North Kansas City Hospital
North Kansas City, Missouri
SUMMARY:The Network Architect partners closely with IT leadership to shape long term infrastructure strategies and technology roadmaps. This includes providing expert guidance in the architecture, design, deployment, and lifecycle management of complex enterprise network systems. The role leads high impact initiatives such as building, testing, implementing, and troubleshooting advanced network solutions across the health system including design, implementation, and optimization to ensure high performance, security, and scalability. This role involves creating detailed network blueprints, selecting appropriate hardware and software, and ensuring seamless integration with existing systems.Key responsibilities include evaluation, recommendation, and championing emerging technologies that strengthen NKC Healths capabilities, supporting strategic objectives across health system environments. The Network Architect is accountable to ensure the Network Engineering team maintain accurate, comprehensive documentation for existing infrastructure as well as newly introduced systems and services. The NA is responsible for developing and reporting of network performance compared to benchmarks.Acting as a subject matter expert across a broad array of technologies, this role delivers technical oversight for all operations under the Network Engineering function and provides mentorship, and direction to ensure consistent execution of architectural standards, operational excellence, and continuous improvement. EXPERIENCE: Seven years experience designing, configuring, and troubleshooting enterprise network systems. Seven years experience managing Cisco routers, switches and managing Cisco Collaboration and VoIP systems. Six years experience managing Cisco and Palo Alto firewalls, as well as managing and troubleshooting wireless networks. SPECIAL SKILLS: Packet capture analysis and troubleshooting with Wireshark or like products. LICENSE/CERT: Required: CCNA (Cisco Certified Network Associate) Preferred: ASE (Architecture Systems Engineer ), CCNP (Cisco Certified Network Professional) EDUCATION: Preferred: Bachelors - Information Technology
10/02/2026
Full time
SUMMARY:The Network Architect partners closely with IT leadership to shape long term infrastructure strategies and technology roadmaps. This includes providing expert guidance in the architecture, design, deployment, and lifecycle management of complex enterprise network systems. The role leads high impact initiatives such as building, testing, implementing, and troubleshooting advanced network solutions across the health system including design, implementation, and optimization to ensure high performance, security, and scalability. This role involves creating detailed network blueprints, selecting appropriate hardware and software, and ensuring seamless integration with existing systems.Key responsibilities include evaluation, recommendation, and championing emerging technologies that strengthen NKC Healths capabilities, supporting strategic objectives across health system environments. The Network Architect is accountable to ensure the Network Engineering team maintain accurate, comprehensive documentation for existing infrastructure as well as newly introduced systems and services. The NA is responsible for developing and reporting of network performance compared to benchmarks.Acting as a subject matter expert across a broad array of technologies, this role delivers technical oversight for all operations under the Network Engineering function and provides mentorship, and direction to ensure consistent execution of architectural standards, operational excellence, and continuous improvement. EXPERIENCE: Seven years experience designing, configuring, and troubleshooting enterprise network systems. Seven years experience managing Cisco routers, switches and managing Cisco Collaboration and VoIP systems. Six years experience managing Cisco and Palo Alto firewalls, as well as managing and troubleshooting wireless networks. SPECIAL SKILLS: Packet capture analysis and troubleshooting with Wireshark or like products. LICENSE/CERT: Required: CCNA (Cisco Certified Network Associate) Preferred: ASE (Architecture Systems Engineer ), CCNP (Cisco Certified Network Professional) EDUCATION: Preferred: Bachelors - Information Technology
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
10/02/2026
Full time
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
10/02/2026
Full time
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
10/02/2026
Full time
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
10/02/2026
Full time
