Job Description Job Description CoreWeave is The Essential Cloud for AI . Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at . What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect critical infrastructure and continuously improve the security posture to meet the needs of our customers. With our growing reliance on connected technology, the need to keep critical systems secure, reliable, and resilient has never been more important. We are seeking an OT Security Engineer to join our team and play a pivotal role in safeguarding the operational technologies that support our datacenter networks. About the role: This position offers a unique opportunity to work at the crossroads of cyber security, operational technology (OT), engineering, and datacenter operations. As the network security engineer responsible for our operational technology networks, your responsibilities will include identifying and evaluating cybersecurity risks, designing and launching pragmatic security solutions, and embedding security controls directly into the operational systems and technologies supporting our infrastructure. You will work with suppliers and third parties in benchmarking their capabilities against expectations and industry standards. You will also lead efforts in partnering with peer security teams and partners in production engineering as you lead continuous improvement of security posture for operational technology network environments and the devices connected. This role requires both depth in understanding network security, and breadth of knowledge of the unique challenges that face the industry in securing the infrastructure that is the foundation of modern datacenters. You will act as a trusted partner who goes beyond advisory work to roll up your sleeves and deliver. Some things you will work on: Establishing standards for security expectations covering all operational technology networks and devices connected to them. This will include network segmentation, host isolation, network traversal controls, and remote connectivity. Providing solutions to complex security issues, manage multiple tasks, and prioritize effectively in a fast-paced environment. Creating an inventory and risk register that can be used as a baseline in understanding near term and long term objectives. Partnering with production engineering and business development teams evaluating priorities for risk reduction in current deployments, and risk avoidance by evolving standards for future growth. Executing and partnering with other parties in using penetration testing to evaluate effectiveness of existing controls. Coordinating with third parties and internal teams in addressing vulnerabilities via mitigation, isolation or other strategies to protect critical infrastructure in these environments. Researching industry risks and drive change in operational networks to continuously reduce risk Developing and test recovery models and response playbooks to handle compromise scenarios. Presenting technical security information to both technical and non-technical audiences, including external partners. Maintain technical documentation, reports, and security tooling with attention to detail. Who You Are: 5+ Years of experience in network infrastructure security (firewalls, ACLs, architecture, risk management) in a global network environment. Proficiency in at least one programming or scripting language (e.g., Go, Python, C/C++) for automation, code reviews, and tooling. Bachelor's degree in Computer Science or related field. Relevant certifications such as CISSP, CCNP, PCNSE are advantageous. Experience with operational technology networks (factory or industrial systems, building management systems, power, physical security systems, remote access, HVAC, etc.), factory networks or other similar environments. Strong technical knowledge of network firewalls, virtual private networks, network segmentation, and defense in depth. Able to navigate ambiguity, identify root causes, and solve complex security problems. Excellent written and verbal communication skills with strong technical documentation abilities. Capable of working independently while managing multiple priorities in a fast-paced environment. Strong desire to continuously learn and adopt new technologies and security techniques. Preferred: Prior experience with operational technology networks that span global locations Experience with the range of obscure solutions that are often deployed on operational technology networks. Deep understanding of business-wide security best practices and implementation strategies. Experience with network automation, agentic network tooling, and incident response automation. Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk. You love to solve problems that few others would tackle. You're curious about critical network infrastructure that is the foundation of modern data centers. You're an expert in network security with a passion to explore the more exotic nature of operational technology. Why CoreWeave? At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your Core Act Like an Owner Empower Employees Deliver Best-in-Class Client Experiences Achieve More Together We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $164,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We Offer The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include: Medical, dental, and vision insurance - 100% paid for by CoreWeave Company-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending Account Health Savings Account Tuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP) Mental Wellness Benefits through Spring Health Family-Forming support provided by Carrot Paid Parental Leave Flexible, full-service childcare support with Kinside 401(k) with a generous employer match Flexible PTO Catered lunch each day in our office and data center locations A casual work environment A work culture focused on innovative disruption California Applicants California Consumer Privacy Act Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA) , CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: . . click apply for full job details
09/28/2026
Full time
Job Description Job Description CoreWeave is The Essential Cloud for AI . Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at . What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect critical infrastructure and continuously improve the security posture to meet the needs of our customers. With our growing reliance on connected technology, the need to keep critical systems secure, reliable, and resilient has never been more important. We are seeking an OT Security Engineer to join our team and play a pivotal role in safeguarding the operational technologies that support our datacenter networks. About the role: This position offers a unique opportunity to work at the crossroads of cyber security, operational technology (OT), engineering, and datacenter operations. As the network security engineer responsible for our operational technology networks, your responsibilities will include identifying and evaluating cybersecurity risks, designing and launching pragmatic security solutions, and embedding security controls directly into the operational systems and technologies supporting our infrastructure. You will work with suppliers and third parties in benchmarking their capabilities against expectations and industry standards. You will also lead efforts in partnering with peer security teams and partners in production engineering as you lead continuous improvement of security posture for operational technology network environments and the devices connected. This role requires both depth in understanding network security, and breadth of knowledge of the unique challenges that face the industry in securing the infrastructure that is the foundation of modern datacenters. You will act as a trusted partner who goes beyond advisory work to roll up your sleeves and deliver. Some things you will work on: Establishing standards for security expectations covering all operational technology networks and devices connected to them. This will include network segmentation, host isolation, network traversal controls, and remote connectivity. Providing solutions to complex security issues, manage multiple tasks, and prioritize effectively in a fast-paced environment. Creating an inventory and risk register that can be used as a baseline in understanding near term and long term objectives. Partnering with production engineering and business development teams evaluating priorities for risk reduction in current deployments, and risk avoidance by evolving standards for future growth. Executing and partnering with other parties in using penetration testing to evaluate effectiveness of existing controls. Coordinating with third parties and internal teams