Senior Firewall Engineer/SME - Team Lead

GCyber

Arlington (VA)

On-site

USD 140,000 - 200,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Paid leave
Parental leave
Disability insurance
Health insurance
401(k) matching
Professional development
Commuter benefits
Parking

Job summary

GCyber is seeking a Senior Firewall Engineer / Team Lead to support the J6 Pentagon enterprise. You will lead a team of firewall engineers, act as the senior technical authority for firewall design, security, operations, and modernization in classified and unclassified environments.

You will manage change control end‑to‑end, ensure policy compliance with STIG/NIST/PPSM guidance, and mentor staff in design patterns and troubleshooting. DoD TS/SCI clearance and relevant certifications are required.

Qualifications

  • Active DoD TS/SCI clearance.
  • DoD 8140 IAT II certification (Security+, CCNA‑Security, CySA+, CND, GICSP, GSEC, SSCP).
  • Industry Firewall Certification (CCNP, Palo Alto, Juniper, etc.).
  • BA/BS degree or equivalent experience.
  • 7+ years in enterprise firewall engineering/operations, with 3+ years in a DoD environment.
  • Experience leading firewall engineers or security staff.
  • Deep knowledge of firewall architecture, zones, DMZs, NAT, HA, logging, and traffic analysis.
  • Hands-on with Cisco ASA & Cisco Firepower; familiarity with FireMon, Stealthwatch, SIEM; DoD STIGs/NIST/PPSM.
  • Strong leadership, writing, and customer communication skills.
  • Willingness for after-hours support.

Responsibilities

  • Lead a team of firewall engineers and administrators; prioritize work and mentor staff.
  • Serve as technical authority for firewall architecture and security controls.
  • Own firewall change management end-to-end including risk and approvals.
  • Maintain rule base hygiene; remediate issues.
  • Escalate and diagnose complex connectivity and performance issues with packet analysis.
  • Manage firewall platform lifecycle including upgrades and migrations.
  • Ensure configurations meet STIG/NIST/PPSM/NSA requirements; produce artifacts.
  • Lead Cisco ASA/Firepower configurations and integration with FireMon/Stealthwatch/SIEM.
  • Author SOPs, reports, change records, diagrams and docs.
  • Interface with Government customers and stakeholders on requirements and status.

Education

BA/BS degree or equivalent experience
DoD 8140 IAT II certification
Industry Firewall Certification (CCNP, Palo Alto, Juniper)

Tools

Cisco ASA
Cisco Firepower
FireMon
Stealthwatch
Enterprise SIEM

Job description

GCyber is seeking a Senior Firewall Engineer / Subject Matter Expert and Team Lead to support the J6 Pentagon enterprise. This hands‑on leadership role is responsible for leading a team of firewall engineers and administrators while serving as the senior technical authority for firewall architecture, security assurance, operations, troubleshooting, and modernization across classified and unclassified environments.

The ideal candidate combines deep enterprise firewall expertise with the leadership, judgment, and communication skills required to manage priorities, mentor technical staff, resolve complex issues, and work directly with Government customers and stakeholders.

As the Senior Firewall Engineer, you will:

