Sr. Network Security Engineer

Titan Technologies

Washington

On-site

USD 110,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Titan Technologies, a Titan Technologies company, seeks a Senior Network Engineer to bolster cybersecurity for DHS USCIS systems. You will join Enterprise Security Architecture in Network Security, shaping controls and threat modeling across the USCIS environment.

Responsibilities include architecting security architecture, evaluating designs, automating security workflows, and producing lifecycle documentation.

Qualifications

  • 10 years of experience in network engineering and operations with security deployments.
  • 3 years of specialized experience deploying security products (Firewalls, IDS/IPS, etc.).
  • Proficiency with Cisco security technologies and standard network controls.

Responsibilities

  • Establish an enterprise cybersecurity architecture with a standard set of controls.
  • Evaluate current/network designs to ensure security is integrated.
  • Develop and maintain threat models and security standards for USCIS systems.
  • Automate security processes and consolidate security data into SIEM and reporting.
  • Write lifecycle documentation and support deployment of security products.
  • Collaborate with teams and participate in IPTs and Scrum activities.

Skills

Network engineering
Cybersecurity
Security architecture
Threat modeling

Education

Bachelor’s degree in Computer Science/Engineering/Information Management

Tools

Cisco IOS
Cisco NX-OS
Cisco ISE
ForeScout CounterACT
FirePOWER
StealthWatch
Tenable.io
Splunk

Job description

Zen Strategics, a Titan Technologies company, is seeking a Senior Network Engineer to support cybersecurity efforts for DHS USCIS systems. The Engineer will be part of Enterprise Security Architecture in Network Security which consists of the policies, processes, and practices to prevent, detect and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources. Network security involves the authorization of access to data in a network. This role supports security activities associated with evaluating and improving the security of the USCIS network.

Duties and Responsibilities:
  • Establish a new cybersecurity architecture and a standard set of controls commensurate with the increased threat to USCIS systems and data, including risk indicators and alignment to current measures.
  • Evaluate current and future network designs to ensure that security is incorporated.
  • Establish an Enterprise Data Security Architecture that identifies sensitive data elements requiring protection.
  • Identify and evaluate information security threat models and methodologies. Manage the implementation and maintenance of the selected methodologies by applying the threat model to support ongoing, proactive protection of the USCIS enterprise environment, and to facilitate an efficient response to security incidents. Develop standards, templates and automated mechanisms to support threat modeling and analysis of individual USCIS information systems and information. Provide recurring inputs, triggers and reporting into the USCIS SIEM and Ongoing Authorization processes.
  • At the discretion of the Federal task lead, architect, deploy, operate, and support a wide range of enterprise security solutions to address a broad set of security needs including, but not limited to: Vulnerability Management, Configuration Management, Network Access Controls, Malware Defenses, Application Software Security, Secure Code and library Review, Software Asset Management, Hardware Asset Management, Vulnerability Remediation, Security Event and Log Management, Incident Response, Penetration Testing, Wireless Access Control, Least Privilege, Network Monitoring, Boundary Defense, Security Assessment, Account Monitoring and Control, Data Protection, Insider Threat, Continuous Monitoring, and/or others as requested by the Government.
  • Automate and streamline repetitive IT security processes, and the handling of vast amounts of security data, at the discretion of the Federal task lead, using programming and the Security Event Management framework to consolidate security information and reporting.
  • Create actionable intelligence through triggers, filters, and signatures that pinpoint threats contained within the SIEM for Security Operations to investigate from new and existing continuous monitoring security products, such as, but not limited to: ForeScout, Tenable.io, CrowdStrike, DbProtect, Splunk, and CISCO ISE/IDS/IPS.
  • Implement and support filters, plugins, access control lists, and monitoring rules for new and existing continuous monitoring security products, such as, but not limited to: Tenable.io, CrowdStrike, Burp Suite, Splunk, CISCO ISE/IDS/IOS, Microsoft SCCM, PortSwigger Burp Suite and Fortify, etc.
  • Attend meetings, design reviews, engineering conference calls, system readiness reviews, and participate in Integrated Planning Teams (IPTs) and/or Scrum Sprints/Increments as required by the Federal lead to monitor security requirement execution throughout the USCIS/DHS Systems Lifecycle process and deliver minutes, and any ad-hoc project reporting requested by the Government.
  • Write system lifecycle documentation for security products or security‑relevant system components. This includes, but is not limited to: project architecture diagrams, project plans and timelines, Concepts of Operations, Standard Operating Procedures, use cases, user stories, change management documents, system lifecycle documentation, technical implementation strategies, and product specific configurations that align with USCIS policy and procedure, DHS policy and procedure, DHS continuous monitoring requirements and annual metrics, DoD STIGs, and NIST Special Publication 800 Guidance.
  • Perform product/standards comparisons based upon research, independent lab test result reports, intelligence agency recommendations, and other resources authoritative, mandatory, or compelling to a U.S. Federal agency.
  • Support the design and deployment of information security solutions at all layers of the OSI model, physical layer to application layer, to facilitate a comprehensive defense‑in‑depth strategy and intrusion defense chain methodology.
  • Be responsible for the technical configuration, installation, and/or monitoring of products into a pilot/evaluation location established via the USCIS Change Request (CR) process.
  • Generate procedures necessary to operate and maintain products under pilot/evaluation.
  • Generate USCIS/DHS Systems Lifecycle Process documentation necessary to obtain engineering approval for products under pilot/evaluation.
  • Generate the Enterprise Architecture (EA) documentation as necessary.
  • Schedule and attend meetings, file USCIS forms, tickets, and change requests necessary to facilitate successful deployment of security products/projects.
  • Generate and present formal reports and presentations that explain and defend the recommended product selections in meetings designated by the Government POC requesting the evaluation.
  • Assist with defining network architecture by ingress/egress micro‑perimeters with some internal micro‑segmentation.
  • Review existing configuration settings to identify potential security vulnerabilities and propose settings or architectural changes to address these vulnerabilities.
  • Work collaboratively with other teams to improve the use of automated configuration management capabilities to initiate network and environment changes and enforce security‑relevant configuration settings.
  • Assist with the development of automation to discovery networks, devices, and services, with manual or dynamic authorization and automated remediation of unauthorized entities.
  • Perform security hardening and rule creation for firewalls, switches, routers and other network equipment. This includes reviewing new and re‑evaluating existing configuration settings and rules to verify USCIS’ security posture and eliminate unnecessary risk.
You MUST have:
  • 10 years of experience in network engineering and operations and 3 years specialized experience deploying security products (Firewalls, IDS/IPS devices, StealthWatch, FirePOWER, Cisco ISE, ForeScout CounterACT, etc.).
  • Proficiency in configuring, securing, and creating custom rule sets for: Cisco Nexus, FlexPod, IOS, Identity Services Engine (ISE), StealthWatch, FirePOWER and any other additional networking technologies introduced by the Government during the duration of the contract.
  • Prior experience utilizing Cisco Prime, Orion SolarWinds or another configuration management tool to create enforceable configuration templates.
  • One of the following active certifications: Cisco Certified Internetwork Expert (CCIE) Security, CCIE Wireless, CCIE Data Center, CCIE Routing & Switching, Cisco Certified Network Professional Security (CCNP Security), or other comparable certification or experience, which must be approved in advance by the Government Program Manager on a case‑by‑case basis.
  • Ability to get and maintain Public Trust Security Clearance or Existing Public Trust Clearance preferred
Education:
  • A Bachelor’s degree in Computer Science, Information Management or Engineering, or other comparable degree or experience, which must be approved in advance by the Government Program Manager.
Company Description:

