Lead Firewall Engineer

D2 Consulting

Springfield (VA)

On-site

USD 140,000 - 150,000

Full time

13 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid time off
Professional development

Job summary

D2 Consulting is seeking a Lead Firewall Engineer in Springfield, VA to oversee the NSS Boundary Team and ensure compliance with QA and SLAs. You will lead daily operations, review CRQs, and provide technical oversight for troubleshooting and solution development.

Required are a TS/SCI clearance and 8+ years in network security, with hands-on experience across F5, Palo Alto, and Juniper SRX platforms. Strong DoD framework knowledge is essential.

Qualifications

  • Active TS/SCI clearance required
  • 8+ years in network security technologies and tools
  • 5+ years with large-scale enterprise/global networks
  • Experience with DoD Architecture Framework and DoW/IC standards
  • Demonstrated leadership of a Firewall/Boundary Security Team
  • Experience with Perimeter and Internal Firewalls (physical/virtual)
  • Advanced experience with baseline configurations and rule evaluation for security
  • Experience with F5, Palo Alto, Juniper SRX platforms
  • Knowledge of DoD PKI, Kerberos, LDAP/AD, SAML, OAuth
  • Willing to work weekends/evenings and obtain CI polygraph

Responsibilities

  • Serve as focal point for all firewall tasks, operations and projects
  • Lead daily operations, troubleshooting, and maintenance for NSS Boundary work center
  • Design and implement security solutions using F5, Juniper SRX, Palo Alto
  • Ensure systems meet STIG/SRG and baseline configurations
  • Conduct regular compliance evaluations and audits
  • Develop and maintain configuration management and SOPs
  • Monitor performance, logs, versioning, and configuration drift
  • Create network diagrams, inventories, and licensing status
  • Provide reports and briefings to contract and government leadership
  • Coordinate with stakeholders to ensure task completion and satisfaction
  • Evaluate new customer requests and emerging network technologies
  • Recommend changes to address performance and standardization
  • Mentor and coach personnel

Skills

Firewall engineering
TS/SCI clearance
Team leadership
F5/AFM/SSLO
Palo Alto
Juniper SRX
DoD standards
TLS/SSL

Education

BS in Computer Science / Cyber Security
MS preferred

Tools

F5
Palo Alto
Juniper SRX
OCSP
LDAP/AD

Job description

  • ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED**
  • ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED**

D2 is looking for a Lead Firewall Engineer to oversee the NSS Boundary Team. This role will report directly to the Branch Chief of Cyber Technology Services. This position is responsible for maintaining compliance with quality assurance standards and ensuring service level agreements are met or exceeded within this service area.

Experience in reviewing, validating, and implementing requirements within enterprise Change Requests (CRQs) and determining impacts to network and cyber operations across the enterprise. This role is also responsible for providing technical oversight of troubleshooting efforts and solutions development executed by the subordinate team.

