it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

27 jobs found

Email me jobs like this
Refine Search
Current Search
palo alto firewall engineer
Network Security Engineer
MDVIP LLC Boca Raton, Florida
Job Description Job Description Description: MDVIP: Transforming Primary Care, One Patient at a Time MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work since 2018, MDVIP is committed to excellence in patient care and employee satisfaction. Position Summary The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers. This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization's on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations - including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score - while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule. Key Responsibilities Security Remediation & Compliance Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery. Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments. Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere). Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements. Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score. Core Platform & Infrastructure Ownership Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders. Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications. Utilize automation tools to deploy required machine certificates across the organization. Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team's SIEM ingestion, correlation, and compliance reporting needs. Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning. Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks. Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass. Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls. Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices. Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure. Operational Reliability & Risk Reduction Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables. Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions. Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives. Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership. Key Competencies Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data. Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships. Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively. Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared. Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions. Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects. Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours. Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed. Requirements: Qualifications Required Qualifications Bachelor's degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience. Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments. Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent). Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure. Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms). Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings. Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass). This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S. Preferred Qualifications Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification. Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks. Why Join MDVIP? Be part of a mission-driven organization leading innovation in personalized healthcare. Drive transformation and growth in a dynamic, fast-paced environment. Competitive Compensation: Attractive base salary complemented by performance-based incentives. Comprehensive Benefits: Health, dental, vision insurance, and retirement plans. Professional Development: Access to ongoing training and leadership development programs. Positive Work Environment: Consistently recognized as a Great Place to Work , fostering a culture of collaboration and excellence. MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture. If you require accommodations during the application or interview process, please let us know, and we will be happy to assist. Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements . click apply for full job details
09/24/2026
Full time
Job Description Job Description Description: MDVIP: Transforming Primary Care, One Patient at a Time MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work since 2018, MDVIP is committed to excellence in patient care and employee satisfaction. Position Summary The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers. This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization's on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations - including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score - while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule. Key Responsibilities Security Remediation & Compliance Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery. Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments. Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere). Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements. Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score. Core Platform & Infrastructure Ownership Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders. Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications. Utilize automation tools to deploy required machine certificates across the organization. Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team's SIEM ingestion, correlation, and compliance reporting needs. Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning. Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks. Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass. Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls. Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices. Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure. Operational Reliability & Risk Reduction Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables. Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions. Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives. Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership. Key Competencies Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data. Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships. Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively. Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared. Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions. Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects. Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours. Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed. Requirements: Qualifications Required Qualifications Bachelor's degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience. Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments. Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent). Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure. Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms). Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings. Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass). This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S. Preferred Qualifications Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification. Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks. Why Join MDVIP? Be part of a mission-driven organization leading innovation in personalized healthcare. Drive transformation and growth in a dynamic, fast-paced environment. Competitive Compensation: Attractive base salary complemented by performance-based incentives. Comprehensive Benefits: Health, dental, vision insurance, and retirement plans. Professional Development: Access to ongoing training and leadership development programs. Positive Work Environment: Consistently recognized as a Great Place to Work , fostering a culture of collaboration and excellence. MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture. If you require accommodations during the application or interview process, please let us know, and we will be happy to assist. Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements . click apply for full job details
Palo Alto Firewall Engineer
System One Springfield, Virginia
Job Description Job Description Job Title: Palo Alto Firewall Engineer Location: Springfield, VA Type: Contract To Hire Compensation: $80/hr. W2 Benefits available Conversion Salary: $150,000 annually plus benefits Work Model: Onsite Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph Responsibilities Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem. Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment. Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations. Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership. Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements. Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms. Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls. Configure and maintain advanced security capabilities and profiles, including App-ID, User-ID, Content-ID, SSL Decryption, WildFire, NAT, IPSec VPNs, and threat prevention. Oversee security-incident reporting, documentation, investigation, and corrective-action development. Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks. Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security. Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting. Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded. Requirements Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph. A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments. Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE). Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date. Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements. Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud. Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet. Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory. Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues. Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates. Knowledge of DISA and Intelligence Community security standards and requirements. Excellent interpersonal skills and technical judgment with the ability to work independently and support weekend/evening work if needed. Bachelor's degree in IT, Cybersecurity, Computer Science, or a related field, with additional relevant experience considered in lieu of a degree. Desired Qualifications Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE). F5 Networks Certified Technology Specialist (CTS). Cisco CCNP, CCVP, CCNA, CCDP, or equivalent. ITIL v3 Foundations and/or ISC2 CISSP Certification. Proficiency in Python and automation tools such as Ansible, Terraform, or Palo Alto XML/REST APIs. Hands-on experience with Cortex XDR or Cortex XSOAR. Experience with Palo Alto Networks Expedition for migration and rule consolidation. Knowledge of Zero Trust Network Access (ZTNA) architectures and additional security platforms (e.g., Juniper SRX, Cisco FTD/ASA). Master's degree in related fields is a plus. System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law. Ref: Baltimore
09/24/2026
Full time
Job Description Job Description Job Title: Palo Alto Firewall Engineer Location: Springfield, VA Type: Contract To Hire Compensation: $80/hr. W2 Benefits available Conversion Salary: $150,000 annually plus benefits Work Model: Onsite Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph Responsibilities Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem. Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment. Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations. Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership. Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements. Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms. Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls. Configure and maintain advanced security capabilities and profiles, including App-ID, User-ID, Content-ID, SSL Decryption, WildFire, NAT, IPSec VPNs, and threat prevention. Oversee security-incident reporting, documentation, investigation, and corrective-action development. Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks. Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security. Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting. Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded. Requirements Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph. A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments. Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE). Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date. Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements. Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud. Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet. Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory. Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues. Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates. Knowledge of DISA and Intelligence Community security standards and requirements. Excellent interpersonal skills and technical judgment with the ability to work independently and support weekend/evening work if needed. Bachelor's degree in IT, Cybersecurity, Computer Science, or a related field, with additional relevant experience considered in lieu of a degree. Desired Qualifications Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE). F5 Networks Certified Technology Specialist (CTS). Cisco CCNP, CCVP, CCNA, CCDP, or equivalent. ITIL v3 Foundations and/or ISC2 CISSP Certification. Proficiency in Python and automation tools such as Ansible, Terraform, or Palo Alto XML/REST APIs. Hands-on experience with Cortex XDR or Cortex XSOAR. Experience with Palo Alto Networks Expedition for migration and rule consolidation. Knowledge of Zero Trust Network Access (ZTNA) architectures and additional security platforms (e.g., Juniper SRX, Cisco FTD/ASA). Master's degree in related fields is a plus. System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law. Ref: Baltimore
Solution Architect / Principal Consultant (NW / DC / Security)
Vaco LLC Addison, Texas
Solution Architect / Principal Consultant (NW / DC / Security) DETAILS Location: Remote Position Type: 6M+ Contract (w/ likely extensions) Hourly / Salary: to $90W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Solution Architect / Principal Engineer for a 6M+ Contract (w/ likely extensions) that is remote. The Solution Architect / Principal Engineer will lead the design and delivery of enterprise-scale network and security solutions for a large Fortune 10 environment. The Solution Architect / Principal Engineer will own technical strategy across data center, WAN/LAN, cloud, and hybrid infrastructures, guiding multiple concurrent initiatives while ensuring solutions align with business objectives, security standards, and enterprise architecture requirements. The Solution Architect / Principal Engineer will serve as the technical leader and escalation point for complex networking and security challenges, driving architecture decisions, overseeing engineering teams, and providing governance from design through deployment. The ideal Solution Architect / Principal Engineer will possess deep networking expertise, broad cross-domain architecture knowledge, and the ability to influence stakeholders while delivering large-scale transformation and modernization initiatives. Enterprise Network / Security Architecture - Leading Design of Scalable / Resilient / Secure Infrastructure Solutions Across Data Center / Campus / Cloud / Hybrid Environments Aligning with Long-Term Business / Technology Strategies Technical Leadership / Solution Governance - Providing Architectural Oversight Across Multiple Concurrent Initiatives via Design Standards / Technical Validation / Governance of Solution Delivery Stakeholder Engagement / Solution Alignment - Partnering with Infrastructure / Security / Cloud / Business Teams Translating Complex Requirements into Actionable Technical Solutions Building Consensus Across Technical / Executive Stakeholders Engineering Leadership / Mentorship - Guiding / Mentoring Network / Security Engineers via Delegation / Technical Reviews / Quality Assurance and Adherence to Architectural Standards Architecture Documentation / Design Reviews - Developing / Presenting High-Level / Detailed Solution Designs / Technical Roadmaps / Implementation Plans Leading Architecture Reviews / Executive Briefings Strategic Advisory / Escalation Leadership - Serving as Senior Escalation Point for Complex Infrastructure / Security Challenges via Risk Identification / Strategic Recommendations / Enterprise Technology Leadership JOB REQUIREMENTS Enterprise Infrastructure / Architecture Experience (9+ years) - Enterprise Infrastructure Experience Network Architect / Security Architect / Solution Architect / Principal Consultant (5+ years) Enterprise Network Architecture (expertise) - Designing / Implementing Enterprise Networking Solutions Across Data Center / Campus / WAN / LAN / SD-WAN / Hybrid Cloud Environments Network Security Architecture (strong architecture-level knowledge) - Next-Generation Firewalls / Network Segmentation / Zero Trust / Identity Integration / Security Policy Governance Architecture Documentation / Executive Advisory - Developing / Presenting High-Level Designs (HLDs) / Low-Level Designs (LLDs) / Technical Roadmaps / Executive Architecture Recommendations Program Leadership / Multi-Project Management - Leading Multiple Large-Scale Infrastructure / Security Initiatives Simultaneously Managing Priorities / Dependencies / Risks / Stakeholder Expectations Enterprise Networking Technologies (hands-on) - Industry-Leading Networking Platforms (Cisco / Arista / Palo Alto and Similar Technologies) Cloud Networking / Security - Applying Strong Understanding of Cloud Networking and Security Principles Across AWS / Azure / Hybrid Cloud Environments Technical Leadership / Governance - Providing Design Oversight / Mentorship / Implementation Governance / Quality Assurance for Engineering Teams Senior Escalation / Strategic Problem Solving - Serving as Senior Escalation Point for Complex Network / Security / Infrastructure Challenges Within Large Enterprise Environments Executive Communication / Influence - Excellent Communication / Presentation Skills Influencing Technical Teams / Business Stakeholders / Executive Leadership Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
09/24/2026
Full time