Titan Technologies, LLC and our wholly owned subsidiaries, TelaForce, LLC, Titan Facilities, Inc. and Zen Strategics, design, build, integrate, and manage innovative solutions and software applications. Our remarkable people, working collaboratively under a shared vision, have earned a reputation with our customers for delivering results with maximum impact. Sound intriguing? Consider Titan Technologies for the next step in your career journey and be part of an impactful team!

Titan is proud to be a Service‑Disabled Veteran Owned Business.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security - Remote
Network Security - Remote

Akima • South Burlington (VT)

Remote
USD 120,000 - 150,000
Comprehensive benefits
Competitive pay
Growth opportunities
Cybersecurity Engineer
Cybersecurity Engineer

CyberJobs.Com • Springfield (VA)

On-site
USD 130,000 - 140,000
Health, Dental, Vision
401(k) match
Paid time off (PTO)
+1
Senior Network Security Engineer: Threat Architect
Senior Network Security Engineer: Threat Architect

Titan Technologies • Washington

On-site
USD 110,000 - 180,000
VMware Architect
VMware Architect

22nd Century Technologies Inc. • Washington

On-site
USD 120,000 - 160,000
Network Administrator (Network Management Systems Engineer)
Network Administrator (Network Management Systems Engineer)

Sarela Technology Solutions LLC • Fort Belvoir (VA)

On-site
USD 85,000 - 100,000
Collaborative environment
Opportunities for technical growth
Network Security Engineer 2
Network Security Engineer 2

Itezz • Annapolis (MD)

On-site
USD 100,000 - 250,000
SEP IRA with 10% employer contribution
Medical plans
Dental plan
+1
Senior Cybersecurity Engineer (ACAS/Trellix SME)
Senior Cybersecurity Engineer (ACAS/Trellix SME)

ZTI Solutions LLC • Fort Meade (MD)

On-site
USD 100,000 - 130,000
Competitive salary
Medical, dental, and vision coverage
401(k) retirement plan
+1
Cyber Data Science Engineer
Cyber Data Science Engineer

TENICA and Associates LLC • Springfield (VA)

On-site
USD 80,000 - 100,000
Technical Lead
Technical Lead

ERT, Inc. • Arlington (VA)

On-site
USD 120,000 - 170,000
System / Cloud Engineer
System / Cloud Engineer

22nd Century Technologies Inc. • Washington

On-site
USD 90,000 - 140,000