The DC Office of the Chief Financial Officer (OCFO) needs a Senior Network Security Engineer to support the design, implementation, operation, and security of the OCFO network and its security infrastructure: configuring and securing network appliances, defending the perimeter, resolving complex issues, and providing network design services. Hybrid in Washington, DC, DMV-local candidates.
What you'll do
- Support the design, implementation, operation, and security of the OCFO network and supporting security infrastructure
- Monitor and analyze traffic patterns, identify network problems, and recommend improvements for optimal performance, reliability, and stability
- Configure routers, switches, firewalls, and other appliances in compliance with OCFO security standards
- Monitor perimeter security measures to prevent breaches and safeguard information from unauthorized access; stay current on the latest threats, worms, and malware
- Resolve complex technical issues escalated to the Network Engineer level with appropriate urgency; coordinate solutions and communicate results
- Provide network design services and coordinate with the Infrastructure Services Group on scope, timing, and technical approach for network changes
What you need
- Experience building large-scale, multi-site network architectures
- Experience with secure remote access / WAN technologies (IPsec, VPN, etc.)
- Knowledge of network-based and system-level attacks and mitigation methods
- Experience with firewalls: Cisco Firepower (NGFW) or Cisco ASA Firewalls, and with security routing protocols
- 4 plus years across networked systems (LANs, WANs, telephony), network standards/protocols, network architecture and topology, routing configuration management, and network systems management (end-to-end performance monitoring)
- Local to the DMV area and able to report onsite in Washington, DC as required
Required skills
- Network architecture and topology design across multi-site LAN/WAN and telephony environments
- Routing, switching, and network configuration management, with end-to-end performance monitoring
- Network security engineering: perimeter defense, threat mitigation, and safeguarding against unauthorized access
- Firewall configuration and operation (next-generation firewalls) in compliance with security standards
- Secure remote access and WAN technologies (IPsec, VPN) and security routing protocols
- Forensic and packet analysis; security-focused monitoring and logging systems