Solution Architect / Principal Consultant (NW / DC / Security) DETAILS Location: Remote Position Type: 6M+ Contract (w/ likely extensions) Hourly / Salary: to $90W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Solution Architect / Principal Engineer for a 6M+ Contract (w/ likely extensions) that is remote. The Solution Architect / Principal Engineer will lead the design and delivery of enterprise-scale network and security solutions for a large Fortune 10 environment. The Solution Architect / Principal Engineer will own technical strategy across data center, WAN/LAN, cloud, and hybrid infrastructures, guiding multiple concurrent initiatives while ensuring solutions align with business objectives, security standards, and enterprise architecture requirements. The Solution Architect / Principal Engineer will serve as the technical leader and escalation point for complex networking and security challenges, driving architecture decisions, overseeing engineering teams, and providing governance from design through deployment. The ideal Solution Architect / Principal Engineer will possess deep networking expertise, broad cross-domain architecture knowledge, and the ability to influence stakeholders while delivering large-scale transformation and modernization initiatives. Enterprise Network / Security Architecture - Leading Design of Scalable / Resilient / Secure Infrastructure Solutions Across Data Center / Campus / Cloud / Hybrid Environments Aligning with Long-Term Business / Technology Strategies Technical Leadership / Solution Governance - Providing Architectural Oversight Across Multiple Concurrent Initiatives via Design Standards / Technical Validation / Governance of Solution Delivery Stakeholder Engagement / Solution Alignment - Partnering with Infrastructure / Security / Cloud / Business Teams Translating Complex Requirements into Actionable Technical Solutions Building Consensus Across Technical / Executive Stakeholders Engineering Leadership / Mentorship - Guiding / Mentoring Network / Security Engineers via Delegation / Technical Reviews / Quality Assurance and Adherence to Architectural Standards Architecture Documentation / Design Reviews - Developing / Presenting High-Level / Detailed Solution Designs / Technical Roadmaps / Implementation Plans Leading Architecture Reviews / Executive Briefings Strategic Advisory / Escalation Leadership - Serving as Senior Escalation Point for Complex Infrastructure / Security Challenges via Risk Identification / Strategic Recommendations / Enterprise Technology Leadership JOB REQUIREMENTS Enterprise Infrastructure / Architecture Experience (9+ years) - Enterprise Infrastructure Experience Network Architect / Security Architect / Solution Architect / Principal Consultant (5+ years) Enterprise Network Architecture (expertise) - Designing / Implementing Enterprise Networking Solutions Across Data Center / Campus / WAN / LAN / SD-WAN / Hybrid Cloud Environments Network Security Architecture (strong architecture-level knowledge) - Next-Generation Firewalls / Network Segmentation / Zero Trust / Identity Integration / Security Policy Governance Architecture Documentation / Executive Advisory - Developing / Presenting High-Level Designs (HLDs) / Low-Level Designs (LLDs) / Technical Roadmaps / Executive Architecture Recommendations Program Leadership / Multi-Project Management - Leading Multiple Large-Scale Infrastructure / Security Initiatives Simultaneously Managing Priorities / Dependencies / Risks / Stakeholder Expectations Enterprise Networking Technologies (hands-on) - Industry-Leading Networking Platforms (Cisco / Arista / Palo Alto and Similar Technologies) Cloud Networking / Security - Applying Strong Understanding of Cloud Networking and Security Principles Across AWS / Azure / Hybrid Cloud Environments Technical Leadership / Governance - Providing Design Oversight / Mentorship / Implementation Governance / Quality Assurance for Engineering Teams Senior Escalation / Strategic Problem Solving - Serving as Senior Escalation Point for Complex Network / Security / Infrastructure Challenges Within Large Enterprise Environments Executive Communication / Influence - Excellent Communication / Presentation Skills Influencing Technical Teams / Business Stakeholders / Executive Leadership Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
Associate Network Security Engineer
Eliassen Group Cary, North Carolina
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/24/2026
Full time
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Network & Cybersecurity Systems Engineer
Evolv Technologies Inc. Waltham, Massachusetts
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/24/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Network Security Engineer
SMART TECH SKILLS LLC Reading, Pennsylvania
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
09/24/2026
Full time
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
Network Security Engineer II
Hyundai Autoever America Irvine, California
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/24/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Senior Network Security Engineer
Penumbra Alameda, California
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
09/24/2026
Full time
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
Secret Cleared Lead Palo Alto Firewall Engineer MIDs (11:00pm-7:30am)
Conceras Beltsville, Maryland
Job Description Job Description PALO ALTO FIREWALL ENGINEER Position Description Description This is an opening for a Firewall Engineer/Team Lead to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. Program is named "Vanguard" and is an IT consolidation consisting of the Department's servers, mainframes, network devices, network perimeter, anti-virus engineering, public key infrastructure (PKI)/biometrics/encryption, monitoring tools, telephony, mobile computing platform, virtual environment, and enclave design/security engineering. This is a firewall engineer position within the Vanguard 2025 program, providing general Tier II monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is MIDs (11:00pm-7:30am), Sun-Thurs after training. During the 6-8 week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Along with being a Team Lead for the MID shift. As the Lead you will be expectant to give a turnover of events for the past shift, create weekly Quad Chart, and be able to direct work to other firewall operations staff. Must be able to guide other staff on tasks assigned to the team. Review request for time off and stay in touch with the manager on all events happening on the shift. Monitor Service Now application for Firewall Operations incident and service requests. Implements firewall rules and policies, perform troubleshoots of firewall, email, and Proxy platforms for performance issues. Analyzes network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on perimeter devices. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership daily. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend weekly teleconferences, onsite meetings, and participate in working groups as required. Qualifications Required Education & Experience BA degree and 6 years of experience; may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 5 years IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (StoneGate, Palo Alto, FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 proxy devices). CLI experience preferred. Experienced in utilizing network monitoring tools such as Nagios and NeuralStar. Basic Microsoft Windows Server 2016 implementation and troubleshooting from a security/firewall perspective. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top Secret clearance. Powered by JazzHR ZpLPHj5F0L