Hunter Douglas seeks an IT Senior Network Engineer to design, secure, and optimize enterprise networks that power our custom manufacturing and smart-home solutions. In this role, you will architect and manage LAN/WAN, wireless, VPN, and firewall infrastructure across plants and offices, ensuring high availability for production and corporate systems. You'll troubleshoot complex issues, drive upgrades, bolster network security, and collaborate closely with cross-functional teams. Ideal candidates bring strong Cisco/networking expertise, experience in high-uptime environments, and a passion for reliable, scalable infrastructure. Responsibilities Design, implement, and maintain secure, high-availability LAN/WAN and wireless networks across manufacturing and corporate sites Administer and optimize firewalls, VPNs, load balancers, and network monitoring tools Troubleshoot complex network issues, ensuring uptime for production, smart-factory, and office environments Plan and execute network upgrades, capacity planning, and lifecycle management Harden network security, enforce policies, and support compliance with corporate standards Collaborate with infrastructure, applications, and OT/plant teams on integrated solutions Document network designs, configurations, and diagrams; create runbooks and standards Participate in on-call rotation and provide Tier 3 escalation support Required Skills Network design and architecture (LAN/WAN/WLAN) Cisco routing and switching (IOS/NX-OS) Firewall administration (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower) VPN and remote access technologies Network security and segmentation Load balancers and traffic management Network monitoring and performance tools (e.g., Solar Winds, PRTG, Nagios) Qo S and voice/data convergence High availability and redundancy (HSRP/VRRP, clustering) IPv4/IPv6, BGP/OSPF/EIGRP routing protocols
Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
09/30/2026
Full time
Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
Job Description Job Description Job Description: Senior IT Network / Security Engineer Job Description: Provide billable consulting services to Colorado client base. Work in tandem with Account Managers to understand client business and technical objectives and deliver IT network and security infrastructure solutions that meet or exceed expectations. Work in a diverse, challenging environment where you use a thorough understanding of the interactions between infrastructure components. Design, optimize and troubleshoot deployments of networking and security for on-prem, hybrid cloud and cloud environments. Duties Include: Become a highly utilized consultant by providing outstanding technical skills that bring excellent value to clients. Evolve to where you become an integral part of clients' IT staff and become a trusted advisor. Develop content for Statements of Work network and security infrastructure consulting projects and deliver services per the Statement of Work. Ensure clear communications during all phases of the project with clients and sales personnel. Maintain and build technical expertise through training, teaming with other engineers and expanding your scope of skills. Become or maintain subject matter expertise in the product areas for which you are assigned. Work with sales staff to develop new business and expand existing business. Be eager to expand your knowledge of other infrastructure disciplines by teaming on projects with engineering staff and through professional training. Develop strong vendor relationships by becoming technically excellent in your understanding of their products and how to position and integrate those products in client environments. Assist in the development, monitoring and management of Managed Services offerings. Skills Required: 10-12 years of IT networking, security, compute and storage experience. This knowledge may have come from a tier 2 or 3 engineer role or similar position - Solid knowledge of TCP/IP stack and networking protocols that include OSPF, BGP, EIGRP, MPLS or others - Architect, deploy, manage, document and monitor networks which include switches, routers, VPNs, remote access, SD-WAN and security devices including firewalls, IDS, A/V, SIEM and other security or network components. - Broad experience in multiple security and networking products (Cisco, Palo Alto, Ruckus, Check Point or Fortinet) and monitoring tools (SolarWinds, LogicMonitor, PRTG and/or other) - Excellent listening and communication skills with an ability to work with a wide range of personalities and varying degrees of technical expertise and management levels. - Strong attention to detail with an analytical mind and outstanding problem-solving skills. About The Root Group: The Root Group is a locally owned IT solution provider / reseller that has been in business for over 35 years that focuses on commercial IT infrastructure and renewable energy sites (solar, battery, wind). We provide a full line of professional services and products for the design, implementation, management and support of IT infrastructure. Each Root Group engineer has many years of tenure at the company and our work environment provides a rewarding level of autonomy and collaboration to rapidly grow your knowledge in all phases of IT infrastructure. Our clients regularly recognize the high level of technical skills and professionalism that each engineer brings an engagement. The Root Group offers a competitive compensation and benefits plan and you will become an integral part of a great team in which you make a significant impact on the company's success!