in addressing vulnerabilities via mitigation, isolation or other strategies to protect critical infrastructure in these environments. Researching industry risks and drive change in operational networks to continuously reduce risk Developing and test recovery models and response playbooks to handle compromise scenarios. Presenting technical security information to both technical and non-technical audiences, including external partners. Maintain technical documentation, reports, and security tooling with attention to detail. Who You Are: 5+ Years of experience in network infrastructure security (firewalls, ACLs, architecture, risk management) in a global network environment. Proficiency in at least one programming or scripting language (e.g., Go, Python, C/C++) for automation, code reviews, and tooling. Bachelor's degree in Computer Science or related field. Relevant certifications such as CISSP, CCNP, PCNSE are advantageous. Experience with operational technology networks (factory or industrial systems, building management systems, power, physical security systems, remote access, HVAC, etc.), factory networks or other similar environments. Strong technical knowledge of network firewalls, virtual private networks, network segmentation, and defense in depth. Able to navigate ambiguity, identify root causes, and solve complex security problems. Excellent written and verbal communication skills with strong technical documentation abilities. Capable of working independently while managing multiple priorities in a fast-paced environment. Strong desire to continuously learn and adopt new technologies and security techniques. Preferred: Prior experience with operational technology networks that span global locations Experience with the range of obscure solutions that are often deployed on operational technology networks. Deep understanding of business-wide security best practices and implementation strategies. Experience with network automation, agentic network tooling, and incident response automation. Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk. You love to solve problems that few others would tackle. You're curious about critical network infrastructure that is the foundation of modern data centers. You're an expert in network security with a passion to explore the more exotic nature of operational technology. Why CoreWeave? At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your Core Act Like an Owner Empower Employees Deliver Best-in-Class Client Experiences Achieve More Together We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $164,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We Offer The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include: Medical, dental, and vision insurance - 100% paid for by CoreWeave Company-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending Account Health Savings Account Tuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP) Mental Wellness Benefits through Spring Health Family-Forming support provided by Carrot Paid Parental Leave Flexible, full-service childcare support with Kinside 401(k) with a generous employer match Flexible PTO Catered lunch each day in our office and data center locations A casual work environment A work culture focused on innovative disruption California Applicants California Consumer Privacy Act Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA) , CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: . . click apply for full job details
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/28/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description Overview We are seeking a CSfC Senior Network Engineer to join our team supporting Network Enterprise Technology Command (NETCOM) in Honolulu, HI. TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at . Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Responsibilities RESPONSIBILITIES Assists the PM in the day-to-day management of leading Network Engineers. Must have an in-depth understanding of advanced networking O&M Commercial Solutions for Classified (CSfC) concepts and processes and experience applying these with little to no guidance. Must be able to provide guidance to others. Must be able to perform successfully in complex, unstructured situations. Must be proficient in multivendor networking environments in configuring firewalls, Intrusion Prevention/Detection systems, VPN gateways, routers, and switches (Cisco, Aruba, Juniper, Cisco ASA, etc.) Be able to develop and modify system scripts. Write standardized system documentation, including configuration guides, test procedures, test results, and training materials. Provide onsite training to technical and non-technical users on the daily use, management, and troubleshooting of the solution after installation. Support all Cross-Domain solution requirements Collaborate with other operations departments to design approved infrastructure Serve as the escalation contact during large outages for Tier 2 and 3 systems. Author network Engineering Design Packages to include detailed implementation project plans and procedures. Configures network, software, and hardware components to meet NSA CSfC, NIAP, and DoD requirements Performs network design and systems integration Designs, develops, implements, tests, and maintains complex secure communications networks Configuring/managing PKI Certificate Authorities for CSfC solutions Familiarity with Certificate Authority configuration (ISC CertAgent/MS Windows Server/Red Hat Certificate systems) Document configuration, test procedure, results, and training materials Preparing test reports and configuration documentation according to customer standards. Providing customer on-site training on solution daily use, management, and troubleshooting Provide tier 2 and 3 support as part of a technical team. Identify and recommend hardware and support solutions based on research and analysis of new technologies, interfacing with customers and vendors. Enhance department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to the company. Apply DoD STIGs and IAVAs Perform special projects and other duties as assigned. REQUIRED QUALIFICATIONS Top Secret OR Higher OR Secret Clearance level with completed T5 investigation Active Professional Network certification (CCNP-Security, CCNA, HPE Aruba Networking Certified Professional - Switching, etc.) Must have experience with one or more networking vendors: Cisco, Aruba, Juniper, etc. One of the following DoD8140 Certifications : SecurityX/CASP+ CCNA CCNP Security CCSP (Certified Cloud Security Professional) GCED (GIAC Certified Enterprise Defender) GCIA (GIAC Certified Intrusion Analyst) GCLD (GIAC Cloud Security Essentials) GDSA (GIAC Defensible Security Architecture) GFACT (GIAC Foundational Cybersecurity Technologies) 10 or more years of experience in engineering MA/MS= 10 years; BS=12 years Qualifications WORK ENVIRONMENT AND PHYSICAL DEMANDS The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: Honolulu, HI Type of environment: Office Noise level: Low Work schedule: CONUS Schedule is day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 20% PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WORK AUTHORIZATION/SECURITY CLEARANCE United States Citizenship Top Secret Clearance requirement WAGE INFORMATION Target salary range: $133,000.00 - $165,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. EQUAL EMPLOYMENT OPPORTUNITY In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
09/28/2026
Full time
Job Description Job Description Overview We are seeking a CSfC Senior Network Engineer to join our team supporting Network Enterprise Technology Command (NETCOM) in Honolulu, HI. TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at . Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Responsibilities RESPONSIBILITIES Assists the PM in the day-to-day management of leading Network Engineers. Must have an in-depth understanding of advanced networking O&M Commercial Solutions for Classified (CSfC) concepts and processes and experience applying these with little to no guidance. Must be able to provide guidance to others. Must be able to perform successfully in complex, unstructured situations. Must be proficient in multivendor networking environments in configuring firewalls, Intrusion Prevention/Detection systems, VPN gateways, routers, and switches (Cisco, Aruba, Juniper, Cisco ASA, etc.) Be able to develop and modify system scripts. Write standardized system documentation, including configuration guides, test procedures, test results, and training materials. Provide onsite training to technical and non-technical users on the daily use, management, and troubleshooting of the solution after installation. Support all Cross-Domain solution requirements Collaborate with other operations departments to design approved infrastructure Serve as the escalation contact during large outages for Tier 2 and 3 systems. Author network Engineering Design Packages to include detailed implementation project plans and procedures. Configures network, software, and hardware components to meet NSA CSfC, NIAP, and DoD requirements Performs network design and systems integration Designs, develops, implements, tests, and maintains complex secure communications networks Configuring/managing PKI Certificate Authorities for CSfC solutions Familiarity with Certificate Authority configuration (ISC CertAgent/MS Windows Server/Red Hat Certificate systems) Document configuration, test procedure, results, and training materials Preparing test reports and configuration documentation according to customer standards. Providing customer on-site training on solution daily use, management, and troubleshooting Provide tier 2 and 3 support as part of a technical team. Identify and recommend hardware and support solutions based on research and analysis of new technologies, interfacing with customers and vendors. Enhance department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to the company. Apply DoD STIGs and IAVAs Perform special projects and other duties as assigned. REQUIRED QUALIFICATIONS Top Secret OR Higher OR Secret Clearance level with completed T5 investigation Active Professional Network certification (CCNP-Security, CCNA, HPE Aruba Networking Certified Professional - Switching, etc.) Must have experience with one or more networking vendors: Cisco, Aruba, Juniper, etc. One of the following DoD8140 Certifications : SecurityX/CASP+ CCNA CCNP Security CCSP (Certified Cloud Security Professional) GCED (GIAC Certified Enterprise Defender) GCIA (GIAC Certified Intrusion Analyst) GCLD (GIAC Cloud Security Essentials) GDSA (GIAC Defensible Security Architecture) GFACT (GIAC Foundational Cybersecurity Technologies) 10 or more years of experience in engineering MA/MS= 10 years; BS=12 years Qualifications WORK ENVIRONMENT AND PHYSICAL DEMANDS The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: Honolulu, HI Type of environment: Office Noise level: Low Work schedule: CONUS Schedule is day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 20% PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WORK AUTHORIZATION/SECURITY CLEARANCE United States Citizenship Top Secret Clearance requirement WAGE INFORMATION Target salary range: $133,000.00 - $165,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. EQUAL EMPLOYMENT OPPORTUNITY In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/28/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Job Description Job Description Benefits: HYBRID Competitive salary Opportunity for advancement Network Security Engineer Fort Collins, CO (Hybrid) Type: Contract (C2C) Interview Mode: Virtual Seeking a senior Network Security Engineer to lead firewall modernization, VPN transformation, zero-trust implementation, and enterprise vulnerability management across enterprise lab environments. This role supports secure, scalable, and compliant next-generation infrastructure platforms. Core Responsibilities : Firewall & Network Security Architecture Configure and optimize enterprise firewall platforms (physical and virtual) Design rule sets, traffic policies, and network segmentation Implement micro-segmentation and zero-trust architecture Align firewall policies with modern security frameworks VPN & Secure Access Transformation Replace legacy OpenVPN environments with OKTA/Atmos-based VPN solutions Build and manage Atmos connectors Implement secure authentication workflows Design secure routing and hybrid access policies Vulnerability Management Design and implement enterprise vulnerability scanning programs Deploy and manage tools such as Nessus or Greenbone Configure scan schedules and tune scan noise Deliver actionable security reports Drive remediation workflows with engineering teams Security Segmentation & Compliance Design security-driven network segmentation strategies Enforce access controls aligned to compliance and corporate standards Partner with corporate security teams on policy implementation Linux & Security Automation Deploy Linux-based security tooling platforms Automate scanning, reporting, and remediation workflows Script security processes and integrations Required Skills: Enterprise firewall configuration and optimization VPN technologies and secure remote access solutions Zero-trust and micro-segmentation principles Vulnerability scanning tools (Nessus, Greenbone, or similar) Security compliance scanning and remediation Linux system administration and automation Nice to Have: OKTA integrations and identity-based access systems SIEM and security monitoring platforms Automation frameworks and API integrations Flexible work from home options available.
09/28/2026
Full time
Job Description Job Description Benefits: HYBRID Competitive salary Opportunity for advancement Network Security Engineer Fort Collins, CO (Hybrid) Type: Contract (C2C) Interview Mode: Virtual Seeking a senior Network Security Engineer to lead firewall modernization, VPN transformation, zero-trust implementation, and enterprise vulnerability management across enterprise lab environments. This role supports secure, scalable, and compliant next-generation infrastructure platforms. Core Responsibilities : Firewall & Network Security Architecture Configure and optimize enterprise firewall platforms (physical and virtual) Design rule sets, traffic policies, and network segmentation Implement micro-segmentation and zero-trust architecture Align firewall policies with modern security frameworks VPN & Secure Access Transformation Replace legacy OpenVPN environments with OKTA/Atmos-based VPN solutions Build and manage Atmos connectors Implement secure authentication workflows Design secure routing and hybrid access policies Vulnerability Management Design and implement enterprise vulnerability scanning programs Deploy and manage tools such as Nessus or Greenbone Configure scan schedules and tune scan noise Deliver actionable security reports Drive remediation workflows with engineering teams Security Segmentation & Compliance Design security-driven network segmentation strategies Enforce access controls aligned to compliance and corporate standards Partner with corporate security teams on policy implementation Linux & Security Automation Deploy Linux-based security tooling platforms Automate scanning, reporting, and remediation workflows Script security processes and integrations Required Skills: Enterprise firewall configuration and optimization VPN technologies and secure remote access solutions Zero-trust and micro-segmentation principles Vulnerability scanning tools (Nessus, Greenbone, or similar) Security compliance scanning and remediation Linux system administration and automation Nice to Have: OKTA integrations and identity-based access systems SIEM and security monitoring platforms Automation frameworks and API integrations Flexible work from home options available.
Job Description Job Description Job Description Summary The System Engineer III, Firewalls, reports to the Manager, Network Infrastructure and Security Engineering in support of MUSC's academic, research and healthcare missions. Areas of expertise include firewall administration, patching, VPN configuration, address translation, routing, IP address management, network segmentation, security group tags, SDWAN, dynamic routing protocols, SSO, certificate management, and advanced troubleshooting. This position serves as a subject matter expert for network security services, evaluates and resolves complex technical issues and demonstrates strong analytical and communication skills to maximize the benefit of services the team provides for Information Solutions. Generates appropriate documentation, communications, processes, and educational plans to identify and remove obstacles to, and mitigate the disruption of change related to the design, management, implementation, and operations of the network; is responsible for the timely resolution of network issues; takes a lead role in projects; participates in team and project meetings and provides input on solutions to improve efficiency. The position coaches and transfers knowledge to peers and staff, maintains high professional standards, and exhibits excellent customer service skills while performing assigned tasks. Entity MUSC Community Physicians (MCP) Worker Type Employee Worker Sub-Type Regular Cost Center CC006134 MCP - Information Solutions Pay Rate Type Salary Pay Grade Health-30 Scheduled Weekly Hours 40 Work Shift Job Description The System Engineer III, Firewalls, reports to the Manager, Network Infrastructure and Security Engineering in support of MUSC's academic, research and healthcare missions. Areas of expertise include