Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
09/30/2026
Full time
Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
Job Description Job Description 4. Scope of Servies The Florida Department of Transportation, Office of Information Technology (OIT) - Integration Services is in search of a Senior Network Engineer to play a key role in assisting the Office of Information Technology in the establishment of new integration methods and standards, along with implementing system integrations, according to those established methods and standards. Duties and Responsibilities will include but are not limited to: 1. Perform security administration to configure and document firewall infrastructure access rules and work with peripheral network components in the technology environment with Palo Alto, Checkpoint and Global Protect VPNs. 2. Firewall deployments, rule migrations, firewall administration and converting existing rule based policies onto new platforms. 3. Works with critical core network infrastructure devices like Next Gen Firewall, VPNs, log collectors and monitors which play a crucial role in security for our IT environment. 4. Works with cloud network infrastructure to configure firewall, security policies and monitor network traffic. 5. Develop and maintain documentation following NIST guidelines. 6. Project Manager; 7. Data Administration; 5 Education Bachelor's Degree in Computer Science, Information Systems or other related field. Or equivalent work experience. Preferred Certifications (PCNSE, CISSP, CCNP, CCIE) 6. Experience 1. Typically have 5 to 10 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, database design and administration 2. Three to five years of experience with information security tools based on NIST standards. 3. Requires knowledge of security issues, techniques, and implications across all existing computer platforms. Preference given for experience with NGFW Palo Alto or Checkpoint security products. 4. Experience using schematic diagramming tools to map infrastructure layouts. 7 Primary Job Duties/ Tasks Senior Network Engineer - Job Duties 1. Develops, implements, and manages enterprise security solutions across multiple IT functional areas, including network infrastructure, data, systems, cloud environments, telecommunications, and Web-based services. Designs and maintains secure network architectures, segmentation strategies, access controls, firewalls, VPNs, encryption technologies, and other security controls. 2. Develops, implements, and maintains enterprise security policies, standards, procedures, and technical controls governing user authentication, privileged access, network access, security monitoring, vulnerability management, firewall administration, encryption, remote access, and incident escalation. Ensures security practices align with organizational requirements, industry standards, and applicable regulatory requirements. 3. Performs security risk assessments and develops risk-based response strategies for enterprise network and infrastructure environments. Prepares executive-level status reports, risk assessments, security metrics, and recommendations addressing vulnerabilities, emerging threats, security incidents, and operational risks. 4. Monitors, analyzes, and responds to cybersecurity threats and security events, including malware, software vulnerabilities, unauthorized access attempts, network anomalies, and policy violations. Administers and monitors security profiles and access controls, reviews security alerts and violation reports, investigates security exceptions, and coordinates remediation activities. Maintains comprehensive documentation of security controls, configurations, incidents, and corrective actions. 5. Evaluates emerging network and security technologies, products, and procedures to improve infrastructure reliability, security, performance, and operational efficiency. Leads technical evaluations, proof-of-concept activities, product assessments, and implementation recommendations for enterprise networking and cybersecurity solutions. 6. Provides advanced technical support and consultation to business and IT stakeholders on complex network, infrastructure, and cybersecurity issues. Troubleshoots escalated network and security incidents, provides technical guidance to infrastructure teams, and educates IT and business personnel on security policies, secure configurations, access requirements, and risk mitigation practices. 7. Provides security expertise and technical leadership throughout the IT project lifecycle, including requirements development, architecture and design, implementation, testing, deployment, and operational support. Reviews project designs and proposed solutions to identify security risks and ensures appropriate security controls are incorporated into network, cloud, application, and infrastructure initiatives. 8. Designs, implements, and supports enterprise network infrastructure, including LAN/WAN, routing and switching, wireless networks, firewalls, VPNs, network segmentation, Internet connectivity, cloud connectivity, and data center infrastructure. Develops network solutions that support high availability, resiliency, scalability, and security requirements. 9. Leads the investigation and resolution of complex network and security incidents, utilizing network monitoring, logging, packet analysis, performance data, and security tools to identify root causes and implement corrective actions. Coordinates with vendors, technical teams, and organizational stakeholders during critical incidents and service disruptions. 10. Develops network security architecture and segmentation strategies designed to limit lateral movement, protect critical systems, isolate sensitive workloads, and establish appropriate security boundaries between users, applications, devices, and infrastructure. Evaluates east-west and north-south traffic flows to identify security risks and opportunities for improved network controls. 11. Establishes and monitors network performance and security metrics to identify trends, capacity requirements, vulnerabilities, and potential operational risks. Develops dashboards, key performance indicators, and management reports to support data-driven infrastructure and security decisions. 12. Maintains technical documentation and configuration standards for network and security infrastructure, including network diagrams, IP addressing, VLANs, firewall rules, access controls, security configurations, operational procedures, and disaster recovery requirements. Ensures documentation remains accurate and aligned with the current enterprise environment. 