Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/28/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/28/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/28/2026
Full time
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
09/28/2026
Full time
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
09/28/2026
Full time
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
09/28/2026
Full time
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
09/28/2026
Full time
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.