Senior Network Security Engineer

Mbi Llc

Mechanicsville (VA)

Hybrid

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VDOT is seeking an experienced Sr Network Security Engineer to implement and support the agency’s IT network, cloud, and computing infrastructure, including Azure networking, Palo Alto firewalls, and WAF technologies.

The Sr NSE will lead security operations, perform threat hunting, vulnerability management, and incident response; collaborate with Infrastructure, Cloud Engineering, and the Information Security Office to ensure confidentiality, integrity, and availability across 300+ locations.

Qualifications

  • Experience in designing and implementing secure, hybrid network architectures.
  • Experience leading investigations and containment of security incidents.
  • Ability to communicate technical issues to technical and executive audiences and mentor junior engineers.
  • Experience with regulatory environments and outage troubleshooting.

Responsibilities

  • Ensures network security architecture aligns with operational security standards prior to deployment.
  • Lead investigation and containment of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments.
  • Monitor security events using SIEM technologies and coordinate incident response activities.
  • Perform network security assessments and recommend remediation strategies.
  • Develop and maintain network security standards, diagrams, and operational documentation.
  • Support penetration testing and remediation efforts.
  • Participate in on-call support during critical security incidents.
  • Responsible for conducting proactive threat hunting and anomaly detection.
  • Validates WAF and firewall placement and integration exposure/connectivity; leads implementation and management of agency WAFs.
  • Identify and diagnose system problems and threats using logs, SIEM, and diagnostic tools.
  • Identify, prioritize, and remediate network security vulnerabilities.
  • Provide documentation, topology diagrams, IP schemes, firewall rules, and access controls when required.
  • Work independently on assigned projects.

Skills

Network security engineering
Incident response
Threat hunting
WAF/NGFW
300+ devices
SIEM (Splunk/Microsoft Sentinel)
Vulnerability management
AD/CA/Certificates
NIST/CIS/Zero Trust
Cisco ISE/NAC/802.1X/RADIUS/TACACS
Palo Alto / F5 / Azure WAF

Tools

Palo Alto
F5 BIG-IP
Azure WAF
Cisco VPN / GlobalProtect

Job description

- VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agency’s IT network, cloud, and computing infrastructure.

- The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.

- The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT’s network and computing related infrastructure.

- The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications.

- The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.

Key Responsibilities:

- Ensures network security architecture aligns with operational security standards prior to and after deployment.

- Lead investigation and containment of network security incidents.

- Review firewall rule requests and ensure compliance with security standards.

- Design and maintain secure hybrid network architecture across on-premises and Azure environments.

- Monitor security events using SIEM technologies and coordinate incident response activities.

- Perform network security assessments and recommend remediation strategies.

- Develop and maintain network security standards, diagrams, and operational documentation.

- Support penetration testing and remediation efforts.

- Participate in on-call support during critical security incidents.

- Responsible for conducting proactive threat hunting and anomaly detection.

- Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).

- Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.

- Identifies, prioritizes, and remediates network security vulnerabilities.

- Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.

- Must have the ability to work independently on assigned projects.

Fill the skill matrix below:

Skill

Amount

Candidate's No. of years of experience

Required

8

Required

5

Required

3

WAF/NGFW

Required

3

Supporting environments with 300+ Network Devices

3

Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor

Required

Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel)

Required

Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def

Required

Candidate must have experience with the following areas: Active Directory, MFA, Conditional Access, Certificates

Required

Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles

Required

Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS

Required

Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP

Required

Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages

Required

Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.

Required

Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),

Required

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Network Security Engineer
Sr Network Security Engineer

Creative Solutions Services, LLC • Mechanicsville (VA)

Hybrid
USD 120,000 - 150,000
Sr Network Security Engineer
Sr Network Security Engineer

Accylerate • Mechanicsville (VA)

Hybrid
USD 130,000 - 180,000
Senior Network Security Engineer
Senior Network Security Engineer

Ampcus, Inc • Mechanicsville (VA)

On-site
USD 140,000 - 170,000
Senior Network Security Engineer
Senior Network Security Engineer

Jobtailor • Mechanicsville (VA)

On-site
USD 120,000 - 150,000
Senior Network Security Engineer - Hybrid Cloud Defense
Senior Network Security Engineer - Hybrid Cloud Defense

Mbi Llc • Mechanicsville (VA)

Hybrid
USD 110,000 - 140,000
Senior Network Security Engineer
Senior Network Security Engineer

TOMORROW HIRE • Mechanicsville (VA)

Hybrid
USD 95,000 - 123,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

CyberJobs.Com • Mechanicsville (VA)

Hybrid
USD 95,000 - 123,000
Senior Network Security Engineer
Senior Network Security Engineer

Liquid Environmental Solutions • Irving (TX)

On-site
USD 120,000 - 150,000
Sr Network Engineer
Sr Network Engineer

Mainz Brady Group • Everett (WA)

On-site
USD 120,000 - 180,000
Senior Network Security Engineer
Senior Network Security Engineer

Jobtailor • Tennessee

On-site
USD 120,000 - 180,000