Network Security Specialist

DSA

Charlottesville (VA)

On-site

USD 120,000 - 160,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Data Systems Analysts, Inc. (DSA) seeks a TS/SCI cleared Network Security Specialist to secure and defend enterprise Cisco-based networks in a strict DoD environment.

The role involves hands-on security configuration, boundary defense, vulnerability remediation, and device hardening across Cisco routers, switches, and firewalls. The ideal candidate collaborates with engineers, administrators, and mission partners to keep systems hardened, resilient, and operationally effective, with strong

Qualifications

  • BS degree in Engineering, Computer Science, or related field; experience may substitute for degree.
  • TS/SCI Clearance and ability to obtain/security clearance.
  • DoD 8140 (8570) IAT Level II Certification.
  • CCNA certification.

Responsibilities

  • Configure and review firewall rules, ACLs, ports, protocols, services, VPN connections, network flows, and boundary protection controls.
  • Configure, validate, and audit security configurations for Cisco routers, switches, firewalls, and related network infrastructure.
  • Support active network security operations, boundary defense engineering, and continuous hardening for enterprise network systems.
  • Support incident response by analyzing network alerts, logs, firewall events, syslog data, and authentication events.
  • Support change control reviews by assessing proposed network changes for cybersecurity impacts and security alignment.
  • Monitor network security posture through syslog alerts, configuration tools, and packet‑level analysis.
  • Conduct, analyze, and remediate vulnerability scans using ACAS, Nessus, STIG Viewer, SCAP, and other DoD tools.
  • Analyze vulnerability findings, identify false positives, engineer workarounds, and remediate across network devices.
  • Implement and validate DISA STIG compliance, SCAP benchmarks, security baselines, and device hardening requirements.
  • Develop and maintain technical network security documentation including device hardening procedures, network diagrams, and PPS listings.
  • Support engineering assessments and security reviews to maintain authorization sustainment.

Skills

Network security
Boundary defense
Vulnerability remediation
Cisco network infra
Documentation
Collaboration

Education

Bachelor's degree in Engineering/CS

Tools

ACAS
Nessus
STIG Viewer
SCAP
Syslog
Wireshark
OpenSearch

Job description

All hired employees are expected to have experience with Microsoft Copilot and / or an approved equivalent AI solution.

Description

Data Systems Analysts, Inc. (DSA) is seeking a TS/SCI cleared Network Security Specialist to secure, engineer, and defend enterprise network systems in a secure DoD environment. The Network Security Specialist will perform hands‑on security configuration, boundary defense engineering, vulnerability remediation, and device hardening for Cisco based network infrastructure.

The Network Security Specialist will work closely with network engineers, cybersecurity staff, security administrators, and mission partners to ensure network systems remain secure, hardened, resilient, and operationally effective. This role is suited for a highly technical security professional with hands‑on experience in Cisco network infrastructure, firewall management, ports and protocols, packet‑level analysis, and active network defense.

onsite in Charlottesville, VA.