09/30/2026
Full time
Job Description Job Description Job Description: Senior IT Network / Security Engineer Job Description: Provide billable consulting services to Colorado client base. Work in tandem with Account Managers to understand client business and technical objectives and deliver IT network and security infrastructure solutions that meet or exceed expectations. Work in a diverse, challenging environment where you use a thorough understanding of the interactions between infrastructure components. Design, optimize and troubleshoot deployments of networking and security for on-prem, hybrid cloud and cloud environments. Duties Include: Become a highly utilized consultant by providing outstanding technical skills that bring excellent value to clients. Evolve to where you become an integral part of clients' IT staff and become a trusted advisor. Develop content for Statements of Work network and security infrastructure consulting projects and deliver services per the Statement of Work. Ensure clear communications during all phases of the project with clients and sales personnel. Maintain and build technical expertise through training, teaming with other engineers and expanding your scope of skills. Become or maintain subject matter expertise in the product areas for which you are assigned. Work with sales staff to develop new business and expand existing business. Be eager to expand your knowledge of other infrastructure disciplines by teaming on projects with engineering staff and through professional training. Develop strong vendor relationships by becoming technically excellent in your understanding of their products and how to position and integrate those products in client environments. Assist in the development, monitoring and management of Managed Services offerings. Skills Required: 10-12 years of IT networking, security, compute and storage experience. This knowledge may have come from a tier 2 or 3 engineer role or similar position - Solid knowledge of TCP/IP stack and networking protocols that include OSPF, BGP, EIGRP, MPLS or others - Architect, deploy, manage, document and monitor networks which include switches, routers, VPNs, remote access, SD-WAN and security devices including firewalls, IDS, A/V, SIEM and other security or network components. - Broad experience in multiple security and networking products (Cisco, Palo Alto, Ruckus, Check Point or Fortinet) and monitoring tools (SolarWinds, LogicMonitor, PRTG and/or other) - Excellent listening and communication skills with an ability to work with a wide range of personalities and varying degrees of technical expertise and management levels. - Strong attention to detail with an analytical mind and outstanding problem-solving skills. About The Root Group: The Root Group is a locally owned IT solution provider / reseller that has been in business for over 35 years that focuses on commercial IT infrastructure and renewable energy sites (solar, battery, wind). We provide a full line of professional services and products for the design, implementation, management and support of IT infrastructure. Each Root Group engineer has many years of tenure at the company and our work environment provides a rewarding level of autonomy and collaboration to rapidly grow your knowledge in all phases of IT infrastructure. Our clients regularly recognize the high level of technical skills and professionalism that each engineer brings an engagement. The Root Group offers a competitive compensation and benefits plan and you will become an integral part of a great team in which you make a significant impact on the company's success!
Job Description Job Description 4. Scope of Servies The Florida Department of Transportation, Office of Information Technology (OIT) - Integration Services is in search of a Senior Network Engineer to play a key role in assisting the Office of Information Technology in the establishment of new integration methods and standards, along with implementing system integrations, according to those established methods and standards. Duties and Responsibilities will include but are not limited to: 1. Perform security administration to configure and document firewall infrastructure access rules and work with peripheral network components in the technology environment with Palo Alto, Checkpoint and Global Protect VPNs. 2. Firewall deployments, rule migrations, firewall administration and converting existing rule based policies onto new platforms. 3. Works with critical core network infrastructure devices like Next Gen Firewall, VPNs, log collectors and monitors which play a crucial role in security for our IT environment. 4. Works with cloud network infrastructure to configure firewall, security policies and monitor network traffic. 5. Develop and maintain documentation following NIST guidelines. 6. Project Manager; 7. Data Administration; 5 Education Bachelor's Degree in Computer Science, Information Systems or other related field. Or equivalent work experience. Preferred Certifications (PCNSE, CISSP, CCNP, CCIE) 6. Experience 1. Typically have 5 to 10 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, database design and administration 2. Three to five years of experience with information security tools based on NIST standards. 3. Requires knowledge of security issues, techniques, and implications across all existing computer platforms. Preference given for experience with NGFW Palo Alto or Checkpoint security products. 