firewall administration, patching, VPN configuration, address translation, routing, IP address management, network segmentation, security group tags, SDWAN, dynamic routing protocols, SSO, certificate management, and advanced troubleshooting. This position serves as a subject matter expert for network security services, evaluates and resolves complex technical issues and demonstrates strong analytical and communication skills to maximize the benefit of services the team provides for Information Solutions. Generates appropriate documentation, communications, processes, and educational plans to identify and remove obstacles to, and mitigate the disruption of change related to the design, management, implementation, and operations of the network; is responsible for the timely resolution of network issues; takes a lead role in projects; participates in team and project meetings and provides input on solutions to improve efficiency. The position coaches and transfers knowledge to peers and staff, maintains high professional standards, and exhibits excellent customer service skills while performing assigned tasks. Additional Job Description Requirements (Education, Work Experience, Licensure, Registry &/or Certifications) A bachelor's degree and five years directly related experience; or a high school diploma and nine years directly related experience; or a Masters' degree and 3 years directly related experience required. 7+ years of Network experience is preferred. Must possess strong interpersonal, project management, analytical and communication skills. Experience in implementing, administering, and troubleshooting network security devices, including: firewalls, network access control, and monitoring applications. Knowledge of communication or information systems. Knowledge and technical expertise in networking protocols, security, and wireless communications. If you like working with energetic enthusiastic individuals, you will enjoy your career with us! The Medical University of South Carolina is an Equal Opportunity Employer. MUSC does not discriminate on the basis of race, color, religion or belief, age, sex, national origin, gender identity, sexual orientation, disability, protected veteran status, family or parental status, or any other status protected by state laws and/or federal regulations. All qualified applicants are encouraged to apply and will receive consideration for employment based upon applicable qualifications, merit and business need. Medical University of South Carolina participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here: -verify/employees
09/28/2026
Full time
Job Description Job Description Job Description Summary The System Engineer III, Firewalls, reports to the Manager, Network Infrastructure and Security Engineering in support of MUSC's academic, research and healthcare missions. Areas of expertise include firewall administration, patching, VPN configuration, address translation, routing, IP address management, network segmentation, security group tags, SDWAN, dynamic routing protocols, SSO, certificate management, and advanced troubleshooting. This position serves as a subject matter expert for network security services, evaluates and resolves complex technical issues and demonstrates strong analytical and communication skills to maximize the benefit of services the team provides for Information Solutions. Generates appropriate documentation, communications, processes, and educational plans to identify and remove obstacles to, and mitigate the disruption of change related to the design, management, implementation, and operations of the network; is responsible for the timely resolution of network issues; takes a lead role in projects; participates in team and project meetings and provides input on solutions to improve efficiency. The position coaches and transfers knowledge to peers and staff, maintains high professional standards, and exhibits excellent customer service skills while performing assigned tasks. Entity MUSC Community Physicians (MCP) Worker Type Employee Worker Sub-Type Regular Cost Center CC006134 MCP - Information Solutions Pay Rate Type Salary Pay Grade Health-30 Scheduled Weekly Hours 40 Work Shift Job Description The System Engineer III, Firewalls, reports to the Manager, Network Infrastructure and Security Engineering in support of MUSC's academic, research and healthcare missions. Areas of expertise include firewall administration, patching, VPN configuration, address translation, routing, IP address management, network segmentation, security group tags, SDWAN, dynamic routing protocols, SSO, certificate management, and advanced troubleshooting. This position serves as a subject matter expert for network security services, evaluates and resolves complex technical issues and demonstrates strong analytical and communication skills to maximize the benefit of services the team provides for Information Solutions. Generates appropriate documentation, communications, processes, and educational plans to identify and remove obstacles to, and mitigate the disruption of change related to the design, management, implementation, and operations of the network; is responsible for the timely resolution of network issues; takes a lead role in projects; participates in team and project meetings and provides input on solutions to improve efficiency. The position coaches and transfers knowledge to peers and staff, maintains high professional standards, and exhibits excellent customer service skills while performing assigned tasks. Additional Job Description Requirements (Education, Work Experience, Licensure, Registry &/or Certifications) A bachelor's degree and five years directly related experience; or a high school diploma and nine years directly related experience; or a Masters' degree and 3 years directly related experience required. 7+ years of Network experience is preferred. Must possess strong interpersonal, project management, analytical and communication skills. Experience in implementing, administering, and troubleshooting network security devices, including: firewalls, network access control, and monitoring applications. Knowledge of communication or information systems. Knowledge and technical expertise in networking protocols, security, and wireless communications. If you like working with energetic enthusiastic individuals, you will enjoy your career with us! The Medical University of South Carolina is an Equal Opportunity Employer. MUSC does not discriminate on the basis of race, color, religion or belief, age, sex, national origin, gender identity, sexual orientation, disability, protected veteran status, family or parental status, or any other status protected by state laws and/or federal regulations. All qualified applicants are encouraged to apply and will receive consideration for employment based upon applicable qualifications, merit and business need. Medical University of South Carolina participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here: -verify/employees
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/28/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
09/28/2026
Full time
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
Georgia System Operations Corporation
Tucker, Georgia
Job Description Job Description Network Security EngineerEngineer Secure, Resilient Network Services That Support Mission-Critical OperationsGeorgia System Operations Corporation (GSOC) is seeking a Network Security Engineer to design, implement, secure, and operate corporate network services and cybersecurity tools that enable reliable, protected business operations.This hands-on role combines enterprise network engineering and cybersecurity expertise across datacenter, campus, remote-site, internet-edge, and approved cloud environments. The Network Security Engineer helps safeguard availability, performance, secure access, and security visibility while advancing resilient, supportable, and automated network and security services.This opportunity is ideal for an experienced network and security professional who enjoys solving complex technical problems, strengthening controls, supporting incident response, mentoring peers, and collaborating across infrastructure, cybersecurity, application, service desk, and vendor teams. This is an onsite position and it is not eligible for visa sponsorshipWhat You'll DoAs a Network Security Engineer, you will engineer and support the network and network-focused security services that connect and protect enterprise users, systems, and sites.You will:Design, deploy, and support datacenter and campus switching, routing, VLANs, VRFs, high availability, capacity planning, and network segmentation.Administer next-generation firewalls, security zones, NAT, threat-prevention services, firewall policy lifecycle, and least-privilege