09/24/2026
Full time
Job Description Job Description PALO ALTO FIREWALL ENGINEER Position Description Description This is an opening for a Firewall Engineer/Team Lead to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. Program is named "Vanguard" and is an IT consolidation consisting of the Department's servers, mainframes, network devices, network perimeter, anti-virus engineering, public key infrastructure (PKI)/biometrics/encryption, monitoring tools, telephony, mobile computing platform, virtual environment, and enclave design/security engineering. This is a firewall engineer position within the Vanguard 2025 program, providing general Tier II monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is MIDs (11:00pm-7:30am), Sun-Thurs after training. During the 6-8 week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Along with being a Team Lead for the MID shift. As the Lead you will be expectant to give a turnover of events for the past shift, create weekly Quad Chart, and be able to direct work to other firewall operations staff. Must be able to guide other staff on tasks assigned to the team. Review request for time off and stay in touch with the manager on all events happening on the shift. Monitor Service Now application for Firewall Operations incident and service requests. Implements firewall rules and policies, perform troubleshoots of firewall, email, and Proxy platforms for performance issues. Analyzes network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on perimeter devices. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership daily. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend weekly teleconferences, onsite meetings, and participate in working groups as required. Qualifications Required Education & Experience BA degree and 6 years of experience; may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 5 years IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (StoneGate, Palo Alto, FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 proxy devices). CLI experience preferred. Experienced in utilizing network monitoring tools such as Nagios and NeuralStar. Basic Microsoft Windows Server 2016 implementation and troubleshooting from a security/firewall perspective. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top Secret clearance. Powered by JazzHR ZpLPHj5F0L
Firewall Operations Engineer Secret Clearance
Conceras Beltsville, Maryland
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
09/24/2026
Full time
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
Senior Network Security Engineer
Zoox San Mateo, California
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/24/2026
Full time
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Network Security Engineer
Credence Mc Lean, Virginia
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/24/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Senior Network / Firewall Engineer - Houston, TX
Zedcor Security Solutions Houston, Texas
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
09/24/2026
Full time
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
Senior Network Security Engineer
2Bridge Partners Addison, Texas
Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct hire opportunity. Hybrid schedule with potential for fully remote if the hired candidate doesn't live within a reasonable commute of the data center. Compensation is competitive including: base, bonus, equity, 401k, unlimited pto, tuition reimbursement and much more! Role: The Network Security Engineer will help identify, research and evaluate security solutions and emerging technologies that align with the company's strategic direction. This person should have a strong knowledge of security, including HTTP compliance, application level security, and end-point protections. The engineer will be tasked with deploying new security technologies as well as maintaining current security infrastructure. A strong troubleshooting background is needed, as well as knowledge in APIs. Candidates should also have a strong ability to interface with other parts of the business and be able to coordinate work with multiple teams. Skills: Network routing and switching Firewall concepts and functions WAF and IPS F5: ASM, DNS, APM, AFM. Knowledge of iRules. Proxy and user access VPN access, both site-to-site and end user. GSLB, and server load balancing TLS knowledge and experience Knowledge of HTTP protocol Tier 3 operational support Preferred Experience: Routing: BGP, OSPF and EIGRP Firewall: ASA, PaloAlto and Juniper SRX Router and Switch: Cisco CCNP level knowledge Experience in reverse proxy solutions (Kemp/NGINX/HA Proxy) Experience in user proxy technologies Experience with Cloud Based DDoS and WAF solutions. Experience with NAC implementations (ClearPass, ISE) Familiarity with REST APIs and automation Anticipated base salary in the 150-180k range, + bonus
09/24/2026
Full time
Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct hire opportunity. Hybrid schedule with potential for fully remote if the hired candidate doesn't live within a reasonable commute of the data center. Compensation is competitive including: base, bonus, equity, 401k, unlimited pto, tuition reimbursement and much more! Role: The Network Security Engineer will help identify, research and evaluate security solutions and emerging technologies that align with the company's strategic direction. This person should have a strong knowledge of security, including HTTP compliance, application level security, and end-point protections. The engineer will be tasked with deploying new security technologies as well as maintaining current security infrastructure. A strong troubleshooting background is needed, as well as knowledge in APIs. Candidates should also have a strong ability to interface with other parts of the business and be able to coordinate work with multiple teams. Skills: Network routing and switching Firewall concepts and functions WAF and IPS F5: ASM, DNS, APM, AFM. Knowledge of iRules. Proxy and user access VPN access, both site-to-site and end user. GSLB, and server load balancing TLS knowledge and experience Knowledge of HTTP protocol Tier 3 operational support Preferred Experience: Routing: BGP, OSPF and EIGRP Firewall: ASA, PaloAlto and Juniper SRX Router and Switch: Cisco CCNP level knowledge Experience in reverse proxy solutions (Kemp/NGINX/HA Proxy) Experience in user proxy technologies Experience with Cloud Based DDoS and WAF solutions. Experience with NAC implementations (ClearPass, ISE) Familiarity with REST APIs and automation Anticipated base salary in the 150-180k range, + bonus
Lead Firewall Engineer
SITEC Consulting Springfield, Virginia
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
09/24/2026
Full time
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
Senior Network Security Engineer
NPO USA Chicago, Illinois
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
09/24/2026
Full time
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
Network Infrastructure Security Engineer
Select Minds LLC Dallas, Texas
Job Description Job Description Benefits: Onsite Competitive salary Opportunity for advancement About the Role: Select Minds LLC is looking for a talented Network Security Engineer to join our growing team in Dallas, TX. This is an exciting opportunity to protect critical infrastructure, design robust security solutions, and work alongside a team of passionate technology professionals. If you thrive in a fast-paced environment and love solving complex security challenges, we want to hear from you! Responsibilities: Design, implement, and maintain network security architectures, firewalls, and intrusion detection/prevention systems (IDS/IPS) Monitor network traffic for suspicious activity and respond to security incidents and threats in real time Perform vulnerability assessments, penetration testing, and risk analysis across network infrastructure Configure and manage VPNs, access control lists (ACLs), and zero-trust network policies Collaborate with IT and DevOps teams to ensure security best practices are integrated into all systems Develop and maintain security documentation, policies, and incident response procedures Stay current with emerging cybersecurity threats, trends, and compliance requirements (NIST, ISO 27001, etc.) Requirements: 3+ years of experience in network security engineering or a related cybersecurity role Proficiency with firewalls, SIEM tools, and network monitoring platforms (e.g., Cisco, Palo Alto, Splunk) Strong understanding of TCP/IP, DNS, VPN, and network protocols Experience with cloud security environments (AWS, Azure, or GCP) is a plus Relevant certifications such as CISSP, CCNP Security, CEH, or CompTIA Security+ preferred Strong analytical and problem-solving skills with keen attention to detail Excellent communication skills and ability to work both independently and collaboratively About Us: Select Minds LLC is a forward-thinking technology firm based in Dallas, TX, dedicated to delivering innovative IT and security solutions to businesses of all sizes. Our clients trust us to safeguard their most critical assets, and our team takes that responsibility seriously. We foster a culture of continuous learning, collaboration, and growth - making Select Minds a place where talented professionals truly thrive.
09/24/2026
Full time
Job Description Job Description Benefits: Onsite Competitive salary Opportunity for advancement About the Role: Select Minds LLC is looking for a talented Network Security Engineer to join our growing team in Dallas, TX. This is an exciting opportunity to protect critical infrastructure, design robust security solutions, and work alongside a team of passionate technology professionals. If you thrive in a fast-paced environment and love solving complex security challenges, we want to hear from you! Responsibilities: Design, implement, and maintain network security architectures, firewalls, and intrusion detection/prevention systems (IDS/IPS) Monitor network traffic for suspicious activity and respond to security incidents and threats in real time Perform vulnerability assessments, penetration testing, and risk analysis across network infrastructure Configure and manage VPNs, access control lists (ACLs), and zero-trust network policies Collaborate with IT and DevOps teams to ensure security best practices are integrated into all systems Develop and maintain security documentation, policies, and incident response procedures Stay current with emerging cybersecurity threats, trends, and compliance requirements (NIST, ISO 27001, etc.) Requirements: 3+ years of experience in network security engineering or a related cybersecurity role Proficiency with firewalls, SIEM tools, and network monitoring platforms (e.g., Cisco, Palo Alto, Splunk) Strong understanding of TCP/IP, DNS, VPN, and network protocols Experience with cloud security environments (AWS, Azure, or GCP) is a plus Relevant certifications such as CISSP, CCNP Security, CEH, or CompTIA Security+ preferred Strong analytical and problem-solving skills with keen attention to detail Excellent communication skills and ability to work both independently and collaboratively About Us: Select Minds LLC is a forward-thinking technology firm based in Dallas, TX, dedicated to delivering innovative IT and security solutions to businesses of all sizes. Our clients trust us to safeguard their most critical assets, and our team takes that responsibility seriously. We foster a culture of continuous learning, collaboration, and growth - making Select Minds a place where talented professionals truly thrive.
