TIC Systems Engineer

ERT, Inc.

Arlington (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Entarian is seeking an experienced TIC Systems Engineer to design, implement, and maintain secure network boundaries across multi-cloud environments. The role emphasizes TIC 3.0, Zero Trust principles, and effective configuration, monitoring, and management of boundary security systems.

You will design, deploy, and manage boundary protections including firewalls, proxies, NAC, IPS, and VPN gateways, and ensure secure connectivity between internal networks and cloud environments.

Qualifications

  • Bachelor-level degree or equivalent experience in computing.
  • At least 5 years designing, deploying, and managing F5 load balancing in large IT environments.
  • Experience implementing TIC 3.0 and Zero Trust architectures.
  • Proficiency with F5 LTM, GTM, and BIG-IQ.
  • Knowledge of F5 ASM and APM security technologies.
  • Strong networking and cloud experience across AWS, Azure, and GCP.

Responsibilities

  • Design, deploy, and manage boundary protection systems including firewalls, proxies, IPS, NAC, and VPN gateways.
  • Support TIC 3.0 security capabilities implementation and enforcement.
  • Design, deploy, and manage Cloudflare services (WAF, DDoS protection, CDN, DNS).
  • Configure Palo Alto firewalls and Panorama for centralized management and policy deployment.
  • Ensure secure connectivity and segmentation between internal networks, partners, and cloud environments.

Skills

TIC 3.0
Zero Trust
F5 load balancing
Palo Alto
Cloudflare
WAF
GTM
LTM
PANORAMA
Cloud platforms

Education

Bachelor's degree in computer science / IT or related field

Tools

Palo Alto
BIG-IP / BIG-IQ
Panorama
Cloudflare
AWS
Azure
GCP

Job description

TIC Systems Engineer
Overview / Job Responsibilities

We are seeking an experienced Trusted Internet Connections (TIC) System Engineer to design, implement, and maintain secure network perimeter defenses for our customer's network infrastructure. This role requires experience supporting TIC 3.0 and Zero Trust principles and focuses on protecting network boundaries against unauthorized access, data exfiltration, and external threats through effective configuration, monitoring, and management of boundary security systems and protocols.

Key Responsibilities:

  • Design, deploy, and manage boundary protection solutions including firewalls, web proxies, intrusion prevention systems (IPS), network access control (NAC), and VPN gateways.
  • Support the implementation and enforcement of Trusted Internet Connections (TIC) 3.0 security capabilities.
  • Design, deploy, and manage Cloudflare services, including Web Application Firewall (WAF), DDoS Protection, CDN, and DNS.
  • Design, configure, and maintain Palo Alto firewalls and configure and optimize Panorama for centralized firewall management and policy deployment.
  • Ensure secure connectivity and segmentation between internal networks, external partners, and cloud environments.
  • Maintain boundary protection documentation including diagrams and system configurations.
  • Ensure secure and efficient operation of systems that support boundary protection, threat detection, and telemetry collection.
  • Ensure the smooth operation of F5 load balancing solutions to support the enterprise network, multi-cloud, and mobility solutions.
  • Configure, and manage F5 load balancing solutions, including Local Traffic Manager (LTM) and Global Traffic Manager (GTM), to support enterprise network, multi-cloud, and mobility solutions.
  • Develop load balancing policies, monitor traffic flows, and fine-tune load balancing algorithms to improve application performance and availability.
  • Migrate existing stakeholder connections to new TIC 3.0 compliant environments.
  • Troubleshoot and resolve issues related to load balancing, including analyzing traffic patterns, identifying bottlenecks, and working with vendors to resolve complex issues.
  • Work with IT and business stakeholders to understand application requirements and develop load balancing solutions that meet those requirements.
  • Develop and implement balancing security policies and procedures to prevent unauthorized access to the network and ensure compliance with regulatory requirements.
  • Design, plan, and establish cloud networks using various cloud providers like AWS, Azure, and Google Cloud.
  • Design network architectures considering high availability, fault tolerance, and scalability.
  • Configure Virtual Private Cloud (VPC), subnets, transit gateways, VPN connections, and other cloud network components.
  • Analyze cloud network traffic patterns and optimize for performance.
  • Collaborate with other teams to ensure applications are using network resources efficiently.
  • Implement Content Delivery Networks (CDNs), load balancers, and other strategies to optimize user access.
  • Install, maintain, and evaluate network systems and communications and troubleshoot the most complex network issues.
  • Conduct various researches and analysis regarding new technology, network traffic, potential security risk, etc.
  • Lead the network architecture design and optimization. Must have extensive knowledge of Internet, computer, routers, switches, firewall, etc.
  • Work on advanced, complex technical projects or business issues requiring state of the art technical or industry knowledge.
  • May provide a leadership role for the work group through knowledge in the area of specialization.
Minimum Qualifications
  • Bachelor's degree in computer science, Information Technology, or related field or equivalent experience.
  • Minimum of 5 years of experience in designing, deploying, and managing F5 load balancing solutions in a large-scale IT environment.
  • Direct experience implementing and supporting Trusted Internet Connections (TIC) 3.0 and Zero Trust Architecture.
  • Technical expertise in F5 load balancing technologies, including LTM, GTM, and BIG-IQ.
  • Knowledge of F5 security technologies, including Advanced Web Application Firewall (ASM) and Access Policy Manager (APM).
  • Proficient in network technologies, including routing protocols, switching, firewalls, and VPN technologies.
  • Experience in designing and implementing load balancing solutions for multi‑cloud and mobile environments.
  • Good understanding of major cloud computing platforms such as AWS, Azure, and Google Cloud.
  • Strong analytical and problem‑solving skills, self‑motivated, and proactive.
  • Excellent verbal and written communication skills, with the ability to interact effectively with technical and non‑technical stakeholders.
  • Must be clearable for a US Government Clearance.

