and secure access to sensitive systems, including admin and infrastructure services • Ensure configurations are fully auditable and defensible for future compliance reviews • Apply cloud networking security, segmentation, and access controls Forensics & Access Context • Use AlienVault and Palo Alto to analyze VPN traffic and user activity and identify systems and applications accessed by approximately 100 VPN users for this engagement • Support forensic investigations related to VPN access • Build a VPN access context from traffic analysis and assign users to the correct VPN groups as part of the Zero Trust initiative Collaboration & Communication • Work closely with the IT Architecture and Cybersecurity teams • Clearly communicate technical findings, access models, and design decisions • Participate in design reviews, scoping discussions, and implementation planning Work Model and On-Site Requirements • Fully onsite in San Jose, CA - this position is not eligible for remote work • Standard business hours: 8:30 AM - 5:00 PM PST, Monday through Friday • Relocation required if not within commutable distance of San Jose, CA Qualifications Required • U.S. Citizenship required • Ability to work onsite in San Jose, CA • Senior-level experience in network security engineering • Strong hands-on experience with Palo Alto Networks firewalls and VPN • Demonstrated understanding of Zero Trust networking concepts • Experience implementing identity-based and role-based access controls • Hands-on experience using SIEM (AlienVault preferred) for logging, analysis, and forensic investigations • Strong troubleshooting and analytical skills, with the ability to communicate effectively with highly technical teams Preferred • Experience in regulated, audit-conscious environments (e.g., utilities / critical infrastructure) • Palo Alto Networks Certified Network Security Administrator (PCNSA) or Palo Alto Networks Certified Network Security Engineer (PCNSE) certification • Familiarity with SASE and cloud-delivered Zero Trust access Compensation & Employment Employment Type: Staff Augmentation. As a W2 employee of Innovation Consulting, you will be placed on assignment with our client. Salary: $225K - $270K per year, DOE. Contract Duration: Approximately 6 months (August 2026 - February 2027). Benefits: Comprehensive benefits package including medical, dental, and vision, 401(k) with safe-harbor matching, HRA, and PTO. No waiting period - benefits are available immediately and accrual items begin accruing immediately. Innovation Consulting LLC is an equal opportunity employer and recruiter. We review candidates without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other protected characteristic.
Job Description Job Description Tier III NOC Technician Washington, DC - metro accessible, 4 days onsite, 1 day remote Perm position, full benefits package, $120K, perhaps some flex depending on experience and certs MUST HAVE ONE OR MORE HIGH LEVEL CERTIFICAITON: CCNP, CCNP Security, JNCIP, or equivalent RESPONSIBILITIES Serve as the final escalation point for complex Tier 1 and Tier 2 incidents requiring advanced technical expertise Lead troubleshooting and resolution of critical network outages, performance degradation, and complex technical issues Perform root cause analysis on major incidents and develop preventive measures to avoid recurrence Provide technical leadership and guidance to junior NOC technicians during critical incidents Design and implement solutions for network optimization, automation, and performance improvements Conduct in-depth packet analysis and protocol troubleshooting to diagnose complex connectivity issues Configure and troubleshoot advanced network devices including core routers, multilayer switches, firewalls, and load balancers Participate in and lead Major Incident Management calls with stakeholders and executive leadership Develop, maintain, and improve NOC procedures, runbooks, and technical documentation Perform advanced network and system performance analysis using multiple monitoring and diagnostic tools Collaborate with Network Engineering, Security, and Systems Administration teams on complex cross-functional issues Evaluate and recommend improvements to network architecture, monitoring capabilities, and operational processes Mentor and train Tier 1 and Tier 2 technicians on troubleshooting techniques and best practices Participate in change advisory board (CAB) reviews and provide technical assessments of proposed changes Execute complex network changes during maintenance windows with minimal service disruption Monitor and optimize network capacity, bandwidth utilization, and traffic patterns Coordinate with vendors and external service providers to resolve carrier and equipment issues Develop and maintain disaster recovery procedures and participate in failover testing Implement network security measures and respond to security incidents in coordination with security teams Create and present technical reports on network performance, incidents, and trends to management Participate in on-call rotation as the senior technical escalation resource Stay current with emerging technologies and industry best practices to continuously improve operations REQUIREMENTS Bachelor's degree OR equivalent experience 7+ years of experience in network operations, network engineering, or systems administration 5+ years of experience working in a 7x24x365 NOC or similar mission-critical environment Demonstrated experience as a senior escalation point for complex technical issues Supporting large-scale enterprise networks with thousands of users Expert-level knowledge of network protocols, routing, and switching (BGP, OSPF, EIGRP, MPLS, spanning-tree, VLAN) Advanced troubleshooting skills using packet analysis tools (Wireshark, tcpdump) Deep understanding of network security technologies including firewalls, IDS/IPS, VPN, and NAT Extensive experience with enterprise network equipment from multiple vendors (Cisco, Juniper, Palo Alto, Arista, F5) Proficiency with network monitoring and management platforms (SolarWinds, Nagios, Splunk, NetFlow/sFlow analysis) Knowledge of TCP/IP stack, network services (DNS, DHCP, NTP), and application protocols Expertise in load balancing, traffic engineering, and high-availability architectures Strong understanding of data center networking, fabric technologies, and virtualization Routing policy implementation and traffic optimization techniques Advanced troubleshooting skills across multiple technology domains (network, systems, applications, security) Ability to interpret network diagrams, technical specifications, and vendor documentation Strong analytical and critical thinking skills for solving complex problems under pressure Leadership and mentoring skills for guiding junior team members Excellent written and verbal communication skills across stakeholder levels Proven incident management ability, including leading bridge calls and coordinating resources during major incidents Proficiency with scripting and automation tools (Python, Ansible, PowerShell, Bash) Deep understanding of ITIL framework (Incident, Problem, Change Management) Knowledge of cloud networking architectures (AWS, Azure, GCP) and DevOps practices Ability to work effectively under extreme pressure and make rapid technical decisions Flexibility to work rotating shifts including nights, weekends, and holidays Strong documentation skills and commitment to accurate technical records Company Description System One is a leading provider of specialized, highly technical services and solutions to critical infrastructure, technology, life sciences, and government sectors. We partner with large private and public organizations who trust us to execute their complex, mission-critical initiatives through our outsourced services and workforce solutions. Company Description System One is a leading provider of specialized, highly technical services and solutions to critical infrastructure, technology, life sciences, and government sectors. We partner with large private and public organizations who trust us to execute their complex, mission-critical initiatives through our outsourced services and workforce solutions.
