Network Engineer - Firewall & Load Balancing

Peraton

Orlando (FL)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Network Engineer specializing in Firewall & Load Balancing to design, implement, and secure enterprise network security infrastructure. The role emphasizes F5 BIG-IP load balancing, Palo Alto NGFW, and Cisco FTD managed through FMC, in collaboration with DHS CBP NOC teams.

The candidate will support secure configurations, incident response, and documentation across hybrid environments, with onsite work in Orlando or nearby Ashburn/Springfield, VA as required.

Qualifications

  • Basic Qualifications: 8 years of experience with a Bachelor’s, 6 with a Master’s, 10 with an Associate’s, or 12 with a HS diploma.
  • U.S. citizenship required for CBP and government positions.
  • Ability to obtain a CBP Public Trust clearance.
  • 5+ years hands-on experience in enterprise network engineering or network security.
  • Experience administering and troubleshooting F5 BIG-IP solutions (LTM, virtual servers, pools, SSL profiles, traffic management).
  • Experience configuring Palo Alto Networks NGFWs (security policies, NAT, VPN, Panorama).
  • Experience supporting Cisco FTD devices using FMC.
  • Strong understanding of network security concepts, TCP/IP, OSI, routing, VLANs, VPNs, segmentation.
  • Experience with monitoring/troubleshooting tools like SolarWinds, PRTG, Splunk, Wireshark.

Responsibilities

  • Design, configure, maintain, and troubleshoot enterprise network security infrastructure (firewalls, load balancers, VPNs).
  • Administer F5 BIG-IP environments (LTM, GTM/DNS, virtual servers, pools, iRules, SSL, health monitors).
  • Manage SSL/TLS certificates, traffic optimization, and load-balancing configuration.
  • Support F5 WAF policies and security configurations.
  • Configure Palo Alto networks NGFWs (security policies, NAT, VPNs, decryption).
  • Administer Palo Alto Panorama for centralized firewall management.
  • Maintain Palo Alto App-ID, User-ID, Content-ID, Threat Prevention, URL Filtering, WildFire.
  • Manage Cisco FTD through FMC; develop ACP, IPS policies, Snort tuning in FMC.
  • Perform firewall event analysis, security monitoring, incident investigation, troubleshooting.
  • Support VLANs, segmentation, routing, VPN connectivity, and network performance optimization.
  • Develop and maintain network documentation and runbooks.
  • Support change management for network security changes; ensure testing and approvals.
  • Monitor performance, troubleshoot incidents, perform root cause analysis, support SLAs.
  • Collaborate on Zero Trust concepts and security compliance.

Skills

Network engineering
Security concepts
TCP/IP
VLANs
VPNs
Troubleshooting

Education

Bachelor's degree
Master’s degree
Associate’s degree
High school diploma

Tools

F5 BIG-IP
Palo Alto NGFW
Cisco FMC
Firepower Management Center
SolarWinds
PRTG
Wireshark

Job description

Network Engineer – Firewall & Load Balancing

Job Locations: US-VA-Springfield | US-VA-Ashburn | US-FL-Orlando

Responsibilities

Peraton is seeking an experienced Network Engineer to join our team of qualified and diverse individuals. The Network Engineer – Firewall & Load Balancing will support the DHS CBP Network Operations Center (NOC) by designing, implementing, securing, and maintaining enterprise network security infrastructure. This role will provide hands‑on support for mission‑critical network environments with a focus on F5 BIG‑IP load‑balancing solutions, Palo Alto Next Generation Firewalls (NGFW), and Cisco Firepower Threat Defense (FTD) managed through Firepower Management Center (FMC).

The ideal candidate will have experience managing complex enterprise security platforms, troubleshooting network security issues, implementing secure configurations, and supporting hybrid infrastructure environments. The Network Security Engineer will collaborate with network operations, cybersecurity teams, and government stakeholders to maintain secure, reliable, and compliant network services.

Location: Onsite based in either Ashburn, VA, Springfield, VA or Orlando, FL. Candidates must reside near one of these locations to be considered.

  • Design, configure, maintain, and troubleshoot enterprise network security infrastructure, including firewalls, load balancers, VPN solutions, and network security platforms.
  • Administer and support F5 BIG‑IP environments, including Local Traffic Manager (LTM), Global Traffic Manager (GTM/DNS), virtual servers, pools, iRules, SSL profiles, health monitors, and traffic policies.
  • Perform SSL/TLS certificate management, traffic optimization, application delivery troubleshooting, and load‑balancing configuration.
  • Support F5 Advanced Web Application Firewall (WAF) policies and security configurations.
  • Configure and manage Palo Alto Networks Next Generation Firewalls, including security policies, NAT, QoS, decryption, and VPN configurations.
  • Administer Palo Alto Panorama for centralized firewall management across enterprise environments.
  • Configure and maintain Palo Alto security capabilities, including App‑ID, User‑ID, Content‑ID, Threat Prevention, URL Filtering, and WildFire.
  • Manage Cisco Firepower Threat Defense (FTD) devices using Firepower Management Center (FMC).
  • Develop and maintain Access Control Policies (ACP), IPS policies, malware inspection policies, and Snort rule tuning within Cisco FMC.
  • Perform firewall event analysis, security monitoring, incident investigation, and troubleshooting activities.
  • Support network engineering activities including VLANs, segmentation, routing protocols, VPN connectivity, and network performance optimization.
  • Develop and maintain network documentation including diagrams, standard operating procedures, and technical runbooks.
  • Support change management activities by ensuring network security changes are tested, documented, approved, and implemented in accordance with established processes.
  • Monitor network performance, troubleshoot incidents, perform root cause analysis, and support service level agreement (SLA) requirements.
  • Collaborate with cybersecurity teams to support Zero Trust architecture, defense in depth strategies, and security compliance requirements.
Qualifications