Senior Network Security Engineer
Ignite IT
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/24/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Firewall Engineer
Tetrad Digital Integrity LLC Arlington, Virginia
Job Description Job Description Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age. TDI is seeking a Firewall Engineer to support the Compartmented Enterprise Services Office (CESO) Task Order for the GIG Service Management - Operations II (GSM-O II) contract. We are looking for a professional with hands-on engineering and testing experience in virtualized and cloud environments. A skilled engineer knowledgeable and experienced in developing and implementing Firewall/Networking Security Solutions. With the CESO program, the Defense Information System Agency (DISA) is looking to transform the existing Secure Web Services (SWS) environment, used to provide secure information sharing to the community, into a more mature service offering to meet the DoD and IC community. The goal will be to manage the commercial cloud migration and fully automate the continuous development & continuous integration environment, fourth estate consolidation, professionalize services - ITIL/DevSecOps based processes, improve the customer experience 1st call resolution, and achieve development of a service catalog for Defense Working Capital Fund (DWCF) Model. This position is onsite 5 days/week in Arlington, VA and requires an active TS/SCI clearance. RESPONSIBILITIES: Identify and remediate misconfigurations, conflicting rules, security gaps, firewall and load balancer security issues, optimize rule-sets, and enhance the overall security posture and performance of Firewalls and Load Balancers Provide Tier 3 support to members of the operations network administrations. Maintain all HW and SW components at vendor supported levels. Support mission-critical Continuity of Operations (COOP). Conduct a minimum of two (2) assessment of firewall each month on CESO and customer devices and generate assessment reports and provide recommendations for improvements. Support the creation of network device performance and traffic utilization monthly reports. Develop and/or participate in After Action Reports (AARs) Provide expert advice and direction regarding the management and operation of all Palo Alto devices in the DISA CESO enterprise architecture. Interact with the customer point of contact to set objectives/goals based on Palo Alto Networks technologies and available technology roadmap for architecture and design discussions. Evaluate current technologies and processes associated with DISA CESO to identify gaps. Provide requirements and strategies for future cybersecurity operations. Active participant in meetings with DISA CESO and mission partner working groups. Adhere to applicable DOD STIGs, DISA applicable orders, and JSIG policy, guidelines, and regulations. QUALIFICATIONS: Bachelor's degree and 8+ years of directly relevant experience. Additionall experience may be considered in lieu of degree. 5+ years of hands-on Cisco / Palo Alto Firewall experience in both engineering and Operations and maintenance roles. Strong knowledge of Palo Alto concepts and best practices: Panorama Installation, HA Config, Template and Template Stacks Panorama Policy creation and push to group of Firewalls and Verify Push Palo Alto Route configuration, IPSec Site to Site VPN Config and Troubleshooting Palo Alto VM in AWS, IPS Configuration, Virtual Router / Systems and Firewall HA Experience working in a high op-temp, Top Secret environment. 8570 IAT Level II Baseline Certification (e.g. CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP) PAY RANGE: The anticipated salary range for this position is $115,000 - $125,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range. TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States. "TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws." Powered by JazzHR K1XH2D1aKL
09/24/2026
Full time
Job Description Job Description Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age. TDI is seeking a Firewall Engineer to support the Compartmented Enterprise Services Office (CESO) Task Order for the GIG Service Management - Operations II (GSM-O II) contract. We are looking for a professional with hands-on engineering and testing experience in virtualized and cloud environments. A skilled engineer knowledgeable and experienced in developing and implementing Firewall/Networking Security Solutions. With the CESO program, the Defense Information System Agency (DISA) is looking to transform the existing Secure Web Services (SWS) environment, used to provide secure information sharing to the community, into a more mature service offering to meet the DoD and IC community. The goal will be to manage the commercial cloud migration and fully