4. Experience using schematic diagramming tools to map infrastructure layouts. 7 Primary Job Duties/ Tasks Senior Network Engineer - Job Duties 1. Develops, implements, and manages enterprise security solutions across multiple IT functional areas, including network infrastructure, data, systems, cloud environments, telecommunications, and Web-based services. Designs and maintains secure network architectures, segmentation strategies, access controls, firewalls, VPNs, encryption technologies, and other security controls. 2. Develops, implements, and maintains enterprise security policies, standards, procedures, and technical controls governing user authentication, privileged access, network access, security monitoring, vulnerability management, firewall administration, encryption, remote access, and incident escalation. Ensures security practices align with organizational requirements, industry standards, and applicable regulatory requirements. 3. Performs security risk assessments and develops risk-based response strategies for enterprise network and infrastructure environments. Prepares executive-level status reports, risk assessments, security metrics, and recommendations addressing vulnerabilities, emerging threats, security incidents, and operational risks. 4. Monitors, analyzes, and responds to cybersecurity threats and security events, including malware, software vulnerabilities, unauthorized access attempts, network anomalies, and policy violations. Administers and monitors security profiles and access controls, reviews security alerts and violation reports, investigates security exceptions, and coordinates remediation activities. Maintains comprehensive documentation of security controls, configurations, incidents, and corrective actions. 5. Evaluates emerging network and security technologies, products, and procedures to improve infrastructure reliability, security, performance, and operational efficiency. Leads technical evaluations, proof-of-concept activities, product assessments, and implementation recommendations for enterprise networking and cybersecurity solutions. 6. Provides advanced technical support and consultation to business and IT stakeholders on complex network, infrastructure, and cybersecurity issues. Troubleshoots escalated network and security incidents, provides technical guidance to infrastructure teams, and educates IT and business personnel on security policies, secure configurations, access requirements, and risk mitigation practices. 7. Provides security expertise and technical leadership throughout the IT project lifecycle, including requirements development, architecture and design, implementation, testing, deployment, and operational support. Reviews project designs and proposed solutions to identify security risks and ensures appropriate security controls are incorporated into network, cloud, application, and infrastructure initiatives. 8. Designs, implements, and supports enterprise network infrastructure, including LAN/WAN, routing and switching, wireless networks, firewalls, VPNs, network segmentation, Internet connectivity, cloud connectivity, and data center infrastructure. Develops network solutions that support high availability, resiliency, scalability, and security requirements. 9. Leads the investigation and resolution of complex network and security incidents, utilizing network monitoring, logging, packet analysis, performance data, and security tools to identify root causes and implement corrective actions. Coordinates with vendors, technical teams, and organizational stakeholders during critical incidents and service disruptions. 10. Develops network security architecture and segmentation strategies designed to limit lateral movement, protect critical systems, isolate sensitive workloads, and establish appropriate security boundaries between users, applications, devices, and infrastructure. Evaluates east-west and north-south traffic flows to identify security risks and opportunities for improved network controls. 11. Establishes and monitors network performance and security metrics to identify trends, capacity requirements, vulnerabilities, and potential operational risks. Develops dashboards, key performance indicators, and management reports to support data-driven infrastructure and security decisions. 12. Maintains technical documentation and configuration standards for network and security infrastructure, including network diagrams, IP addressing, VLANs, firewall rules, access controls, security configurations, operational procedures, and disaster recovery requirements. Ensures documentation remains accurate and aligned with the current enterprise environment. 13. Collaborates with architecture, cybersecurity, systems, database, application, cloud, telecommunications, and infrastructure teams to develop integrated technology solutions. Serves as a senior technical resource and provides guidance on enterprise networking, security architecture, infrastructure design, and technology modernization. 