Computational Physics, Inc.
Washington, Washington DC
Job Description Job Description Computational Physics, Inc. (CPI) is looking for a Full-Time Operations Analyst to support our customers at USNO DC.BackgroundCPI supports the U.S. Naval Observatory (USNO) Operations Center in Washington, D.C. - USNO's single secure location for executing and monitoring the automated generation of the Navy's key operational timing and astrometric products. USNO determines and disseminates precise time and time interval (PTTI), Earth orientation parameters (EOP), and precise positions of celestial bodies for the Department of Defense, other federal agencies, and the public. These products underpin navigation, platform orientation, communications, intelligence, command and control, mission planning, and electronic warfare systems.The Operations Analyst works as a member of the Operations Center watch team, reporting to a watch team lead. The primary responsibility is executing and monitoring the automated generation of USNO operational products and ensuring customer access to them. This includes:Direct and remote inspection of hardware and monitoring the health status of automated data acquisition and reduction systems supporting Master Clock time determination and dissemination, EOP solutions, and VLBI data transfer and correlationRecognizing anomalous conditions and distinguishing between unusual-but-acceptable behavior and situations requiring intervention, drawing on familiarity with multiple data sources and productsTaking timely remedial action per SOPs, established procedures, or direction from subject matter experts when unexpected results or alarm conditions occurInteracting with data providers and product users - reporting product availability, responding to routine inquiries, and escalating alarm situations to the appropriate USNO personnel per SOP contact listsCoordinating with the watch team lead, supervisor, and USNO technical staff on system functionality, SOP effectiveness, and assignment planningThis is a 24/7 watch operation. The position requires shift work and is designated Mission Essential - the incumbent may be directed to report during inclement weather, installation closure, or other emergency situations, and may be required to work off-hours shifts as the mission requires.QualificationsBS from an ABET-accredited institution in physics, astronomy, geophysics, engineering, computer science, or a closely related physical science discipline. 3 years of relevant technical experience, to include:Monitoring, operating, or troubleshooting automated data acquisition, processing, or control systems in an operational (not purely research) environmentWorking from written standard operating procedures and applying judgment where guidance is incomplete or does not cleanly fit the situationAnalyzing technical data to identify anomalies, and communicating findings clearly in writing and verballyWorking knowledge of the mathematics and basic statistics underlying the physical sciencesWatch floor, NOC, SOC, mission control, or other 24/7 operations center experienceFamiliarity with precise timing (PTTI), atomic clocks, GNSS, Earth orientation, or VLBI/radio astronomy dataLinux system administration and monitoring tools (e.g., Nagios, Zabbix, Grafana); scripting in Python, Bash, or PerlExperience with hardware inspection, rack-level equipment, and instrumentationPrior U.S. military operations, technician, or DoD contractor experienceActive Secret clearance required at start; must be eligible for and willing to be processed for Top Secret / SCI.U.S. citizenship is required for DoD contracts.Position DetailsLocation: USNO, DCOn-Site Requirements: On SiteEmployment Type: Full-TimeSalary Range: $105,000 - $125,000About CPIWe love science! We study the physical properties of the Earth and our atmosphere, neighboring planets, and the sun. We make the study of science practical by translating our findings into products, both hardware and software, that make our customer's lives easier and better. CPI has served various U.S. Government agencies, universities, international science organizations, prime contractors, as well as commercial customers for 40 years.CPI is an employee-owned company our team members receive company stock. Employee ownership motivates and empowers increased productivity, contribution to the longevity of the business, improved retention, and enhanced employee engagement.Why Work for Us?Competitive salary and comprehensive benefitsPositive, upbeat, and transparent company culture with opportunities for self-development and career advancementEmployee -owned small business that allows team members to learn from each other and take ownershipProfessional development support including conference attendance and certification trainingBenefits401(k), Profit Sharing and an Employee Stock Ownership Plan (ESOP)Disability insurance (short-term and long-term)Flexible scheduleFlexible spending accountHealth, Dental and Vision insuranceLife insurancePaid time offParental LeaveTuition reimbursementTo apply please visit our careers page. CPI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.If you need a reasonable accommodation for any part of the employment process, please contact us and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis.
