Senior Network Security Engineer

GovCIO

Cheyenne (WY)

Remote

USD 120,000 - 140,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Employee Assistance Program
Learning & Development platform
Training, Education and Certification
Flexible Work Environment

Job summary

GovCIO is seeking aSenior Network & Security Engineer to design, deploy, and operate enterprise network security infrastructure in a fully remote US-based role.

You will lead Palo Alto NGFWs, Panorama, and Cisco switching, coordinate with SOC and leadership teams, and drive secure, scalable network solutions while mentoring peers.

Qualifications

  • 8+ years in network engineering or security operations.
  • Hands-on Palo Alto firewall experience in production enterprise environments.
  • Advanced experience with Palo Alto Panorama, multi-device policy management, and upgrades.
  • Strong HA design and troubleshooting skills for high-availability deployments.
  • Deep knowledge of TCP/IP, routing, NAT, VPNs, and packet-level troubleshooting.
  • Clearance eligible AOUSC Public Trust.

Responsibilities

  • Lead design, deployment, administration, and lifecycle management of Palo Alto NGFW environments running PAN-OS.
  • Own centralized firewall management through Panorama, device groups, templates, and policy inheritance.
  • Design and govern security policies using zero-trust and least-privilege principles.
  • Configure and troubleshoot NAT, VPNs, URL Filtering, Threat Prevention, and App-ID policies.
  • Lead network segmentation and microsegmentation initiatives with VLANs and routing controls.
  • Mentor junior engineers and lead security reviews.

Skills

Technical leadership
Firewall administration
Network security design
Incident escalation
Mentoring
TCP/IP troubleshooting

Education

Bachelor's degree or commensurate experience

Tools

Palo Alto NGFW
PAN-OS
Palo Alto Panorama
Cisco Catalyst/Nexus
Cortex XSIAM
Strata Logging Service

Job description

United States

Suitability/Public Trust

Fully remote

Information Technology

Overview

GovCIO is seeking a highly experienced Senior Network & Security Engineer to lead the design, operation, troubleshooting, and continuous improvement of enterprise network-security infrastructure. This role is responsible for Palo Alto Networks next-generation firewalls, Panorama, High Availability, Cisco switching, network segmentation, Cortex XSIAM, and Strata Logging Service.

The Senior Engineer will serve as a technical escalation point for complex network and security incidents, lead architecture and implementation initiatives, establish standards, and partner with SOC, infrastructure, cloud, application, and leadership teams to reduce risk and maintain highly available services.

This position will be located within the United States and will be a fully remote opportunity.

Responsibilities

The successful Senior Network & Security Engineer will be a hands‑on technical leader with deep expertise in Palo Alto Networks firewalls, Panorama, HA, and Cisco enterprise networking. This person will lead firewall‑policy and microsegmentation design, troubleshoot complex TCP/IP and packet‑flow issues, ensure resilient HA operations, and integrate security telemetry with Cortex XSIAM and Strata Logging Service. The candidate must be able to independently lead technical projects, resolve high‑impact incidents, improve security controls, and mentor other engineering team members.

  • Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS.

  • Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.

  • Design and govern security policies using zero‑trust, least‑privilege, application‑aware, and risk‑based principles.

  • Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App‑ID policies.

  • Lead enterprise network‑segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application‑based security policies.

  • Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data‑center workloads, and cloud resources.

  • Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required.

  • Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split‑brain prevention, and failover recovery.

  • Plan and execute HA failover testing, PAN-OS upgrades, disaster‑recovery exercises, and maintenance procedures while minimizing service impact.

  • Troubleshoot HA infrastructure dependencies, including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant‑path failures.

  • Lead the configuration, support, and troubleshooting of Cisco Catalyst and Nexus switching environments.

  • Design and support VLANs, trunking, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access‑control technologies.

  • Diagnoses complex connectivity and performance issues through firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network‑monitoring platforms.

  • Analyze TCP/IP behavior, including handshake failures, SYN/SYN‑ACK/ACK flow, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, packet loss, and NAT translation problems.

  • Verify packet flow across firewall policy, App‑ID, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.

  • Monitor firewall management‑plane and dataplane health, including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.

  • Integrate Palo Alto NGFWs and Panorama with Strata Logging Service and Cortex XSIAM.

  • Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event availability, retention, and telemetry quality.

  • Use Cortex XSIAM and XQL Search to investigate, correlate, and respond to firewall, endpoint, identity, cloud, and third‑party security events.

  • Partner with SOC teams to tune detections, investigate alerts, develop response procedures, improve visibility, and support incident containment and remediation.

  • Lead root‑cause analyses for major network or security incidents and deliver corrective and preventive action plans.

  • Develop and maintain network diagrams, firewall‑policy documentation, HA designs, runbooks, change plans, architecture standards, and operational procedures.

  • Mentor junior engineers and provide technical leadership during projects, production incidents, and security reviews.

Qualifications

Bachelor’s degree with 8+ years (or commensurate experience)

  • 7+ years of progressive experience in network engineering, network security, firewall administration, or security infrastructure operations.

  • 5+ years of hands‑on Palo Alto Networks firewall experience in a production enterprise environment.