Basic Qualifications:

  • Bachelor's degree with 8 years of experience, Master’s degree and 6 years of experience, Associate’s degree with 10 years of experience, or high school diploma/equivalent with 12 years of experience.
  • U.S. citizenship (required for CBP and government positions).
  • Must have the ability to obtain a CBP Public Trust clearance.
  • 5+ years of hands‑on experience supporting enterprise network engineering or network security environments.
  • Experience administering and troubleshooting F5 BIG‑IP solutions, including LTM, virtual servers, pools, SSL profiles, and traffic management configurations.
  • Experience configuring and managing Palo Alto Networks Next Generation Firewalls, including security policies, NAT, VPNs, and Panorama administration.
  • Experience supporting Cisco Firepower Threat Defense (FTD) devices using Firepower Management Center (FMC).
  • Strong understanding of network security concepts, TCP/IP networking, OSI model, routing protocols, VLANs, VPNs, and network segmentation.
  • Experience using network monitoring and troubleshooting tools such as SolarWinds, PRTG, Splunk, Wireshark, or similar platforms.

Desired Qualifications:

  • Active security clearance required; DHS clearance or prior DHS suitability preferred.
  • Experience supporting DHS, CBP, federal government, or other mission‑critical network environments.
  • Experience with DISA STIGs, NIST 800‑53 security controls, or federal cybersecurity compliance requirements.
  • Experience supporting SD‑WAN technologies such as Palo Alto Prisma SD‑WAN or Cisco Viptela.
  • Experience supporting cloud networking environments, including AWS, Azure, and hybrid connectivity solutions.
  • Experience with network automation and scripting using Python, Ansible, Terraform, or similar technologies.
  • Experience using IT Service Management platforms such as ServiceNow or Remedy.
  • Experience supporting legacy Cisco ASA migration to Cisco Firepower Threat Defense.
  • Preferred Certifications:
    • F5 Certified BIG‑IP Administrator (F5‑CA)
    • Palo Alto Networks Certified Network Security Engineer (PCNSE)
    • Cisco Certified Network Professional (CCNP) Security or CCNP Enterprise
    • Cisco Certified Internetwork Expert (CCIE) Security
    • CompTIA Security+ or equivalent security certification

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Engineer - Firewall & Load Balancing
Network Engineer - Firewall & Load Balancing

Peraton • Ashburn (VA)

On-site
USD 120,000 - 150,000
Network Engineer – Firewall & Load Balancing
Network Engineer – Firewall & Load Balancing

Peraton • Virginia (MN)

On-site
USD 120,000 - 160,000
Network Engineer - Firewall & Load Balancing
Network Engineer - Firewall & Load Balancing

Peraton • Springfield (VA)

On-site
USD 104,000 - 166,000
Network Security Engineer - Firewalls & Load Balancing
Network Security Engineer - Firewalls & Load Balancing

Peraton • Springfield (VA)

On-site
USD 104,000 - 166,000
Network Engineer: Enterprise Firewall & Load Balancing
Network Engineer: Enterprise Firewall & Load Balancing

Peraton • Orlando (FL)

On-site
USD 110,000 - 150,000
Senior Network Engineer: Firewall & Load Balancing
Senior Network Engineer: Firewall & Load Balancing

Peraton • Ashburn (VA)

On-site
USD 120,000 - 150,000
TIC Systems Engineer
TIC Systems Engineer

Entarian • Arlington (VA)

On-site
USD 140,000 - 190,000
TIC Systems Engineer
TIC Systems Engineer

ERT, Inc. • Arlington (VA)

On-site
USD 120,000 - 160,000
Network Engineer (Palo Alto & Cisco)
Network Engineer (Palo Alto & Cisco)

Edgewater Federal Solutions, Inc. • Washington

On-site
USD 120,000 - 128,000
Paid Time Off & Holiday Pay
Medical Insurance
Dental Insurance
+5
Network Engineer - Network Configuration
Network Engineer - Network Configuration

Peraton • Springfield (VA)

On-site
USD 86,000 - 138,000
Medical benefits
401(k)
Paid holidays
+1