14. Provides technical leadership and mentoring to network and security staff, establishes network engineering standards and best practices, reviews technical solutions, and assists with the development of team capabilities in enterprise networking, cybersecurity, cloud infrastructure, and emerging technologies. Senior-Level Requirements Must have extensive knowledge and demonstrated experience in enterprise networking, cybersecurity, systems, databases, cloud infrastructure, and/or Web operations. The senior-level Network Engineer is responsible for developing and implementing enterprise network and security strategies, leading complex technical projects, designing secure and resilient infrastructure, resolving the most complex network and security issues, conducting risk assessments, evaluating emerging technologies, and providing technical guidance to IT and business leadership. The position requires advanced knowledge of network architecture, routing and switching, firewalls, VPN technologies, network segmentation, wireless infrastructure, cloud networking, identity and access management, security monitoring, incident response, vulnerability management, disaster recovery, and enterprise security controls. 8 Job Specific Skills and Abilities (KSAs): Intermediate professional level role. Works independently or on multiple IT security projects as a project team member, occasionally as a project leader. Works on small to large, complex security issues or projects that require increased skill in multiple IT functional areas. May coach more junior staff. 9 General Knowledge Skills and Abilities (KSAs): The submitted candidate must be able to apply common knowledge, skills, and abilities in the following areas: 1. Communication: Have the ability to clearly convey information, in both written and verbal formats, to individuals or groups in a wide variety of settings (i.e.; project team meetings, management presentations, etc.). Must have the ability to effectively listen and process information provided by others. 2. Customer Service: Works well with clients and customers (i.e.; business office, public, or other agencies). Able to assess the needs of the customer, provide information or assistance to satisfy expectations or resolve a problem. 3. Decision Making: Makes sound, well-informed, and objective decisions. 4. Flexibility: Is open to change, new processes (or process improvement), and new information. Has the ability to adapt in response to new information, changing conditions . click apply for full job details
09/30/2026
Full time
Job Description Job Description 4. Scope of Servies The Florida Department of Transportation, Office of Information Technology (OIT) - Integration Services is in search of a Senior Network Engineer to play a key role in assisting the Office of Information Technology in the establishment of new integration methods and standards, along with implementing system integrations, according to those established methods and standards. Duties and Responsibilities will include but are not limited to: 1. Perform security administration to configure and document firewall infrastructure access rules and work with peripheral network components in the technology environment with Palo Alto, Checkpoint and Global Protect VPNs. 2. Firewall deployments, rule migrations, firewall administration and converting existing rule based policies onto new platforms. 3. Works with critical core network infrastructure devices like Next Gen Firewall, VPNs, log collectors and monitors which play a crucial role in security for our IT environment. 4. Works with cloud network infrastructure to configure firewall, security policies and monitor network traffic. 5. Develop and maintain documentation following NIST guidelines. 6. Project Manager; 7. Data Administration; 5 Education Bachelor's Degree in Computer Science, Information Systems or other related field. Or equivalent work experience. Preferred Certifications (PCNSE, CISSP, CCNP, CCIE) 6. Experience 1. Typically have 5 to 10 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, database design and administration 2. Three to five years of experience with information security tools based on NIST standards. 3. Requires knowledge of security issues, techniques, and implications across all existing computer platforms. Preference given for experience with NGFW Palo Alto or Checkpoint security products. 4. Experience using schematic diagramming tools to map infrastructure layouts. 7 Primary Job Duties/ Tasks Senior Network Engineer - Job Duties 1. Develops, implements, and manages enterprise security solutions across multiple IT functional areas, including network infrastructure, data, systems, cloud environments, telecommunications, and Web-based services. Designs and maintains secure network architectures, segmentation strategies, access controls, firewalls, VPNs, encryption technologies, and other security controls. 2. Develops, implements, and maintains enterprise security policies, standards, procedures, and technical controls governing user authentication, privileged access, network access, security monitoring, vulnerability management, firewall administration, encryption, remote access, and incident escalation. Ensures security practices align with organizational requirements, industry standards, and applicable regulatory requirements. 3. Performs security risk assessments and develops risk-based response strategies for enterprise network and infrastructure environments. Prepares executive-level status reports, risk assessments, security metrics, and recommendations addressing vulnerabilities, emerging threats, security incidents, and operational risks. 4. Monitors, analyzes, and responds to cybersecurity threats and security events, including malware, software vulnerabilities, unauthorized access attempts, network anomalies, and policy violations. Administers and monitors security profiles and access controls, reviews security alerts and violation reports, investigates security exceptions, and coordinates remediation activities. Maintains comprehensive documentation of security controls, configurations, incidents, and corrective actions. 