  • Advanced operational experience with Palo Alto Panorama, including multi‑device policy management, templates, device groups, upgrades, configuration management, and troubleshooting.

  • Strong hands‑on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments.

  • Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes.

  • Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet‑level troubleshooting.

  • Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior.

  • Extensive experience with Cisco Catalyst and/or Nexus switching technologies.

  • Strong knowledge of enterprise switching and routing, including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch‑security controls.

  • Proven experience designing or implementing network segmentation and microsegmentation solutions.

  • Working knowledge of Cortex XSIAM, Strata Logging Service, security‑event correlation, alert investigation, XQL Search, and firewall log ingestion.

  • Ability to lead technical design discussions, independently manage complex workstreams, and communicate risks and recommendations to technical and nontechnical stakeholders.

  • Strong documentation, change‑management, incident‑management, and root‑cause‑analysis skills.

Clearance Required: Must be able to attain and maintain AOUSC Public Trust

Preferred Skills and Education
  • Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field preferred

  • Palo Alto Networks certifications: PCNSA, PCNSE, PCCSE, or equivalent enterprise‑level experience.

  • Cisco certifications: CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or comparable expertise.

  • Experience with Palo Alto Prisma Access, Prisma Cloud, Cortex XDR, Cortex XSOAR, or cloud‑delivered security services.

  • Experience with Cortex XSIAM alert triage, XQL queries, data‑source integrations, detection tuning, dashboards, reporting, and response automation.

  • Experience with Cisco ISE, Cisco ACI, SD‑Access, or enterprise network‑access‑control solutions.

  • Familiarity with Fortinet Security Fabric, FortiGate, FortiManager, and FortiAnalyzer.

  • Experience with AWS, Azure, Google Cloud Platform, hybrid‑cloud network design, and cloud‑security controls.

  • Familiarity with SIEM, SOAR, EDR/XDR, vulnerability‑management, NDR, network‑monitoring, and ticketing platforms.

  • Automation skills using Python, Ansible, Terraform, REST APIs, or related infrastructure‑as‑code and orchestration tools.

  • Experience supporting 24x7 environments, participating in an on‑call rotation, leading critical incidents, and executing emergency changes.

Posted Salary Range

USD $120,000.00 - USD $140,000.00 /Yr.

Company Overview

GovCIO is a team of transformers--people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens.

But we can't do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer?

What You Can Expect
Interview & Hiring Process

If you are selected to move forward through the process, here’s what you can expect:

  • During the Interview Process

  • Virtual video interview conducted via video with the hiring manager and/or team

  • Camera must be on

  • A valid photo ID must be presented during each interview

  • During the Hiring Process

  • Enhanced Biometrics ID verification screening

  • Background check, to include:

  • Criminal history (past 7 years)

  • Verification of your highest level of education

  • Verification of your employment history (past 7 years), based on information provided in your application

Employee Perks

At GovCIO, we consistently hear that meaningful work and a collaborative team environment are two of the top reasons our employees enjoy working here. In addition, our employees have access to a range of perks and benefits to support their personal and professional well‑being, beyond the standard company offered health benefits, including:

  • Employee Assistance Program (EAP)

  • Corporate Discounts

  • Learning & Development platform, to include certification preparation content

  • Training, Education and Certification Assistance*

  • Referral Bonus Program

  • Internal Mobility Program

  • Pet Insurance

  • Flexible Work Environment

*Available to full‑time employees

Our employees’ unique talents and contributions are the driving force behind our success in supporting our customers, which ultimately fuels the success of our company. Join us and be a part of a culture that invests in its people and prioritizes continuous enhancement of the employee experience.

We are an Equal Opportunity Employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets.

Posted Pay Range

The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job‑related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an “at‑will position” and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Network Security Engineer
Senior Network Security Engineer

GovCIO • Augusta (ME)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Senior Network Security Engineer
Senior Network Security Engineer

GovCIO • Helena (MT)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+1
Senior Network Security Engineer
Senior Network Security Engineer

GovCIO • Montpelier (VT)

Remote
USD 120,000 - 140,000
Employee Assistance Program
Corporate Discounts
Learning & Development platform
+5
Senior Network Security Engineer
Senior Network Security Engineer

GovCIO • Honolulu (HI)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Senior Network Security Engineer
Senior Network Security Engineer

GovCIO • Boise (ID)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Network Security Engineer Master
Network Security Engineer Master

GovCIO • Salt Lake City (UT)

Remote
USD 125,000 - 150,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Network Security Engineer Master
Network Security Engineer Master

GovCIO • Juneau (AK)

Remote
USD 125,000 - 150,000
EAP
Corporate Discounts
Learning & Development
+5
Network Security Engineer Master
Network Security Engineer Master

GovCIO • Cheyenne (WY)

Remote
USD 125,000 - 150,000
Employee Assistance Program
Corporate Discounts
Learning & Development platform
+5
Data Security Analyst
Data Security Analyst

GovCIO • Boise (ID)

Remote
USD 125,000 - 150,000
EAP
Corporate Discounts
Learning & Development platform
+5
Network Security Engineer Master
Network Security Engineer Master

GovCIO • Montpelier (VT)

Remote
USD 125,000 - 150,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5