Responsibilities
  • Configure and review firewall rules, access control lists, ports, protocols, services, VPN connections, network flows, and boundary protection controls.
  • Configure, validate, and audit security configurations for Cisco routers, switches, firewalls, and related network infrastructure.
  • Support active network security operations, boundary defense engineering, and continuous hardening for enterprise network systems.
  • Support incident response activities by performing technical analysis of network related alerts, logs, firewall events, syslog data, and authentication events.
  • Support change control reviews by assessing proposed network changes for cybersecurity impacts, configuration vulnerabilities, and security architecture alignment.
  • Monitor network security posture through syslog alerts, configuration management tools, and packet‑level analysis.
  • Conduct, analyze, and remediate vulnerability scans using ACAS, Tenable Nessus, STIG Viewer, and other approved DoD tools.
  • Analyze vulnerability findings, identify false positives, engineer technical workarounds, and execute remediation actions across network devices.
  • Implement and validate DISA STIG compliance, SCAP benchmarks, security baselines, and device hardening requirements.
  • Develop and maintain technical network security documentation including device hardening procedures, network diagrams, and Ports, Protocols, and Services (PPS) listings.
  • Support technical engineering assessments and security reviews to maintain authorization sustainment activities.
  • Prepare technical security status updates, vulnerability remediation roadmaps, and network security risk briefings for engineering teams and stakeholders.
Required Education, Certifications And Security Clearance
  • BS degree in Engineering, Computer Science, or related field. Experience may be substituted for degree.
  • TS/SCI Clearance
  • DoD 8140 (8570) IAT Level II Certification
  • CCNA certification
Requirements Experience/Qualifications
  • Minimum 4 years of experience supporting network security engineering, secure network operations, boundary defense, or hands‑on network administration.
  • Working knowledge of Cisco routers, switches, firewalls, Cisco ASA, Cisco Firepower, Cisco Secure Firewall, Cisco ISE, Catalyst, Nexus, ISR, or ASR platforms.
  • Working knowledge of routing, switching, VLANs, ACLs, firewall policies, ports, protocols, VPNs, IPsec, NAT, DNS, DHCP, subnetting, logging, and boundary protection.
  • Ability to design and review network diagrams, firewall rule sets, data flows, ports and protocols, and system interconnections for security vulnerabilities.
  • Demonstrated understanding of network hardening practices, secure protocols, network security architecture, and boundary defense concepts.
  • Experience coordinating with network engineers, systems administrators, security analysts, and mission partners to resolve technical security findings.
  • Hands on experience with ACAS, Tenable Nessus, STIG Viewer, SCAP, and network vulnerability remediation processes.
  • Experience applying, validating, or remediating vulnerability findings and DISA STIGs for network devices.
  • Experience developing or maintaining technical configuration standards, ports and protocols lists, network topology diagrams, and device configuration baselines.
  • Familiarity with applying and verifying security controls on network hardware to support technical authorization maintenance.
  • Experience supporting network security activities within the DoD, Intelligence Community, or other secure enterprise environment.
  • Knowledge of NIST SP 800-53 security controls (specifically Network/Access Control families), DISA Network Infrastructure STIGs, and secure network design practices.
  • Strong technical documentation, communication, analytical, and troubleshooting skills.
Preferred Experience/Qualifications
  • Experience securing, assessing, and engineering Cisco ASA, Cisco Firepower, Cisco Secure Firewall, Cisco ISE, Catalyst, Nexus, ISR, or ASR platforms in a production environment.
  • Experience writing and auditing firewall rules, access control policies, route tables, network diagrams, ports and protocols, and VPN configurations.
  • Experience with Splunk, Elastic, ELK Stack, OpenSearch, SolarWinds, Wireshark, NetFlow, syslog, firewall logs, or other tools used to support monitoring and packet‑level analysis.
  • Familiarity with network automation or scripting tools such as Ansible, Python, PowerShell, Terraform, or Cisco Catalyst Center to automate security baselines.
  • Familiarity with Zero Trust principles, micro‑segmentation, identity‑based access control, and modern DoD cybersecurity architecture.
  • CCNP, CCNP Security, Cisco CyberOps, or equivalent network security certification.
  • CISSP, CEH, PenTest+, CySA+, CASP+, SecurityX, or equivalent cybersecurity certification.
  • Knowledge of continuous monitoring, active threat hunting, and automated configuration compliance.
Applicable Military Backgrounds
  • Army: 17C, 25B, 25D, 25H, 255A, 255N, 255S
  • Navy: IT, ITS, ITN, ITR, CWT, 1820, 1880
  • Air Force: 1B4X1, 1D7X1, 1D7X1A, 1D7X5, 17D, 17S
  • Marine Corps: 0631, 0671, 0681, 1702, 1721
  • Space Force: 5C0X1, 17X
  • Coast Guard: IT, CMS, CMM, C5I

#DSA209

The posted salary range is a good-faith estimate

The posted salary range is a good-faith estimate. Actual compensation will be based on the selected candidate’s qualifications, experience, skills, and other job‑related factors.

DSA - Salary Pay Range

$120,000 - $160,000 USD

Many of DSA's positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information.

DSA is proud to be an Equal Opportunity Employer. DSA is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. DSA requires background checks , where permitted , by law. DSA is an E‑Verify Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Specialist
Network Security Specialist

DSA Inc. • Charlottesville (VA)

On-site
USD 120,000 - 160,000
Network Security Specialist
Network Security Specialist

Data Systems Analysts, Inc. • Charlottesville (VA)

On-site
USD 120,000 - 160,000
Information Systems Security Officer (ISSO), Network Security, TS/SCI
Information Systems Security Officer (ISSO), Network Security, TS/SCI

DSA • Charlottesville (VA)

On-site
USD 90,000 - 120,000
Information Systems Security Officer (ISSO), Network Security, TS/SCI
Information Systems Security Officer (ISSO), Network Security, TS/SCI

DSA Inc. • Charlottesville (VA)

On-site
USD 80,000 - 110,000
Software Engineer / Developer (DevSecOps / Full Stack) Charlottesville, VA
Software Engineer / Developer (DevSecOps / Full Stack) Charlottesville, VA

DSA Inc. • Charlottesville (VA), Northern (KY)

Hybrid
USD 140,000 - 200,000
Senior Information Security Analyst
Senior Information Security Analyst

DSA • Fairfax (VA)

Hybrid
USD 105,000 - 115,000
Senior Information Security Analyst
Senior Information Security Analyst

Data Systems Analysts, Inc. • Fairfax (VA)

Hybrid
USD 105,000 - 115,000
Senior Information Security Analyst
Senior Information Security Analyst

Data Systems Analysts, Inc. • Maryland

Hybrid
USD 105,000 - 115,000
Network Engineer
Network Engineer

DSA • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Telework flexibility
Health benefits
Retirement plans
Senior Computer Systems Engineer/Architect
Senior Computer Systems Engineer/Architect

Data Systems Analysts, Inc. • Frederick (MD)

On-site
USD 170,000 - 175,000