5. Evaluates emerging network and security technologies, products, and procedures to improve infrastructure reliability, security, performance, and operational efficiency. Leads technical evaluations, proof-of-concept activities, product assessments, and implementation recommendations for enterprise networking and cybersecurity solutions. 6. Provides advanced technical support and consultation to business and IT stakeholders on complex network, infrastructure, and cybersecurity issues. Troubleshoots escalated network and security incidents, provides technical guidance to infrastructure teams, and educates IT and business personnel on security policies, secure configurations, access requirements, and risk mitigation practices. 7. Provides security expertise and technical leadership throughout the IT project lifecycle, including requirements development, architecture and design, implementation, testing, deployment, and operational support. Reviews project designs and proposed solutions to identify security risks and ensures appropriate security controls are incorporated into network, cloud, application, and infrastructure initiatives. 8. Designs, implements, and supports enterprise network infrastructure, including LAN/WAN, routing and switching, wireless networks, firewalls, VPNs, network segmentation, Internet connectivity, cloud connectivity, and data center infrastructure. Develops network solutions that support high availability, resiliency, scalability, and security requirements. 9. Leads the investigation and resolution of complex network and security incidents, utilizing network monitoring, logging, packet analysis, performance data, and security tools to identify root causes and implement corrective actions. Coordinates with vendors, technical teams, and organizational stakeholders during critical incidents and service disruptions. 10. Develops network security architecture and segmentation strategies designed to limit lateral movement, protect critical systems, isolate sensitive workloads, and establish appropriate security boundaries between users, applications, devices, and infrastructure. Evaluates east-west and north-south traffic flows to identify security risks and opportunities for improved network controls. 11. Establishes and monitors network performance and security metrics to identify trends, capacity requirements, vulnerabilities, and potential operational risks. Develops dashboards, key performance indicators, and management reports to support data-driven infrastructure and security decisions. 12. Maintains technical documentation and configuration standards for network and security infrastructure, including network diagrams, IP addressing, VLANs, firewall rules, access controls, security configurations, operational procedures, and disaster recovery requirements. Ensures documentation remains accurate and aligned with the current enterprise environment. 13. Collaborates with architecture, cybersecurity, systems, database, application, cloud, telecommunications, and infrastructure teams to develop integrated technology solutions. Serves as a senior technical resource and provides guidance on enterprise networking, security architecture, infrastructure design, and technology modernization. 14. Provides technical leadership and mentoring to network and security staff, establishes network engineering standards and best practices, reviews technical solutions, and assists with the development of team capabilities in enterprise networking, cybersecurity, cloud infrastructure, and emerging technologies. Senior-Level Requirements Must have extensive knowledge and demonstrated experience in enterprise networking, cybersecurity, systems, databases, cloud infrastructure, and/or Web operations. The senior-level Network Engineer is responsible for developing and implementing enterprise network and security strategies, leading complex technical projects, designing secure and resilient infrastructure, resolving the most complex network and security issues, conducting risk assessments, evaluating emerging technologies, and providing technical guidance to IT and business leadership. The position requires advanced knowledge of network architecture, routing and switching, firewalls, VPN technologies, network segmentation, wireless infrastructure, cloud networking, identity and access management, security monitoring, incident response, vulnerability management, disaster recovery, and enterprise security controls. 8 Job Specific Skills and Abilities (KSAs): Intermediate professional level role. Works independently or on multiple IT security projects as a project team member, occasionally as a project leader. Works on small to large, complex security issues or projects that require increased skill in multiple IT functional areas. May coach more junior staff. 9 General Knowledge Skills and Abilities (KSAs): The submitted candidate must be able to apply common knowledge, skills, and abilities in the following areas: 1. Communication: Have the ability to clearly convey information, in both written and verbal formats, to individuals or groups in a wide variety of settings (i.e.; project team meetings, management presentations, etc.). Must have the ability to effectively listen and process information provided by others. 2. Customer Service: Works well with clients and customers (i.e.; business office, public, or other agencies). Able to assess the needs of the customer, provide information or assistance to satisfy expectations or resolve a problem. 3. Decision Making: Makes sound, well-informed, and objective decisions. 4. Flexibility: Is open to change, new processes (or process improvement), and new information. Has the ability to adapt in response to new information, changing conditions . click apply for full job details
