Senior Network Security Engineer

TOMORROW HIRE

Mechanicsville (VA)

Hybrid

USD 95,000 - 123,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TOMORROW HIRE seeks a Senior Network Security Engineer to secure and support a hybrid enterprise network across on-premises and Azure environments. You will design secure networks, lead incident response, and drive vulnerability management for mission critical systems and public-facing apps.

The role requires hands-on security expertise in Palo Alto, WAF/NGFW, Azure networking, and SIEM; collaboration with Infra, Cloud, and Security teams; and an in-person interview for final consideration.

Qualifications

  • Minimum 8 years of enterprise networking experience.
  • Minimum 5 years of enterprise security experience.
  • Minimum 3 years of Azure networking experience.
  • Minimum 3 years of WAF/NGFW experience.
  • Experience with incident response, log analysis, and security monitoring.
  • Experience with SIEM platforms such as Splunk or Microsoft Sentinel.
  • Experience with vulnerability assessment tools such as Nessus/Tenable.
  • Experience with Active Directory, MFA, CA, and certificate management.
  • Experience applying NIST CSF, 800-53, and Zero Trust principles.

Responsibilities

  • Design, implement, and maintain secure network architectures across on-premises and Azure environments.
  • Lead investigations, containment, and resolution of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Monitor security events using SIEM platforms and coordinate incident response.
  • Perform proactive threat hunting and vulnerability remediation across enterprise networks.
  • Lead implementation and management of WAF solutions and secure connectivity.

Skills

Enterprise networking
Azure networking
WAF/NGFW
Incident response
SIEM (Splunk)
Vulnerability management
AD/MFA/CA
Zero Trust

Tools

Palo Alto
Azure WAF
Cisco ISE
Nessus/Tenable
Splunk
Microsoft Sentinel

Job description

Job Title: Senior Network Security Engineer
Work Type: Hybrid
Location: Mechanicsville, VA
Start Date: 08/03/2026
End Date: 06/30/2027
Industry Category: Information Technology / Government
Employment Type: 1099 Contract
Requisition ID: 807471

Overview

We are seeking an experienced Senior Network Security Engineer to implement, secure, and support the agency's enterprise network, cloud, and computing infrastructure. This position plays a critical role in protecting a hybrid enterprise environment spanning approximately 300 statewide locations while ensuring the confidentiality, integrity, and availability of mission-critical systems and public-facing applications. The successful candidate will collaborate closely with Infrastructure, Cloud Engineering, and the Information Security Office to strengthen VDOT's cybersecurity posture across on-premises and Azure environments.

Application

Applications will be reviewed as received.

Candidates must:

  • Physically reside within the United States for the duration of the assignment.
  • Be legally authorized to work in the United States without employer sponsorship, now or in the future.
  • Be available to attend an in-person interview.
  • Meet all required technical qualifications listed below.
Job Description

The Senior Network Security Engineer is responsible for securing, designing, documenting, researching, implementing, and supporting VDOT's enterprise network and computing infrastructure. This role supports a large-scale hybrid environment that includes Palo Alto firewalls, Azure networking, ExpressRoute connectivity, Web Application Firewalls (WAF), Splunk SIEM, SD-WAN technologies, and mission-critical public-facing applications. The engineer will lead security initiatives, respond to incidents, perform proactive threat hunting, and ensure network security architecture aligns with agency standards and best practices.

