Flybridge Staffing is currently seeking a Network Security Engineer for a client based in the Boca Raton area. This is a contract-to-hire role that works on a hybrid schedule. This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization's on-premises and hybrid infrastructure. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments are completed on schedule.
Experience/responsibilities:
- BA degree in Computer Science, Information Technology, or Cybersecurity, and 5 years of experience preferred.
- Must have experience with Security hardening of systems, networks, and Cloud infrastructure tools.
- Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments.
- Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent).
- Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs
- Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere).
- Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables.
- Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning.
- Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls.
- Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings.
- Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices.
- Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours.
- Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments.
- Review and administer security tools to harden network edge security, including next-generation firewalls, SD-WAN, and switching, striving for zero trust networks.
- Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass.
- Patching: Handles the deployment of security patches and system updates across the enterprise.
- Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass).
- Strong understanding of TCP/IP routing, switching, network protocols, and cloud security.
- Experience with IDS/IPS, firewalls (e.g., Palo Alto, Cisco), and EDR platforms.
- Experience with scripting languages (e.g., Python, PowerShell) for automation.
****NO SPONSORSHIP AVAILABLE**** US Citizen, GC, only please.