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
09/30/2026
Full time
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/29/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/28/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/28/2026
Full time
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/28/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
09/28/2026
Full time
Job Description Job Description Lead Firewall EngineerClearance: Active TS/SCIExperience: 8+ yearsLead an enterprise boundary security team responsible for firewall operations, engineering, compliance, and modernization. You will provide technical direction, oversee complex troubleshooting, and support secure, reliable network performance.What You Will DoLead daily firewall operations, maintenance, troubleshooting, and project execution.Design and implement solutions using Palo Alto, Juniper SRX, and F5 technologies.Review network changes and assess operational and security impacts.Maintain secure configuration baselines, architecture diagrams, inventories, procedures, and technical documentation.Monitor performance, logs, software versions, and configuration drift.Lead compliance reviews, technical evaluations, and modernization efforts.Brief stakeholders and mentor engineering personnel.What You BringActive TS/SCI clearance with the ability to obtain and maintain a CI polygraph.At least eight years of network security experience, including five years supporting large enterprise networks.Experience leading a firewall or boundary security team.Advanced experience with Palo Alto, Juniper SRX, and F5 platforms.Strong knowledge of firewall policy, TLS/SSL, PKI, Kerberos, LDAP, Active Directory, SAML, OAuth, and network architecture.Experience with network design, implementation, cost estimates, and labor estimates.Current DoD 8140/8570 IAT Level II certification.Ability to obtain CSSP Infrastructure Support certification within 120 days.Availability for occasional evening or weekend work.Preferred QualificationsBachelor 's or master's degree in computer science, cybersecurity, network security, or a related field.F5, Juniper, or Palo Alto professional certification. Job Posted by ApplicantPro
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
09/28/2026
Full time
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
09/28/2026
Full time
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
09/28/2026
Full time
Job Description Job Description Network Operations - Firewall Operations Engineer Position Description Description This is an opening for a Firewall Engineer to support a Department of State (DoS) Bureau of Diplomatic Technology (DT) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. DT provides enterprise architecture design, engineering, operations and maintenance support services for servers, networks, firewalls, and enterprise applications across the Department. This is a firewall engineer position, providing general Tier 2 monitoring, configuration, and support to multiple firewalls and perimeter security systems. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally. This is a hybrid position based out of Beltsville, MD with 3 days on-site. Shift is Day's (7:00am-3:30pm), Tuesday-Saturday after training. During the 6-8-week training period, it will be 5 days on-site Mon-Fri (7:00am-3:30pm). Your responsibilities will include: Provides Tier 2 support in the monitoring, management, and troubleshooting of perimeter devices to include firewalls, proxies, and mail transport agents. Monitor Service Now application for Firewall Operations (FWOPS) incident and service requests. Implements firewall rules and policies, perform troubleshooting of firewalls (Palo Alto, Cloud Palo Alto, and FortiGate), CISCO Email Security Appliance (ESA), A10 (load balancer), Proxy platforms, URL filtering across platforms, and analyzing network traffic captures. Escalates issues as required to Tier 3 staff and monitors issues throughout a problem's life cycle. Performs recurring maintenance activities such as device reboots and software upgrades on all devices underneath the Firewall Operations Team. Records and reports on firewall operations, utilization, and maintenance. Collaborate across Bureaus and Agencies to implement and repair network changes as they relate to perimeter security devices. Support Diplomatic Security Computer Incident Response Team (CIRT) by implementing block requests for IP's, Websites, and Email addresses. Update architecture diagrams using Visio. Monitor and perform health checks on multiple perimeter security devices. Draft, coordinate and publish outage notifications as required. Update shift logs and provide reports to leadership as needed. Maintain standard operating procedures (SOP), work instructions, and other working documents. Attend calls requiring a FWOPS team to attend, to include troubleshooting calls. Required Education & Experience: BA degree and 2-4 years of experience, may accept additional experience in lieu of degree. In Depth experience using Palo Alto