access controls.Engineer WAN, internet-edge, remote-site, remote-access VPN, and site-to-site VPN connectivity, including integrations with identity, MFA, and device-trust services.Design and support corporate and guest wireless, controllers, access points, RF performance, 802.1X, network access control, device profiling, and secure authentication.Configure load balancers, virtual servers, pools, health monitors, persistence, TLS termination, and high-availability services.Manage the network-facing certificate lifecycle and PKI integrations.Engineer and operate secure web and DNS controls, network detection and response, security logging, SIEM integrations, and security-control health monitoring.Partner with the Security Operations Center on alert tuning, investigations, evidence gathering, and operational security use cases.Support secure DNS, DHCP, and IP address management and maintain telemetry, flow data, logging, alerting, packet analysis, and service dashboards.Maintain secure configuration baselines, backups, firmware and software lifecycle, and remediation of network-device and security-tool vulnerabilities.Automate repeatable work using APIs, scripting, and infrastructure-as-code practices.Develop and test network and security-platform recovery and failover capabilities.Prepare change and rollback plans and provide incident escalation, containment support, root-cause analysis, and vendor coordination. This role also:Works independently within established standards and change processes.Provides technical leadership for projects and mentors peers.Participates in technology evaluations, proof-of-concepts, cross-functional initiatives, backup support, and knowledge transfer. What You BringBachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related field. Equivalent combination of education, training, and directly related work experience may be considered.Ideally 5+ years of progressive experience supporting enterprise network and network-security infrastructure, including switching, routing, firewall administration, VPN, wireless, and troubleshooting.Strong knowledge of enterprise LAN/WAN, datacenter switching, routing, firewalls, VPN, wireless, NAC, load balancing, PKI and certificates, DNS, DHCP, IPAM, and secure configuration management.Hands-on experience operating cybersecurity tooling such as secure web and DNS services, network detection and response, vulnerability management, SIEM and logging integrations, and security monitoring.Experience with network and security automation using Python, PowerShell, Ansible, Terraform, APIs, or comparable tools.Working knowledge of NIST CSF, CIS Controls, incident-response practices, and applicable regulatory or industry requirements, including NERC CIP where relevant to the IT environment.Strong analytical, troubleshooting, documentation, communication, collaboration, and customer-service skills. Preferred QualificationsEnterprise Network EngineeringExperience engineering highly available datacenter, campus, WAN, internet-edge, remote-site, wireless, and VPN services.Experience with segmentation, least-privilege access, identity and MFA integrations, device trust, and network access control.Experience with load balancing, TLS termination, application delivery, certificate lifecycle management, and PKI integrations.Network Security & DetectionExperience operating next-generation firewalls, threat-prevention services, secure web or DNS controls, network detection and response, and vulnerability-management processes.Experience integrating network-security telemetry with SIEM, logging, alerting, dashboards, and incident-response workflows.Experience partnering with a SOC on investigation, tuning, containment, evidence, or root-cause activities.Automation, Resilience & OperationsExperience automating network or security operations through scripting, APIs, Ansible, Terraform, or infrastructure as code.Experience developing recovery, failover, configuration-backup, firmware-lifecycle, and vulnerability-remediation practices.Experience preparing changes, rollback plans, technical documentation, performance measures, and vendor-supported resolutions.CertificationsRelevant credentials such as CCNA, CCNP, ACP, PCNSE or equivalent firewall-vendor certification, CWNA, Security+, CISSP, AZ-700, or similar certifications are preferred. Advantages of Working at GSOCWorking at GSOC means more than just a job it's an opportunity to contribute to work that truly matters. Mission-Driven ImpactYour work supports secure, reliable corporate network services and cybersecurity capabilities used across GSOC's enterprise environment. Network Engineering & Cybersecurity DepthApply both network engineering and hands-on security expertise across switching, routing, wireless, firewalls, VPN, application delivery, monitoring, automation, and incident support. Technical Leadership & Continuous ImprovementLead technical projects, mentor peers, evaluate new technologies, automate repeatable work, and strengthen resilience, visibility, and operational supportability. Strong Values and Professional StandardsWork in an environment grounded in accountability, collaboration, integrity, security, compliance, and continuous improvement. Work Environment & BenefitsGSOC offers a professional, collaborative work environment with competitive compensation, comprehensive benefits, and a commitment to creating a respectful and inclusive workplace.Participation in an on-call rotation, emergency support, and scheduled maintenance outside normal business hours is required. Why Join GSOCAt GSOC, you will help engineer the network and security services that enable dependable business operations, secure access, security visibility, and resilient enterprise technology.You'll collaborate across infrastructure, cybersecurity, applications, service desk, and vendor teams while expanding your technical leadership and automation capabilities. Apply TodayIf you're ready to combine enterprise network engineering and cybersecurity expertise in a hands-on role supporting reliable, protected operations, we encourage you to apply. GSOC does not accept unsolicited resumes or candidate submissions from staffing agencies, search firms, or third-party recruiters. Any unsolicited resumes submitted without a valid, executed agreement will become the property of GSOC, and no placement fee will be paid. Job Posted by ApplicantPro
09/28/2026
Full time
Job Description Job Description Network Security EngineerEngineer Secure, Resilient Network Services That Support Mission-Critical OperationsGeorgia System Operations Corporation (GSOC) is seeking a Network Security Engineer to design, implement, secure, and operate corporate network services and cybersecurity tools that enable reliable, protected business operations.This hands-on role combines enterprise network engineering and cybersecurity expertise across datacenter, campus, remote-site, internet-edge, and approved cloud environments. The Network Security Engineer helps safeguard availability, performance, secure access, and security visibility while advancing resilient, supportable, and automated network and security services.This opportunity is ideal for an experienced network and security professional who enjoys solving complex technical problems, strengthening controls, supporting incident response, mentoring peers, and collaborating across infrastructure, cybersecurity, application, service desk, and vendor teams. This is an onsite position and it is not eligible for visa sponsorshipWhat You'll DoAs a Network Security Engineer, you will engineer and support the network and network-focused security services that connect and protect enterprise users, systems, and sites.You will:Design, deploy, and support datacenter and campus switching, routing, VLANs, VRFs, high availability, capacity planning, and network segmentation.Administer next-generation firewalls, security zones, NAT, threat-prevention services, firewall policy lifecycle, and least-privilege access controls.Engineer WAN, internet-edge, remote-site, remote-access VPN, and site-to-site VPN connectivity, including integrations with identity, MFA, and device-trust services.Design and support corporate and guest wireless, controllers, access points, RF performance, 802.1X, network access control, device profiling, and secure authentication.Configure load balancers, virtual servers, pools, health monitors, persistence, TLS termination, and high-availability services.Manage the network-facing certificate lifecycle and PKI integrations.Engineer and operate secure web and DNS controls, network detection and response, security logging, SIEM integrations, and security-control health monitoring.Partner with the Security Operations Center on alert tuning, investigations, evidence gathering, and operational security use cases.Support