09/24/2026
Full time
Job Description Job Description Tier III NOC Technician Washington, DC - metro accessible, 4 days onsite, 1 day remote Perm position, full benefits package, $120K, perhaps some flex depending on experience and certs MUST HAVE ONE OR MORE HIGH LEVEL CERTIFICAITON: CCNP, CCNP Security, JNCIP, or equivalent RESPONSIBILITIES Serve as the final escalation point for complex Tier 1 and Tier 2 incidents requiring advanced technical expertise Lead troubleshooting and resolution of critical network outages, performance degradation, and complex technical issues Perform root cause analysis on major incidents and develop preventive measures to avoid recurrence Provide technical leadership and guidance to junior NOC technicians during critical incidents Design and implement solutions for network optimization, automation, and performance improvements Conduct in-depth packet analysis and protocol troubleshooting to diagnose complex connectivity issues Configure and troubleshoot advanced network devices including core routers, multilayer switches, firewalls, and load balancers Participate in and lead Major Incident Management calls with stakeholders and executive leadership Develop, maintain, and improve NOC procedures, runbooks, and technical documentation Perform advanced network and system performance analysis using multiple monitoring and diagnostic tools Collaborate with Network Engineering, Security, and Systems Administration teams on complex cross-functional issues Evaluate and recommend improvements to network architecture, monitoring capabilities, and operational processes Mentor and train Tier 1 and Tier 2 technicians on troubleshooting techniques and best practices Participate in change advisory board (CAB) reviews and provide technical assessments of proposed changes Execute complex network changes during maintenance windows with minimal service disruption Monitor and optimize network capacity, bandwidth utilization, and traffic patterns Coordinate with vendors and external service providers to resolve carrier and equipment issues Develop and maintain disaster recovery procedures and participate in failover testing Implement network security measures and respond to security incidents in coordination with security teams Create and present technical reports on network performance, incidents, and trends to management Participate in on-call rotation as the senior technical escalation resource Stay current with emerging technologies and industry best practices to continuously improve operations REQUIREMENTS Bachelor's degree OR equivalent experience 7+ years of experience in network operations, network engineering, or systems administration 5+ years of experience working in a 7x24x365 NOC or similar mission-critical environment Demonstrated experience as a senior escalation point for complex technical issues Supporting large-scale enterprise networks with thousands of users Expert-level knowledge of network protocols, routing, and switching (BGP, OSPF, EIGRP, MPLS, spanning-tree, VLAN) Advanced troubleshooting skills using packet analysis tools (Wireshark, tcpdump) Deep understanding of network security technologies including firewalls, IDS/IPS, VPN, and NAT Extensive experience with enterprise network equipment from multiple vendors (Cisco, Juniper, Palo Alto, Arista, F5) Proficiency with network monitoring and management platforms (SolarWinds, Nagios, Splunk, NetFlow/sFlow analysis) Knowledge of TCP/IP stack, network services (DNS, DHCP, NTP), and application protocols Expertise in load balancing, traffic engineering, and high-availability architectures Strong understanding of data center networking, fabric technologies, and virtualization Routing policy implementation and traffic optimization techniques Advanced troubleshooting skills across multiple technology domains (network, systems, applications, security) Ability to interpret network diagrams, technical specifications, and vendor documentation Strong analytical and critical thinking skills for solving complex problems under pressure Leadership and mentoring skills for guiding junior team members Excellent written and verbal communication skills across stakeholder levels Proven incident management ability, including leading bridge calls and coordinating resources during major incidents Proficiency with scripting and automation tools (Python, Ansible, PowerShell, Bash) Deep understanding of ITIL framework (Incident, Problem, Change Management) Knowledge of cloud networking architectures (AWS, Azure, GCP) and DevOps practices Ability to work effectively under extreme pressure and make rapid technical decisions Flexibility to work rotating shifts including nights, weekends, and holidays Strong documentation skills and commitment to accurate technical records Company Description System One is a leading provider of specialized, highly technical services and solutions to critical infrastructure, technology, life sciences, and government sectors. We partner with large private and public organizations who trust us to execute their complex, mission-critical initiatives through our outsourced services and workforce solutions. Company Description System One is a leading provider of specialized, highly technical services and solutions to critical infrastructure, technology, life sciences, and government sectors. We partner with large private and public organizations who trust us to execute their complex, mission-critical initiatives through our outsourced services and workforce solutions.