  • Lead a team of firewall engineers and administrators: assign and prioritize daily work, review peer configurations before implementation, and mentor junior staff on design patterns and troubleshooting methodology.
  • Serve as the technical authority for enterprise firewall architecture, including boundary design, security zone segmentation, high-availability pairs, and integration with routing, IDS/IPS, proxy, and remote‑access infrastructure.
  • Own the firewall change‑management process end to end, including validating rule requests, assessing risk and least‑privilege impact, coordinating required Government and Risk Management approvals, and overseeing implementation and post‑change verification.
  • Maintain rule base hygiene through recurring assessments by identifying and remediating shadowed, expired, duplicate, conflicting, and overly permissive rules.
  • Act as the final escalation point for complex connectivity and performance issues, using packet captures, session and traffic‑flow analysis, and log correlation to isolate faults across the network path.
  • Manage firewall platform lifecycle activities, including upgrades, patching, failover testing, performance monitoring, and planning and executing end‑of‑life hardware migrations.
  • Ensure firewall configurations meet applicable STIG, NIST, PPSM, DISA, NSA, and organizational security requirements and produce supporting artifacts for assessments and accreditation activities.
  • Lead the configuration, migration, integration, and monitoring of Cisco ASA and Firepower platforms and associated FireMon, Stealthwatch, and enterprise SIEM capabilities.
  • Author and maintain SOPs, assessment reports, After Action Reports, change records, logical configuration diagrams, and other technical documentation required to support secure and consistent operations.
  • Interface directly with the Government customer and stakeholder teams on requirements, status reporting, metrics, outage communications, and long‑range technical roadmap input.
Minimum Qualifications and Experience:
  • Active DoD TS/SCI clearance
  • DoD 8140 IAT II certification (i.e., Security+, CCNA‑Security, CySA+, CND, GICSP, GSEC, SSCP)
  • Industry Firewall Certification (CCNP, Palo Alto, Juniper, etc.)
  • BA/BS degree or equivalent experience
  • Minimum 7 years experience engineering, administering, and troubleshooting enterprise firewall environments, with at least 3 years in DoD enterprise environments
  • Experience leading firewall engineers, network security personnel, or a comparable technical team.
  • Advanced knowledge of firewall architecture, security zones, DMZs, access‑control policies, routing, NAT, high availability, traffic inspection, logging, and packet analysis.
  • Experience evaluating and optimizing complex firewall rulesets.
  • Experience leading major firewall changes, platform migrations, security assessments, and complex incident resolution.
  • Hands‑on experience with Cisco ASA and Cisco Firepower technologies.
  • Familiarity with FireMon, Stealthwatch, enterprise SIEM capabilities, and load balancer technologies.
  • Working knowledge of DoD STIGs, NIST guidance, PPSM requirements, and formal Government change‑management processes.
  • Experience supporting classified networks and mission‑critical operational environments.
  • Strong leadership, technical writing, documentation, and customer communication skills.
  • Ability to provide after‑hours emergency support when required.
Preferred Qualifications
  • Experience supporting the Pentagon, DISA, or another large DoD enterprise environment.
  • Experience with Juniper NetScreen and Cisco PIX configuration cleanup and migration.
  • Relevant firewall, networking, or cybersecurity certifications.
Our Benefits

GCyber is committed to the well‑being and development of every employee. Our benefits are designed to support your personal and professional goals, from health and wellness programs to retirement savings and career development opportunities. Highlights include:

  • 26 Days of Paid Leave + Annual PTO Increase
  • An extra day of paid leave for every year of employment with GCyber
  • Paid Parental Leave
  • Additional Leave Allowances for Military Duty, Jury Duty, and Bereavement Leave
  • 401(k) Matching
  • 100% Company‑funded Disability Insurance
  • 90% Company‑Funded Health, Dental, and Vision Insurance, with contributions to insurance benefits for spouses, children, and family members
  • Training and Professional Development Plans
  • Commuter Benefits Plan
  • Parking and Transportation Allowance
Equal Opportunity Employer

GCyber is an Equal Opportunity Employer. This means you don't have to worry about whether your application process will be fair. We consider all applicants without regard to race, color, religion, age, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, veteran status, or disability.

Stay in Touch

For future job notifications please follow GCyber on LinkedIn. https://linkedin.com/company/gcyber

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Firewall Architect & Team Lead
Senior Firewall Architect & Team Lead

GCyber • Arlington (VA)

On-site
USD 140,000 - 200,000
Paid leave
Parental leave
Disability insurance
+5
Senior Network Engineer
Senior Network Engineer

GCyber • Scott Air Force Base (IL)

On-site
USD 140,000 - 190,000
26 Days of Paid Leave + Annual PTO In-
Annual PTO Increase
Paid Parental Leave
+7
Palo Alto Engineer
Palo Alto Engineer

GCyber • Arlington (VA)

On-site
USD 150,000 - 190,000
Paid leave
Parental leave
401(k) matching
+4
Principal Software Engineer/Tech Lead
Principal Software Engineer/Tech Lead

GCyber • Arlington (VA)

Hybrid
USD 180,000 - 235,000
Paid leave
Parental leave
401(k) matching
+3
Senior Firewall Engineer
Senior Firewall Engineer

NTG • Alexandria (VA)

On-site
USD 140,000 - 180,000
Senior Firewall Engineer
Senior Firewall Engineer

D2 Consulting • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Palo Alto Engineer
Palo Alto Engineer

GCyber • Arlington (TX)

On-site
USD 120,000 - 160,000
26 Days Paid Leave
401(k) Matching
Health, Dental, Vision Insurance
+2
Lead Firewall Engineer
Lead Firewall Engineer

D2 Consulting • Springfield (VA)

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid time off
+1
Lead Firewall Engineer
Lead Firewall Engineer

Koitecc Solutions • Washington, Northern (KY)

Hybrid
USD 131,000 - 237,000
Lead Firewall Engineer
Lead Firewall Engineer

Leidos • Washington

On-site
USD 131,300 - 237,350
Health and Wellness programs
Income Protection
Paid Leave
+1