Responsibilities:
  • Serve as the focal point for all firewall tasks, operations, and projects
  • Lead, direct, and manage execution of all daily operations, troubleshooting, and maintenance activities of the NSS Boundary work center.
  • Design, implement Manage security solutions using F5, Juniper SRX, and Palo Alto for project-based requirements.
  • Ensure systems, devices, and application under your responsibility and span of control meet applicable STIG/SRG and organizational configuration baselines
    • Lead regular compliance evaluations and audits
    • Develop, oversee, maintain, and enforce configuration management processes, Standard Operational Procedures (SOPs), and other documentation as needed/required.
  • Monitor platform performance, logs, software version(s), and configuration drift to identify and mitigate performance, compliance, and security issues.
  • Develop and maintain network architecture diagrams, inventories, and licensing status for the various capabilities within the scope of the team.
  • Provide written reports and oral briefings to contract and government leadership
  • Coordinate issues with the appropriate stakeholders to ensure task completeness and overall customer satisfaction.
  • Provide recommendations on newly submitted customer requests.
  • Evaluate and report on new/emerging network/communication technologies to enhance capacity, performance and reliability of the network.
  • Evaluate and recommend changes and/or technology upgrades to address performance, standardization and industry best practices.
  • Conduct performance assessments, mentor, and coach personnel.
Qualifications:
Required:
  • Security Clearance: Active TS/SCI
  • 8+ years related technical experience network security technologies, tools, and techniques
  • 5+ years' experience with large-scale enterprise/global networks in a high paced diverse environment
  • Understanding and experience with the DoD Architecture Framework and other key DoD network architecture and strategic planning instructions
  • Demonstrated knowledge in planning, directing, and managing a Firewall / Boundary Security Team in an organization similar in size
  • Firewall experience within the DoW or IC
  • Demonstrated knowledge of implementation of Perimeter and Internal Firewalls (both physical and virtual contexts)
  • Demonstrated advanced experience in managing baseline configurations across numerous firewalls
  • Demonstrated advanced experience in evaluating rules to ensure maximum security while minimizing redundancy and processing overhead
  • Demonstrated experience with researching and fielding new and innovative firewall technology
  • Experience with F5 platforms/technologies (APM, AFM, SSLO, etc.)
  • Experience with Palo Alto platforms/technologies (Threat Prevention, Wildfire, URL Filtering, Global Protect)
  • Experience with Juniper SRX platforms/technologies
  • Experience with Online Certificate Status Protocol OCSP revocation
  • Familiar with DoD PKI, Kerberos, LDAP, Active Directory, Authentication (SAML, OAuth)
  • Ability to describe and troubleshoot TLS/SSL handshake/connection issues
  • Network design, engineering, and implementation (Advanced Level)
  • Creation of network related Rough Order Magnitude (ROM) equipment lists and costing, Level of Effort (LOE) estimation for labor
  • Understanding of DoW, DISA, and IC standards and processes
  • Ability to work weekends and evening hours as needed
  • Ability to obtain and maintain a CI polygraph
  • S6DoD 8140.01 and DoD 8570.01-M IAT Level II compliant certification (current). Must be able to successfully obtain/maintain CSSP Infrastructure Support certification within 120 days.
Desired:
  • BS or MS degree in Computer Science, Cyber Security, Network Security or related field
  • F5 Networks certifications
  • Juniper JNCIS/JNCIP, Palo Alto PCNSE (or equivalent)
Additional Information
  • All your information will be kept confidential according to EEO guidelines.
  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $140-$150k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Accrued PTO, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and more!

D2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals. As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience. Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Firewall Engineer New Springfield, VA
Lead Firewall Engineer New Springfield, VA

D2 Consulting • Springfield (VA), Northern (KY)

Hybrid
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
PTO
+3
Lead Firewall Engineer
Lead Firewall Engineer

D2 Technical Services • Springfield (VA)

On-site
USD 140,000 - 150,000
Lead Firewall Engineer
Lead Firewall Engineer

Abile Group, Inc • Springfield (VA)

On-site
USD 150,000 - 185,000
Senior Firewall Engineer
Senior Firewall Engineer

D2 Consulting • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Senior Firewall Engineer
Senior Firewall Engineer

D2 Technical Services • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
PTO
+3
Lead Firewall Engineer | TS/SCI Clearance
Lead Firewall Engineer | TS/SCI Clearance

D2 Technical Services • Springfield (VA)

On-site
USD 140,000 - 150,000
Lead Firewall Engineer Arnold, MO, US
Lead Firewall Engineer Arnold, MO, US

CACI International Inc. • Arnold (MO)

On-site
USD 90,000 - 190,000
Senior Network Engineer
Senior Network Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Senior Firewall Engineer & Boundary Team Lead (TS/SCI)
Senior Firewall Engineer & Boundary Team Lead (TS/SCI)

D2 Consulting • Springfield (VA)

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid time off
+1
Lead Firewall Engineer
Lead Firewall Engineer

Leidos • Washington

On-site
USD 131,000 - 238,000
Health and Wellness programs
Income Protection
Paid Leave
+1