Firewalls and Panorama monitoring tools to troubleshoot and configure a Firewall infrastructure. Strong understanding of networking, proxy, and packet filtering technologies. Minimum 3-5 years of IT Customer Support experience (Tier I and/or Tier II). First-hand experience with supporting the monitoring and configuration of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, Palo Alto virtual FW (cloud), FortiGate, Azure Firewall, Cloudflare, Cisco Email Security Appliances (ESA), A10 (Load Balancer), and proxy devices. CLI experience preferred. Experienced in utilizing network monitoring tools such as NeuralStar. Experienced with TCP/IP network implementation and troubleshooting. Required Clearance US Citizenship. An Interim Secret clearance is required to start work and requires eligibility to obtain a Top-Secret clearance. Powered by JazzHR 2IrLa6mmdU
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/28/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Benefits: Onsite Competitive salary Opportunity for advancement About the Role: Select Minds LLC is looking for a talented Network Security Engineer to join our growing team in Dallas, TX. This is an exciting opportunity to protect critical infrastructure, design robust security solutions, and work alongside a team of passionate technology professionals. If you thrive in a fast-paced environment and love solving complex security challenges, we want to hear from you! Responsibilities: Design, implement, and maintain network security architectures, firewalls, and intrusion detection/prevention systems (IDS/IPS) Monitor network traffic for suspicious activity and respond to security incidents and threats in real time Perform vulnerability assessments, penetration testing, and risk analysis across network infrastructure Configure and manage VPNs, access control lists (ACLs), and zero-trust network policies Collaborate with IT and DevOps teams to ensure security best practices are integrated into all systems Develop and maintain security documentation, policies, and incident response procedures Stay current with emerging cybersecurity threats, trends, and compliance requirements (NIST, ISO 27001, etc.) Requirements: 3+ years of experience in network security engineering or a related cybersecurity role Proficiency with firewalls, SIEM tools, and network monitoring platforms (e.g., Cisco, Palo Alto, Splunk) Strong understanding of TCP/IP, DNS, VPN, and network protocols Experience with cloud security environments (AWS, Azure, or GCP) is a plus Relevant certifications such as CISSP, CCNP Security, CEH, or CompTIA Security+ preferred Strong analytical and problem-solving skills with keen attention to detail Excellent communication skills and ability to work both independently and collaboratively About Us: Select Minds LLC is a forward-thinking technology firm based in Dallas, TX, dedicated to delivering innovative IT and security solutions to businesses of all sizes. Our clients trust us to safeguard their most critical assets, and our team takes that responsibility seriously. We foster a culture of continuous learning, collaboration, and growth - making Select Minds a place where talented professionals truly thrive.
09/28/2026
Full time
Job Description Job Description Benefits: Onsite Competitive salary Opportunity for advancement About the Role: Select Minds LLC is looking for a talented Network Security Engineer to join our growing team in Dallas, TX. This is an exciting opportunity to protect critical infrastructure, design robust security solutions, and work alongside a team of passionate technology professionals. If you thrive in a fast-paced environment and love solving complex security challenges, we want to hear from you! Responsibilities: Design, implement, and maintain network security architectures, firewalls, and intrusion detection/prevention systems (IDS/IPS) Monitor network traffic for suspicious activity and respond to security incidents and threats in real time Perform vulnerability assessments, penetration testing, and risk analysis across network infrastructure Configure and manage VPNs, access control lists (ACLs), and zero-trust network policies Collaborate with IT and DevOps teams to ensure security best practices are integrated into all systems Develop and maintain security documentation, policies, and incident response procedures Stay current with emerging cybersecurity threats, trends, and compliance requirements (NIST, ISO 27001, etc.) Requirements: 3+ years of experience in network security engineering or a related cybersecurity role Proficiency with firewalls, SIEM tools, and network monitoring platforms (e.g., Cisco, Palo Alto, Splunk) Strong understanding of TCP/IP, DNS, VPN, and network protocols Experience with cloud security environments (AWS, Azure, or GCP) is a plus Relevant certifications such as CISSP, CCNP Security, CEH, or CompTIA Security+ preferred Strong analytical and problem-solving skills with keen attention to detail Excellent communication skills and ability to work both independently and collaboratively About Us: Select Minds LLC is a forward-thinking technology firm based in Dallas, TX, dedicated to delivering innovative IT and security solutions to businesses of all sizes. Our clients trust us to safeguard their most critical assets, and our team takes that responsibility seriously. We foster a culture of continuous learning, collaboration, and growth - making Select Minds a place where talented professionals truly thrive.