secure DNS, DHCP, and IP address management and maintain telemetry, flow data, logging, alerting, packet analysis, and service dashboards.Maintain secure configuration baselines, backups, firmware and software lifecycle, and remediation of network-device and security-tool vulnerabilities.Automate repeatable work using APIs, scripting, and infrastructure-as-code practices.Develop and test network and security-platform recovery and failover capabilities.Prepare change and rollback plans and provide incident escalation, containment support, root-cause analysis, and vendor coordination. This role also:Works independently within established standards and change processes.Provides technical leadership for projects and mentors peers.Participates in technology evaluations, proof-of-concepts, cross-functional initiatives, backup support, and knowledge transfer. What You BringBachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related field. Equivalent combination of education, training, and directly related work experience may be considered.Ideally 5+ years of progressive experience supporting enterprise network and network-security infrastructure, including switching, routing, firewall administration, VPN, wireless, and troubleshooting.Strong knowledge of enterprise LAN/WAN, datacenter switching, routing, firewalls, VPN, wireless, NAC, load balancing, PKI and certificates, DNS, DHCP, IPAM, and secure configuration management.Hands-on experience operating cybersecurity tooling such as secure web and DNS services, network detection and response, vulnerability management, SIEM and logging integrations, and security monitoring.Experience with network and security automation using Python, PowerShell, Ansible, Terraform, APIs, or comparable tools.Working knowledge of NIST CSF, CIS Controls, incident-response practices, and applicable regulatory or industry requirements, including NERC CIP where relevant to the IT environment.Strong analytical, troubleshooting, documentation, communication, collaboration, and customer-service skills. Preferred QualificationsEnterprise Network EngineeringExperience engineering highly available datacenter, campus, WAN, internet-edge, remote-site, wireless, and VPN services.Experience with segmentation, least-privilege access, identity and MFA integrations, device trust, and network access control.Experience with load balancing, TLS termination, application delivery, certificate lifecycle management, and PKI integrations.Network Security & DetectionExperience operating next-generation firewalls, threat-prevention services, secure web or DNS controls, network detection and response, and vulnerability-management processes.Experience integrating network-security telemetry with SIEM, logging, alerting, dashboards, and incident-response workflows.Experience partnering with a SOC on investigation, tuning, containment, evidence, or root-cause activities.Automation, Resilience & OperationsExperience automating network or security operations through scripting, APIs, Ansible, Terraform, or infrastructure as code.Experience developing recovery, failover, configuration-backup, firmware-lifecycle, and vulnerability-remediation practices.Experience preparing changes, rollback plans, technical documentation, performance measures, and vendor-supported resolutions.CertificationsRelevant credentials such as CCNA, CCNP, ACP, PCNSE or equivalent firewall-vendor certification, CWNA, Security+, CISSP, AZ-700, or similar certifications are preferred. Advantages of Working at GSOCWorking at GSOC means more than just a job it's an opportunity to contribute to work that truly matters. Mission-Driven ImpactYour work supports secure, reliable corporate network services and cybersecurity capabilities used across GSOC's enterprise environment. Network Engineering & Cybersecurity DepthApply both network engineering and hands-on security expertise across switching, routing, wireless, firewalls, VPN, application delivery, monitoring, automation, and incident support. Technical Leadership & Continuous ImprovementLead technical projects, mentor peers, evaluate new technologies, automate repeatable work, and strengthen resilience, visibility, and operational supportability. Strong Values and Professional StandardsWork in an environment grounded in accountability, collaboration, integrity, security, compliance, and continuous improvement. Work Environment & BenefitsGSOC offers a professional, collaborative work environment with competitive compensation, comprehensive benefits, and a commitment to creating a respectful and inclusive workplace.Participation in an on-call rotation, emergency support, and scheduled maintenance outside normal business hours is required. Why Join GSOCAt GSOC, you will help engineer the network and security services that enable dependable business operations, secure access, security visibility, and resilient enterprise technology.You'll collaborate across infrastructure, cybersecurity, applications, service desk, and vendor teams while expanding your technical leadership and automation capabilities. Apply TodayIf you're ready to combine enterprise network engineering and cybersecurity expertise in a hands-on role supporting reliable, protected operations, we encourage you to apply. GSOC does not accept unsolicited resumes or candidate submissions from staffing agencies, search firms, or third-party recruiters. Any unsolicited resumes submitted without a valid, executed agreement will become the property of GSOC, and no placement fee will be paid. Job Posted by ApplicantPro
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/28/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
09/28/2026
Full time
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
09/28/2026
Full time
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
Job Description Job Description "A World of Opportunities" Committed to an industry that combines innovation and responsibility, we embody our slogan on a daily basis: "A World of Opportunities". Trust, Reputation, Integrity and Rise are strong values that make up Clayens' DNA! Job Summary: The Network and Cybersecurity Engineer is responsible for the design, deployment, administration, and security of the organization's network and IT infrastructure. This role ensures the availability, performance, and protection of LAN, WAN, cloud, and hybrid environments while leading cybersecurity initiatives across multiple sites. The engineer works closely with local IT teams, business stakeholders, and group's cybersecurity team to implement secure technologies, investigate security incidents, manage network operations, and support strategic infrastructure projects. Supervisory Responsibilities: None Keys Responsibilities: Design, deploy, and maintain LAN/WAN/VLAN and wireless network infrastructure. Configure and support firewalls, VPNs, SASE, NAC, and network security solutions. Monitor, investigate, and remediate cybersecurity threats, incidents, and vulnerabilities. Maintain and improve cybersecurity controls, including EDR, PAM. Create and maintain network diagrams, technical documentation, and operational procedures. Provide technical support and guidance for network and security-related issues. Collaborate with regional and global IT teams on infrastructure and cybersecurity projects. Lead cybersecurity improvements for all North America locations. Required Qualifications and Experience: Degree in Information Technology, Computer Science, Cybersecurity, or related field. Experience administering enterprise networks, firewalls, routing, switching, and wireless technologies. Experience in cybersecurity investigation such as incident response, phishing, unusual sign-in, suspicious activities or any security alerts. Experience with Microsoft Windows Server, virtualization platforms, Azure and Microsoft Entra ID / Active Directory. Strong troubleshooting, analytical, and documentation skills. Excellent communication and collaboration skills, with the ability to provide clear insights and recommendations to leadership and cross-functional teams. Ability to work independently, exercise sound judgment, maintain confidentiality, and ensure alignment with organizational policies and compliance requirements. Preferred Qualifications and Experience Hands-on experience deploying Meraki wireless access points and FortiGate firewalls. Experience supporting HPE, Aruba switches. Experience with SASE, SIEM, SOAR, EDR, and PAM solutions. Familiarity with cybersecurity frameworks and compliance requirements, including NIS2, ISO 27001, ITAR, and CMMC. Expertise in Microsoft Entra ID and on-premises Active Directory within hybrid environments. Relevant networking or cybersecurity certifications. Experience supporting multi-site manufacturing environments and collaborating with international teams.