13. Collaborates with architecture, cybersecurity, systems, database, application, cloud, telecommunications, and infrastructure teams to develop integrated technology solutions. Serves as a senior technical resource and provides guidance on enterprise networking, security architecture, infrastructure design, and technology modernization. 14. Provides technical leadership and mentoring to network and security staff, establishes network engineering standards and best practices, reviews technical solutions, and assists with the development of team capabilities in enterprise networking, cybersecurity, cloud infrastructure, and emerging technologies. Senior-Level Requirements Must have extensive knowledge and demonstrated experience in enterprise networking, cybersecurity, systems, databases, cloud infrastructure, and/or Web operations. The senior-level Network Engineer is responsible for developing and implementing enterprise network and security strategies, leading complex technical projects, designing secure and resilient infrastructure, resolving the most complex network and security issues, conducting risk assessments, evaluating emerging technologies, and providing technical guidance to IT and business leadership. The position requires advanced knowledge of network architecture, routing and switching, firewalls, VPN technologies, network segmentation, wireless infrastructure, cloud networking, identity and access management, security monitoring, incident response, vulnerability management, disaster recovery, and enterprise security controls. 8 Job Specific Skills and Abilities (KSAs): Intermediate professional level role. Works independently or on multiple IT security projects as a project team member, occasionally as a project leader. Works on small to large, complex security issues or projects that require increased skill in multiple IT functional areas. May coach more junior staff. 9 General Knowledge Skills and Abilities (KSAs): The submitted candidate must be able to apply common knowledge, skills, and abilities in the following areas: 1. Communication: Have the ability to clearly convey information, in both written and verbal formats, to individuals or groups in a wide variety of settings (i.e.; project team meetings, management presentations, etc.). Must have the ability to effectively listen and process information provided by others. 2. Customer Service: Works well with clients and customers (i.e.; business office, public, or other agencies). Able to assess the needs of the customer, provide information or assistance to satisfy expectations or resolve a problem. 3. Decision Making: Makes sound, well-informed, and objective decisions. 4. Flexibility: Is open to change, new processes (or process improvement), and new information. Has the ability to adapt in response to new information, changing conditions . click apply for full job details
09/30/2026
Full time
Job Description Job Description 4. Scope of Servies The Florida Department of Transportation, Office of Information Technology (OIT) - Integration Services is in search of a Senior Network Engineer to play a key role in assisting the Office of Information Technology in the establishment of new integration methods and standards, along with implementing system integrations, according to those established methods and standards. Duties and Responsibilities will include but are not limited to: 1. Perform security administration to configure and document firewall infrastructure access rules and work with peripheral network components in the technology environment with Palo Alto, Checkpoint and Global Protect VPNs. 2. Firewall deployments, rule migrations, firewall administration and converting existing rule based policies onto new platforms. 3. Works with critical core network infrastructure devices like Next Gen Firewall, VPNs, log collectors and monitors which play a crucial role in security for our IT environment. 4. Works with cloud network infrastructure to configure firewall, security policies and monitor network traffic. 5. Develop and maintain documentation following NIST guidelines. 6. Project Manager; 7. Data Administration; 5 Education Bachelor's Degree in Computer Science, Information Systems or other related field. Or equivalent work experience. Preferred Certifications (PCNSE, CISSP, CCNP, CCIE) 6. Experience 1. Typically have 5 to 10 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, database design and administration 2. Three to five years of experience with information security tools based on NIST standards. 3. Requires knowledge of security issues, techniques, and implications across all existing computer platforms. Preference given for experience with NGFW Palo Alto or Checkpoint security products. 4. Experience using schematic diagramming tools to map infrastructure layouts. 7 Primary Job Duties/ Tasks Senior Network Engineer - Job Duties 1. Develops, implements, and manages enterprise security solutions across multiple IT functional areas, including network infrastructure, data, systems, cloud environments, telecommunications, and Web-based services. Designs and maintains secure network architectures, segmentation strategies, access controls, firewalls, VPNs, encryption technologies, and other security controls. 2. Develops, implements, and maintains enterprise security policies, standards, procedures, and technical controls governing user authentication, privileged access, network access, security monitoring, vulnerability management, firewall administration, encryption, remote access, and incident escalation. Ensures security practices align with organizational requirements, industry standards, and applicable regulatory requirements. 3. Performs security risk assessments and develops risk-based response strategies for enterprise network and infrastructure environments. Prepares executive-level status reports, risk assessments, security metrics, and recommendations addressing vulnerabilities, emerging threats, security incidents, and operational risks. 4. Monitors, analyzes, and responds to cybersecurity threats and security events, including malware, software vulnerabilities, unauthorized access attempts, network anomalies, and policy violations. Administers and monitors security profiles and access controls, reviews security alerts and violation reports, investigates security exceptions, and coordinates remediation activities. Maintains comprehensive documentation of security controls, configurations, incidents, and corrective actions. 5. Evaluates emerging network and security technologies, products, and procedures to improve infrastructure reliability, security, performance, and operational efficiency. Leads technical evaluations, proof-of-concept activities, product assessments, and implementation recommendations for enterprise networking and cybersecurity solutions. 6. Provides advanced technical support and consultation to business and IT stakeholders on complex network, infrastructure, and cybersecurity issues. Troubleshoots escalated network and security incidents, provides technical guidance to infrastructure teams, and educates IT and business personnel on security policies, secure configurations, access requirements, and risk mitigation practices. 7. Provides security expertise and technical leadership throughout the IT project lifecycle, including requirements development, architecture and design, implementation, testing, deployment, and operational support. Reviews project designs and proposed solutions to identify security risks and ensures appropriate security controls are incorporated into network, cloud, application, and infrastructure initiatives. 8. Designs, implements, and supports enterprise network infrastructure, including LAN/WAN, routing and switching, wireless networks, firewalls, VPNs, network segmentation, Internet connectivity, cloud connectivity, and data center infrastructure. Develops network solutions that support high availability, resiliency, scalability, and security requirements. 9. Leads the investigation and resolution of complex network and security incidents, utilizing network monitoring, logging, packet analysis, performance data, and security tools to identify root causes and implement corrective actions. Coordinates with vendors, technical teams, and organizational stakeholders during critical incidents and service disruptions. 10. Develops network security architecture and segmentation strategies designed to limit lateral movement, protect critical systems, isolate sensitive workloads, and establish appropriate security boundaries between users, applications, devices, and infrastructure. Evaluates east-west and north-south traffic flows to identify security risks and opportunities for improved network controls. 11. Establishes and monitors network performance and security metrics to identify trends, capacity requirements, vulnerabilities, and potential operational risks. Develops dashboards, key performance indicators, and management reports to support data-driven infrastructure and security decisions. 12. Maintains technical documentation and configuration standards for network and security infrastructure, including network diagrams, IP addressing, VLANs, firewall rules, access controls, security configurations, operational procedures, and disaster recovery requirements. Ensures documentation remains accurate and aligned with the current enterprise environment. 13. Collaborates with architecture, cybersecurity, systems, database, application, cloud, telecommunications, and infrastructure teams to develop integrated technology solutions. Serves as a senior technical resource and provides guidance on enterprise networking, security architecture, infrastructure design, and technology modernization. 14. Provides technical leadership and mentoring to network and security staff, establishes network engineering standards and best practices, reviews technical solutions, and assists with the development of team capabilities in enterprise networking, cybersecurity, cloud infrastructure, and emerging technologies. Senior-Level Requirements Must have extensive knowledge and demonstrated experience in enterprise networking, cybersecurity, systems, databases, cloud infrastructure, and/or Web operations. The senior-level Network Engineer is responsible for developing and implementing enterprise network and security strategies, leading complex technical projects, designing secure and resilient infrastructure, resolving the most complex network and security issues, conducting risk assessments, evaluating emerging technologies, and providing technical guidance to IT and business leadership. The position requires advanced knowledge of network architecture, routing and switching, firewalls, VPN technologies, network segmentation, wireless infrastructure, cloud networking, identity and access management, security monitoring, incident response, vulnerability management, disaster recovery, and enterprise security controls. 8 Job Specific Skills and Abilities (KSAs): Intermediate professional level role. Works independently or on multiple IT security projects as a project team member, occasionally as a project leader. Works on small to large, complex security issues or projects that require increased skill in multiple IT functional areas. May coach more junior staff. 9 General Knowledge Skills and Abilities (KSAs): The submitted candidate must be able to apply common knowledge, skills, and abilities in the following areas: 1. Communication: Have the ability to clearly convey information, in both written and verbal formats, to individuals or groups in a wide variety of settings (i.e.; project team meetings, management presentations, etc.). Must have the ability to effectively listen and process information provided by others. 2. Customer Service: Works well with clients and customers (i.e.; business office, public, or other agencies). Able to assess the needs of the customer, provide information or assistance to satisfy expectations or resolve a problem. 3. Decision Making: Makes sound, well-informed, and objective decisions. 4. Flexibility: Is open to change, new processes (or process improvement), and new information. Has the ability to adapt in response to new information, changing conditions . click apply for full job details
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
09/30/2026
Full time
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/29/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/28/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
09/28/2026
Full time
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
09/28/2026
Full time
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
09/28/2026
Full time
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
09/28/2026
Full time
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.