*Must be eligible to obtain a Department of Homeland Security EOD clearance (Requirements 1. US Citizenship, 2. Favorable Background Investigation)

Desired Qualifications
  • DHS EOD - 1st priority.
  • Any DHS badge + DoD Top Secret or Secret - 2nd choice.
  • DoD Secret or Top Secret + willingness to get EOD clearance - 3rd choice (it can take 45 days to obtain EOD clearance - work can only begin once the clearance is fully adjudicated).
Equal Opportunity Statement

Entarian is an Equal Opportunity and affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TIC Systems Engineer
TIC Systems Engineer

Entarian • Arlington (VA)

On-site
USD 140,000 - 190,000
Network Engineer - Firewall & Load Balancing
Network Engineer - Firewall & Load Balancing

Peraton • Ashburn (VA)

On-site
USD 120,000 - 150,000
Network Engineer - Firewall & Load Balancing
Network Engineer - Firewall & Load Balancing

Peraton • Orlando (FL)

On-site
USD 110,000 - 150,000
Network Engineer – Firewall & Load Balancing
Network Engineer – Firewall & Load Balancing

Peraton • Virginia (MN)

On-site
USD 120,000 - 160,000
Network Architect
Network Architect

Sarela Technology Solutions • Fort Belvoir (VA)

On-site
USD 180,000 - 230,000
401(k)
401(k) matching
Dental insurance
+6
Network Engineer - Firewall & Load Balancing
Network Engineer - Firewall & Load Balancing

Peraton • Springfield (VA)

On-site
USD 104,000 - 166,000
Network Architect
Network Architect

Career Listings • Fort Belvoir (VA)

On-site
USD 120,000 - 150,000
401(k)
Dental insurance
Health insurance
+3
TIC Security Engineer: Zero Trust & Cloud Boundary Expert
TIC Security Engineer: Zero Trust & Cloud Boundary Expert

Entarian • Arlington (VA)

On-site
USD 140,000 - 190,000
TIC 3.0 Developer
TIC 3.0 Developer

Big Impact Tech (BIT) • Washington

On-site
USD 100,000 - 130,000
Firewall Engineer
Firewall Engineer

Tetrad Digital Integrity LLC • Arlington (VA)

On-site
USD 115,000 - 125,000