09/28/2026
Full time
Job Description Job Description "A World of Opportunities" Committed to an industry that combines innovation and responsibility, we embody our slogan on a daily basis: "A World of Opportunities". Trust, Reputation, Integrity and Rise are strong values that make up Clayens' DNA! Job Summary: The Network and Cybersecurity Engineer is responsible for the design, deployment, administration, and security of the organization's network and IT infrastructure. This role ensures the availability, performance, and protection of LAN, WAN, cloud, and hybrid environments while leading cybersecurity initiatives across multiple sites. The engineer works closely with local IT teams, business stakeholders, and group's cybersecurity team to implement secure technologies, investigate security incidents, manage network operations, and support strategic infrastructure projects. Supervisory Responsibilities: None Keys Responsibilities: Design, deploy, and maintain LAN/WAN/VLAN and wireless network infrastructure. Configure and support firewalls, VPNs, SASE, NAC, and network security solutions. Monitor, investigate, and remediate cybersecurity threats, incidents, and vulnerabilities. Maintain and improve cybersecurity controls, including EDR, PAM. Create and maintain network diagrams, technical documentation, and operational procedures. Provide technical support and guidance for network and security-related issues. Collaborate with regional and global IT teams on infrastructure and cybersecurity projects. Lead cybersecurity improvements for all North America locations. Required Qualifications and Experience: Degree in Information Technology, Computer Science, Cybersecurity, or related field. Experience administering enterprise networks, firewalls, routing, switching, and wireless technologies. Experience in cybersecurity investigation such as incident response, phishing, unusual sign-in, suspicious activities or any security alerts. Experience with Microsoft Windows Server, virtualization platforms, Azure and Microsoft Entra ID / Active Directory. Strong troubleshooting, analytical, and documentation skills. Excellent communication and collaboration skills, with the ability to provide clear insights and recommendations to leadership and cross-functional teams. Ability to work independently, exercise sound judgment, maintain confidentiality, and ensure alignment with organizational policies and compliance requirements. Preferred Qualifications and Experience Hands-on experience deploying Meraki wireless access points and FortiGate firewalls. Experience supporting HPE, Aruba switches. Experience with SASE, SIEM, SOAR, EDR, and PAM solutions. Familiarity with cybersecurity frameworks and compliance requirements, including NIS2, ISO 27001, ITAR, and CMMC. Expertise in Microsoft Entra ID and on-premises Active Directory within hybrid environments. Relevant networking or cybersecurity certifications. Experience supporting multi-site manufacturing environments and collaborating with international teams.
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
09/28/2026
Full time
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
09/28/2026
Full time
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/28/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
09/28/2026
Full time
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
Job Description Job Description CSfC Network Security EngineerOverview Tech(x) is an energized small company with experienced, specialized, and progressive thought leaders advancing talented professionals in technology, security, logistics, project management, talent management, and procurement. We are expanding our DoD and technology footprint by offering hybrid and remote work opportunities, along with flexible schedules. As a solution-based company, we foster a collaborative environment that welcomes innovation and new perspectives from all team members. Tech(x) is seeking a highly skilled CSfC Network Security Engineer to support the design, implementation, configuration, and sustainment of secure enterprise and tactical network architectures. The ideal candidate will possess deep expertise in networking, cybersecurity, virtualization, and systems administration, with experience supporting complex secure communications environments. Knowledge of National Security Agency (NSA) Commercial Solutions for Classified (CSfC) requirements is highly preferred. Responsibilities Design, configure, test, and troubleshoot secure network infrastructures independently and as part of a technical team. Configure, administer, and maintain multiple firewall platforms from various vendors. Configure and maintain VPN gateways, including both dynamic and static configurations. Implement Virtual Routing and Forwarding (VRF) solutions across complex network architectures. Design, architect, and troubleshoot enterprise networks containing multiple security enclaves and layered security controls. Design, configure, and secure network solutions that meet National Security Agency Commercial Solutions for Classified (CSfC) requirements and United States Army Communications Security (COMSEC) requirements. Configure log management platforms and alert dashboards as part of a Security Information and Event Management (SIEM) infrastructure. Deploy, configure, and secure both Microsoft Windows and Red Hat Enterprise Linux environments. Design and configure virtualized environments utilizing VMware solutions. Develop automation scripts utilizing PowerShell and Bash . Coordinate with customer representatives to identify architecture requirements, technical solutions, and issue resolution strategies. Develop professional technical documentation supporting architecture design, system configurations, maintenance procedures, and end-user training. Provide technical recommendations to improve security posture, network resiliency, and operational effectiveness. Perform other duties as assigned. Qualifications Demonstrated experience designing and supporting secure enterprise network environments. Strong expertise with networking and security technologies, including: Firewalls VPN Gateways Wireless Controllers Intrusion Prevention Systems (IPS) Intrusion Detection Systems (IDS) Hands-on experience configuring solutions from vendors such as: Hewlett Packard Enterprise Aruba Cisco Systems SonicWall Juniper Networks Experience with virtualization platforms and infrastructure management. Strong knowledge of routing, switching, and enterprise networking protocols. Experience supporting both Windows and Linux operating systems. Experience with scripting and automation tools. Strong technical writing and communication skills. Ability to work independently and collaboratively within a team environment. Ability to manage multiple priorities and adapt to evolving mission requirements. Preferred Qualifications Knowledge of National Security Agency CSfC architecture requirements Experience supporting secure DoD communications environments Experience with SIEM implementation and monitoring tools Experience supporting multi-enclave classified network architectures Familiarity with COMSEC processes and secure key management practices Preferred Certifications Certified Information Systems Security Professional CompTIA Security+ Certified Ethical Hacker Cisco Certified Network Associate / Cisco Certified Internetwork Expert Clearance: Current DoD Secret clearance required. Must be eligible to obtain a Top Secret clearance . Education & Experience: Bachelor's degree in Engineering, Computer Science, Cybersecurity, Information Technology, or related field Equivalent years of relevant experience may be substituted in lieu of degree requirements Minimum of 5-10 years of experience in Information Technology, Cybersecurity, or Enterprise Networking Location: Aberdeen Proving Grounds, Maryland. Monday-Friday Travel: Up to 20% travel required Join the Team: Tech(x) is a customer centric team, both external and internal customers. This team supports each other to be successful on the job and in meeting the mission. Tech(x) is an Equal Opportunity Employer.
