Network Security Firewall Engineer (NAC) / Active Secret

Peraton

United States

On-site

USD 80,000 - 128,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Peraton seeks a Network Security Firewall Engineer to design, implement, and maintain advanced network security for U.S. Army Europe RCC-E. Location is Wiesbaden, on-site.

Responsibilities cover Cisco ASA/Firepower, ISE, and F5 Big-IP implementations with a focus on threat prevention, authentication, and high availability. The role requires DoD security clearance, U.S. citizenship, and extensive hands-on experience with Cisco ASA/Firepower, ISE, FMC/FDM, and related technologies.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field with 8 years of relevant experience, OR Associate's Degree with 10 years, OR High School Diploma with 12 years.

Responsibilities

  • Lead design, implementation, and maintenance of Cisco Firepower infrastructure.
  • Design, deploy, configure, and maintain ISE across ATLA; implement 802.1X authentication.
  • Design and implement F5 BIG-IP solutions including LTM and GTM; monitor performance.

Skills

Cisco ASA/Firepower
ISE
F5 BIG-IP
802.1X
RADIUS/TACACS+
PKI
FMC/FDM
DoD clearance
ACLs/NAT/IPS-IDS

Education

Bachelor's degree
Associate's Degree
High School Diploma

Tools

FMC
FDM
Cisco Firepower
TMSH

Job description

Responsibilities

We are seeking a highly skilled Network Security Firewall Engineer to join our team supporting the U.S. Army Europe Regional Cyber Center (RCC-E). This role focuses on designing, implementing, and maintaining advanced network security solutions to ensure the integrity and availability of mission-critical systems.

Location

Wiesbaden, Germany (On-site at U.S. Army Europe Regional Cyber Center - RCC-E)

Key Responsibilities
Cisco ASA & Firepower
  • Lead design, implementation, and maintenance of Cisco Firepower infrastructure.
  • Focus on threat prevention, intrusion detection/prevention, and policy management.
  • Perform OS upgrades on Cisco ASA, FTD, and FMC platforms.
  • Troubleshoot VPNs, policies, and connectivity issues related to FTD and FMC.
  • Conduct security audits and performance tuning for high availability.
Cisco Identity Services Engine (ISE)
  • Design, deploy, configure, and maintain ISE across the Army Top-Level Architecture (ATLA).
  • Implement 802.1X authentication for wired and wireless users.
  • Develop posture‑assessment policies and TrustSec segmentation strategies.
  • Configure and administer TACACS+ and RADIUS for AAA services.
  • Integrate ISE with Active Directory, PKI, RAVPN, and other technologies.
  • Provide Tier-3 support for identity and access incidents.
  • Monitor ISE health and generate compliance reports.
F5 Load Balancers
  • Design and implement F5 BIG-IP solutions including LTM and GTM.
  • Configure virtual servers, pools, SNATs, and network settings.
  • Perform firmware upgrades and configuration changes.
  • Monitor traffic and troubleshoot F5-related performance issues.
Documentation & Collaboration
  • Maintain architecture diagrams, runbooks, and SOPs.
  • Participate in formal change-control processes.
  • Collaborate with network, application, and security teams to integrate solutions.
Qualifications
Minimum Requirements
Education & Experience Requirements (TESA):
  • Bachelor's degree in Computer Science, Cybersecurity, or related field and 8 years of relevant experience,OR Associate's Degree and 10 years relevant experience, OR High School Diploma and 12 years relevant experience.
Certifications (8140 DCWF Code 441):
  • DCWF Code: 441
  • Required Certifications:
    • SecurityX / CASP+
    • CCNP Security, CCSP, GCIA, GCED, GCIH
    • AND ONE of the following:
      • Network Firewall, IDS, F5-CA, F5-CTS, F5-CSE, BCCPA, CCNP Security, CCIE Security, Cisco CyberOps Professional
Hands‑On Expertise:
  • Minimum 8 years designing and administering Cisco ASA or Firepower Firewall, Cisco ISE in large‑scale environments.
  • Experience with Cisco Firepower management platforms (FMC and FDM).
  • Understanding of network security principles, including ACLs, NAT, and IPS/IDS.
  • Deep understanding of 802.1X, RADIUS, TACACS+, TrustSec, Software-Defined Access.
  • Familiarity with command-line interfaces (like TMSH), networking concepts and protocols, and security principles.
  • Strong command of Cisco routing/switching, firewalls (ASA/FW-A), remote‑access VPNs, IPS/IDS, F5 Big-IP, Blue Coat proxy.
  • In‑depth knowledge of F5 Big-IP platforms and technologies like LTM, GTM, and TMOS.
  • Familiarity with PKI, certificate lifecycle management, and AAA integrations.
Soft Skills & Clearance:
  • Demonstrated analytical, troubleshooting, and communication experience and capabilities.
  • Ability to thrive in fast‑paced, mission‑critical settings.
  • U.S. citizenship required.
  • Active DoD Secret security clearance required.
Peraton Overview

Peraton is a next‑generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

All

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Firewall Engineer (NAC) / Active Secret
Network Security Firewall Engineer (NAC) / Active Secret

Peraton • Buffalo (NY)

On-site
USD 80,000 - 128,000
Network DevOps Developer - Ansible / Active Secret
Network DevOps Developer - Ansible / Active Secret

Peraton • Buffalo (NY)

On-site
USD 80,000 - 128,000
Network/ Firewall Engineer
Network/ Firewall Engineer

Peraton • United States

On-site
USD 80,000 - 128,000
SITEC - Network Security Engineer - MacDill AFB
SITEC - Network Security Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 104,000 - 166,000
Network DevOps Developer - Ansible
Network DevOps Developer - Ansible

Peraton • United States

On-site
USD 80,000 - 128,000
External Job Posting Title Network/ Firewall Engineer
External Job Posting Title Network/ Firewall Engineer

Peraton • Northern (KY)

Hybrid
USD 80,000 - 128,000
Senior Network Security Engineer: Cisco Firepower & ISE
Senior Network Security Engineer: Cisco Firepower & ISE

Peraton • Buffalo (NY)

On-site
USD 80,000 - 128,000
Lead Network Security & Firewall Engineer
Lead Network Security & Firewall Engineer

Peraton • United States

On-site
USD 80,000 - 128,000
Network Security Engineer
Network Security Engineer

Peraton • United States

On-site
USD 176,000 - 282,000
External Job Posting Title SITEC - Network Security Administrator - MacDill AFB
External Job Posting Title SITEC - Network Security Administrator - MacDill AFB

Peraton • Town of Florida (NY)

On-site
USD 80,000 - 128,000