Responsibilities
Technical Duties
  • Design, implement, and maintain secure network architectures across on-premises and Microsoft Azure environments.
  • Ensure network security architecture complies with operational security standards before and after deployment.
  • Lead investigations, containment, and resolution of network security incidents.
  • Review firewall rule requests and validate compliance with established security standards.
  • Monitor security events using SIEM platforms and coordinate incident response activities.
  • Conduct proactive threat hunting and anomaly detection across enterprise environments.
  • Perform network security assessments and recommend remediation strategies.
  • Identify, prioritize, and remediate network security vulnerabilities.
  • Support penetration testing initiatives and remediation efforts.
  • Validate Web Application Firewall (WAF) and firewall placement, integration, and connectivity.
  • Lead implementation, review, and ongoing management of agency WAF solutions.
  • Diagnose security threats using system logs, SIEM platforms, diagnostic tools, monitoring utilities, and test equipment.
Documentation & Security Governance
  • Develop and maintain network security standards and operational documentation.
  • Produce and maintain network architecture diagrams, IP addressing schemes, firewall rule documentation, and access control records.
  • Ensure documentation accurately reflects enterprise security configurations and operational procedures.
Collaboration
  • Partner with Infrastructure, Cloud Engineering, and Information Security teams to maintain secure enterprise operations.
  • Communicate technical issues effectively to both technical teams and executive leadership.
  • Mentor junior engineers and provide technical guidance on security best practices.
Operational Support
  • Support a hybrid enterprise environment consisting of approximately 300 statewide locations.
  • Participate in on-call support during critical security incidents.
  • Independently manage assigned projects while maintaining operational excellence.
Minimum Qualifications
  • Minimum 8 years of enterprise networking experience.
  • Minimum 5 years of enterprise security experience.
  • Minimum 3 years of Azure networking experience.
  • Minimum 3 years of WAF/Next-Generation Firewall (NGFW) experience.
  • Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
  • Experience with SIEM platforms such as Splunk or Microsoft Sentinel.
  • Experience with vulnerability management, remediation tracking, and vulnerability scanning tools such as Nessus, Tenable, or similar solutions.
  • Experience with Active Directory, Multi-Factor Authentication (MFA), Conditional Access, and certificate management.
  • Experience applying SEC530 guidance, CIS Benchmarks, NIST Cybersecurity Framework (CSF), NIST 800-53, and Zero Trust principles.
  • Experience with Cisco ISE, Network Access Control (NAC), 802.1X, ccExperience with Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, GlobalProtect, and F5 BIG-IP technologies.
  • Experience supporting highly regulated environments and leading technical troubleshooting during production outages.
  • Demonstrated ability to communicate technical concepts to technical and executive audiences.
  • Ability to mentor junior engineers.
  • Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), or the ability to achieve these certifications.
  • Must physically reside within the United States for the duration of the assignment.
  • Must attend an in-person interview.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Preferred Qualifications
  • Minimum 3 years of experience supporting enterprise environments with more than 300 network devices.
Compensation

This is a 1099 Contract position.

Pay Rate: $69 - $89 per hour

Schedule
  • Start Date: August 3, 2026
  • End Date: June 30, 2027
  • Assignment Duration: Approximately 11 months
  • Hybrid work arrangement.
  • Participation in on-call support during critical security incidents is required.
Work Location

Worksite Address:

Mechanicsville, VA

  • Hybrid work arrangement with onsite presence as required.
  • In-person interview is mandatory.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer 3
Cybersecurity Engineer 3

CyberJobs.Com • Mechanicsville (VA)

Hybrid
USD 95,000 - 123,000
Senior Network Security Engineer
Senior Network Security Engineer

Data Capital Inc • Richmond (VA)

Hybrid
USD 120,000 - 160,000
Senior Network Security Engineer
Senior Network Security Engineer

Mbi Llc • Mechanicsville (VA)

Hybrid
USD 110,000 - 140,000
Senior Network Engineer
Senior Network Engineer

Openkyber • United States

On-site
USD 120,000 - 180,000
Sr Network Security Engineer
Sr Network Security Engineer

Creative Solutions Services, LLC • Mechanicsville (VA)

Hybrid
USD 120,000 - 150,000
VDOT Sr. Infrastructure Engineer
VDOT Sr. Infrastructure Engineer

Software Technology Inc • United States

Hybrid
USD 110,000 - 150,000
Senior Network Security Engineer
Senior Network Security Engineer

Ampcus, Inc • Mechanicsville (VA)

On-site
USD 140,000 - 170,000
Senior Network Engineer – Hybrid Cloud & Azure Security (W2)
Senior Network Engineer – Hybrid Cloud & Azure Security (W2)

Snowrelic Inc • United States

Hybrid
USD 100,000 - 130,000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Data Capital Inc • Richmond (VA)

Hybrid
USD 90,000 - 130,000
M730-Senior Network Security Engineer
M730-Senior Network Security Engineer

Focused HR Solutions • Mechanicsville (VA)

Hybrid
USD 110,000 - 160,000