09/28/2026
Full time
Job Description Job Description CSfC Network Security EngineerOverview Tech(x) is an energized small company with experienced, specialized, and progressive thought leaders advancing talented professionals in technology, security, logistics, project management, talent management, and procurement. We are expanding our DoD and technology footprint by offering hybrid and remote work opportunities, along with flexible schedules. As a solution-based company, we foster a collaborative environment that welcomes innovation and new perspectives from all team members. Tech(x) is seeking a highly skilled CSfC Network Security Engineer to support the design, implementation, configuration, and sustainment of secure enterprise and tactical network architectures. The ideal candidate will possess deep expertise in networking, cybersecurity, virtualization, and systems administration, with experience supporting complex secure communications environments. Knowledge of National Security Agency (NSA) Commercial Solutions for Classified (CSfC) requirements is highly preferred. Responsibilities Design, configure, test, and troubleshoot secure network infrastructures independently and as part of a technical team. Configure, administer, and maintain multiple firewall platforms from various vendors. Configure and maintain VPN gateways, including both dynamic and static configurations. Implement Virtual Routing and Forwarding (VRF) solutions across complex network architectures. Design, architect, and troubleshoot enterprise networks containing multiple security enclaves and layered security controls. Design, configure, and secure network solutions that meet National Security Agency Commercial Solutions for Classified (CSfC) requirements and United States Army Communications Security (COMSEC) requirements. Configure log management platforms and alert dashboards as part of a Security Information and Event Management (SIEM) infrastructure. Deploy, configure, and secure both Microsoft Windows and Red Hat Enterprise Linux environments. Design and configure virtualized environments utilizing VMware solutions. Develop automation scripts utilizing PowerShell and Bash . Coordinate with customer representatives to identify architecture requirements, technical solutions, and issue resolution strategies. Develop professional technical documentation supporting architecture design, system configurations, maintenance procedures, and end-user training. Provide technical recommendations to improve security posture, network resiliency, and operational effectiveness. Perform other duties as assigned. Qualifications Demonstrated experience designing and supporting secure enterprise network environments. Strong expertise with networking and security technologies, including: Firewalls VPN Gateways Wireless Controllers Intrusion Prevention Systems (IPS) Intrusion Detection Systems (IDS) Hands-on experience configuring solutions from vendors such as: Hewlett Packard Enterprise Aruba Cisco Systems SonicWall Juniper Networks Experience with virtualization platforms and infrastructure management. Strong knowledge of routing, switching, and enterprise networking protocols. Experience supporting both Windows and Linux operating systems. Experience with scripting and automation tools. Strong technical writing and communication skills. Ability to work independently and collaboratively within a team environment. Ability to manage multiple priorities and adapt to evolving mission requirements. Preferred Qualifications Knowledge of National Security Agency CSfC architecture requirements Experience supporting secure DoD communications environments Experience with SIEM implementation and monitoring tools Experience supporting multi-enclave classified network architectures Familiarity with COMSEC processes and secure key management practices Preferred Certifications Certified Information Systems Security Professional CompTIA Security+ Certified Ethical Hacker Cisco Certified Network Associate / Cisco Certified Internetwork Expert Clearance: Current DoD Secret clearance required. Must be eligible to obtain a Top Secret clearance . Education & Experience: Bachelor's degree in Engineering, Computer Science, Cybersecurity, Information Technology, or related field Equivalent years of relevant experience may be substituted in lieu of degree requirements Minimum of 5-10 years of experience in Information Technology, Cybersecurity, or Enterprise Networking Location: Aberdeen Proving Grounds, Maryland. Monday-Friday Travel: Up to 20% travel required Join the Team: Tech(x) is a customer centric team, both external and internal customers. This team supports each other to be successful on the job and in meeting the mission. Tech(x) is an Equal Opportunity Employer.
Job Description Job Description SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a seasoned Senior Network Security Engineer to join our dynamic security team. The ideal candidate will possess deep expertise in network security technologies, focusing on switching and routing systems within cloud-native and AI-focused infrastructure. You will thrive in a fast-paced, challenging environment, demonstrating adaptability, excellent multitasking skills, and the drive to tackle complex security issues independently while ensuring robust protection for our innovative technologies. RESPONSIBILITIES: Serve as a subject matter expert in network security, particularly firewalls, VPNs, IDS/IPS, routing protocols (e.g., BGP, OSPF), and switching technologies. Manage and update firewall configurations across our enterprise network to align with operational and security needs. Deploy new firewalls, switches, routers, and network security devices in response to evolving threats and demands. Develop and propose innovative network security solutions to address operational challenges in routing and switching environments. Enhance security processes through thorough documentation and change management. Act as the primary resolver for complex network security issues, including escalation support. Ensure network security systems, switches, and routers are up-to-date with patches, firmware, and maintenance. Monitor and respond to security events in cloud environments (e.g., AWS, GCP, Azure, Datacenter), with emphasis on network traffic analysis. BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. 4+ years of experience in network security engineering, with hands-on focus on switching and routing. Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred. Strong understanding of network security principles, protocols (e.g., TCP/IP, VLANs, ACLs), and best practices for secure routing and switching. Proficiency in at least one major cloud platform (AWS, GCP, or Azure) and its network security services (e.g., VPCs, Security Groups). Experience with network analysis tools such as Wireshark, tcpdump; and vendors including Cisco, Juniper, Palo Alto Networks. Familiarity with scripting languages (e.g., Python, Bash) for automation of network security tasks. PREFERRED SKILLS AND EXPERIENCE: Relevant network-specific certifications (e.g., CCNP Security, CCIE Security, JNCIP-SEC, PCNSE). Experience in multi-cloud environments and Infrastructure as Code tools like Terraform for network provisioning. Knowledge of DevSecOps practices tailored to network security integration. Experience building custom tools or integrations for enhancing network security operations. Interest in leveraging AI for network threat detection and automation. Contributions to open-source projects in network security or related tools. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
09/28/2026
Full time
Job Description Job Description SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a seasoned Senior Network Security Engineer to join our dynamic security team. The ideal candidate will possess deep expertise in network security technologies, focusing on switching and routing systems within cloud-native and AI-focused infrastructure. You will thrive in a fast-paced, challenging environment, demonstrating adaptability, excellent multitasking skills, and the drive to tackle complex security issues independently while ensuring robust protection for our innovative technologies. RESPONSIBILITIES: Serve as a subject matter expert in network security, particularly firewalls, VPNs, IDS/IPS, routing protocols (e.g., BGP, OSPF), and switching technologies. Manage and update firewall configurations across our enterprise network to align with operational and security needs. Deploy new firewalls, switches, routers, and network security devices in response to evolving threats and demands. Develop and propose innovative network security solutions to address operational challenges in routing and switching environments. Enhance security processes through thorough documentation and change management. Act as the primary resolver for complex network security issues, including escalation support. Ensure network security systems, switches, and routers are up-to-date with patches, firmware, and maintenance. Monitor and respond to security events in cloud environments (e.g., AWS, GCP, Azure, Datacenter), with emphasis on network traffic analysis. BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. 4+ years of experience in network security engineering, with hands-on focus on switching and routing. Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred. Strong understanding of network security principles, protocols (e.g., TCP/IP, VLANs, ACLs), and best practices for secure routing and switching. Proficiency in at least one major cloud platform (AWS, GCP, or Azure) and its network security services (e.g., VPCs, Security Groups). Experience with network analysis tools such as Wireshark, tcpdump; and vendors including Cisco, Juniper, Palo Alto Networks. Familiarity with scripting languages (e.g., Python, Bash) for automation of network security tasks. PREFERRED SKILLS AND EXPERIENCE: Relevant network-specific certifications (e.g., CCNP Security, CCIE Security, JNCIP-SEC, PCNSE). Experience in multi-cloud environments and Infrastructure as Code tools like Terraform for network provisioning. Knowledge of DevSecOps practices tailored to network security integration. Experience building custom tools or integrations for enhancing network security operations. Interest in leveraging AI for network threat detection and automation. Contributions to open-source projects in network security or related tools. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.