automate the continuous development & continuous integration environment, fourth estate consolidation, professionalize services - ITIL/DevSecOps based processes, improve the customer experience 1st call resolution, and achieve development of a service catalog for Defense Working Capital Fund (DWCF) Model. This position is onsite 5 days/week in Arlington, VA and requires an active TS/SCI clearance. RESPONSIBILITIES: Identify and remediate misconfigurations, conflicting rules, security gaps, firewall and load balancer security issues, optimize rule-sets, and enhance the overall security posture and performance of Firewalls and Load Balancers Provide Tier 3 support to members of the operations network administrations. Maintain all HW and SW components at vendor supported levels. Support mission-critical Continuity of Operations (COOP). Conduct a minimum of two (2) assessment of firewall each month on CESO and customer devices and generate assessment reports and provide recommendations for improvements. Support the creation of network device performance and traffic utilization monthly reports. Develop and/or participate in After Action Reports (AARs) Provide expert advice and direction regarding the management and operation of all Palo Alto devices in the DISA CESO enterprise architecture. Interact with the customer point of contact to set objectives/goals based on Palo Alto Networks technologies and available technology roadmap for architecture and design discussions. Evaluate current technologies and processes associated with DISA CESO to identify gaps. Provide requirements and strategies for future cybersecurity operations. Active participant in meetings with DISA CESO and mission partner working groups. Adhere to applicable DOD STIGs, DISA applicable orders, and JSIG policy, guidelines, and regulations. QUALIFICATIONS: Bachelor's degree and 8+ years of directly relevant experience. Additionall experience may be considered in lieu of degree. 5+ years of hands-on Cisco / Palo Alto Firewall experience in both engineering and Operations and maintenance roles. Strong knowledge of Palo Alto concepts and best practices: Panorama Installation, HA Config, Template and Template Stacks Panorama Policy creation and push to group of Firewalls and Verify Push Palo Alto Route configuration, IPSec Site to Site VPN Config and Troubleshooting Palo Alto VM in AWS, IPS Configuration, Virtual Router / Systems and Firewall HA Experience working in a high op-temp, Top Secret environment. 8570 IAT Level II Baseline Certification (e.g. CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP) PAY RANGE: The anticipated salary range for this position is $115,000 - $125,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range. TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States. "TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws." Powered by JazzHR K1XH2D1aKL
A-10-27-Network Engineer - Consultant 8502
FHR Columbia, South Carolina
Job Description Job Description Work Location: Hybrid (3 days remote, 2 days in office) Candidate location - Candidates local to South Carolina are required. Candidates local to Georgia or North Carolina will be considered if they are willing to relocate to South Carolina at their own expense. Employment Type: W2 only, no subcontractors Our direct client is seeking an experienced Network Engineer - Consultant 8502 for a 12-month contract, located in Columbia, SC. -5+ years of experience with FIREWALLS IN AWS AND AZURE. -5+ years of experience with PALO ALTO FIREWALLS Both of these skills are now required for resources. Preferred Prisma Cloud Forescout Cisco Umbrella F5 load balancing/firewall CISSP - Certified Information Systems Security Professional SC100 Microsoft Cybersecurity Architect AWS Certified Cloud Solutions Architect Prisma Certified Cloud Security Engineer, PCNSA, PCNSE
09/24/2026
Full time
Job Description Job Description Work Location: Hybrid (3 days remote, 2 days in office) Candidate location - Candidates local to South Carolina are required. Candidates local to Georgia or North Carolina will be considered if they are willing to relocate to South Carolina at their own expense. Employment Type: W2 only, no subcontractors Our direct client is seeking an experienced Network Engineer - Consultant 8502 for a 12-month contract, located in Columbia, SC. -5+ years of experience with FIREWALLS IN AWS AND AZURE. -5+ years of experience with PALO ALTO FIREWALLS Both of these skills are now required for resources. Preferred Prisma Cloud Forescout Cisco Umbrella F5 load balancing/firewall CISSP - Certified Information Systems Security Professional SC100 Microsoft Cybersecurity Architect AWS Certified Cloud Solutions Architect Prisma Certified Cloud Security Engineer, PCNSA, PCNSE

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board