Job Description Job Description Computational Physics, Inc. (CPI) is looking for a Full-Time Operations Analyst to support our customers at USNO DC.BackgroundCPI supports the U.S. Naval Observatory (USNO) Operations Center in Washington, D.C. - USNO's single secure location for executing and monitoring the automated generation of the Navy's key operational timing and astrometric products. USNO determines and disseminates precise time and time interval (PTTI), Earth orientation parameters (EOP), and precise positions of celestial bodies for the Department of Defense, other federal agencies, and the public. These products underpin navigation, platform orientation, communications, intelligence, command and control, mission planning, and electronic warfare systems.The Operations Analyst works as a member of the Operations Center watch team, reporting to a watch team lead. The primary responsibility is executing and monitoring the automated generation of USNO operational products and ensuring customer access to them. This includes:Direct and remote inspection of hardware and monitoring the health status of automated data acquisition and reduction systems supporting Master Clock time determination and dissemination, EOP solutions, and VLBI data transfer and correlationRecognizing anomalous conditions and distinguishing between unusual-but-acceptable behavior and situations requiring intervention, drawing on familiarity with multiple data sources and productsTaking timely remedial action per SOPs, established procedures, or direction from subject matter experts when unexpected results or alarm conditions occurInteracting with data providers and product users - reporting product availability, responding to routine inquiries, and escalating alarm situations to the appropriate USNO personnel per SOP contact listsCoordinating with the watch team lead, supervisor, and USNO technical staff on system functionality, SOP effectiveness, and assignment planningThis is a 24/7 watch operation. The position requires shift work and is designated Mission Essential - the incumbent may be directed to report during inclement weather, installation closure, or other emergency situations, and may be required to work off-hours shifts as the mission requires.QualificationsBS from an ABET-accredited institution in physics, astronomy, geophysics, engineering, computer science, or a closely related physical science discipline. 3 years of relevant technical experience, to include:Monitoring, operating, or troubleshooting automated data acquisition, processing, or control systems in an operational (not purely research) environmentWorking from written standard operating procedures and applying judgment where guidance is incomplete or does not cleanly fit the situationAnalyzing technical data to identify anomalies, and communicating findings clearly in writing and verballyWorking knowledge of the mathematics and basic statistics underlying the physical sciencesWatch floor, NOC, SOC, mission control, or other 24/7 operations center experienceFamiliarity with precise timing (PTTI), atomic clocks, GNSS, Earth orientation, or VLBI/radio astronomy dataLinux system administration and monitoring tools (e.g., Nagios, Zabbix, Grafana); scripting in Python, Bash, or PerlExperience with hardware inspection, rack-level equipment, and instrumentationPrior U.S. military operations, technician, or DoD contractor experienceActive Secret clearance required at start; must be eligible for and willing to be processed for Top Secret / SCI.U.S. citizenship is required for DoD contracts.Position DetailsLocation: USNO, DCOn-Site Requirements: On SiteEmployment Type: Full-TimeSalary Range: $105,000 - $125,000About CPIWe love science! We study the physical properties of the Earth and our atmosphere, neighboring planets, and the sun. We make the study of science practical by translating our findings into products, both hardware and software, that make our customer's lives easier and better. CPI has served various U.S. Government agencies, universities, international science organizations, prime contractors, as well as commercial customers for 40 years.CPI is an employee-owned company our team members receive company stock. Employee ownership motivates and empowers increased productivity, contribution to the longevity of the business, improved retention, and enhanced employee engagement.Why Work for Us?Competitive salary and comprehensive benefitsPositive, upbeat, and transparent company culture with opportunities for self-development and career advancementEmployee -owned small business that allows team members to learn from each other and take ownershipProfessional development support including conference attendance and certification trainingBenefits401(k), Profit Sharing and an Employee Stock Ownership Plan (ESOP)Disability insurance (short-term and long-term)Flexible scheduleFlexible spending accountHealth, Dental and Vision insuranceLife insurancePaid time offParental LeaveTuition reimbursementTo apply please visit our careers page. CPI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.If you need a reasonable accommodation for any part of the employment process, please contact us and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis.
Ignite IT
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance