Remote job
Senior Network Security Engineer
Job details
About this role
Role overview This is a senior-level network security engineering role focused on modernizing a federal network perimeter from legacy colocation-based designs to a cloud-integrated Trusted Internet Connection (TIC) 3.0 framework. The position operates as a technical anchor in a high-tempo, availability-first environment, supporting mission-critical government operations. The role is fully remote within the United States and may require occasional on-site presence for system-impacting events.
Responsibilities - Design, configure, and maintain geographically distributed network boundaries, including secure site-to-site IPsec VPN tunnels supporting the TIC 3.0 transition. - Administer and troubleshoot enterprise firewall and switching infrastructure across multi-vendor platforms (e.g., Palo Alto Networks, Fortinet, Juniper, Brocade). - Maintain network configuration baselines using Infrastructure-as-Code practices, writing and executing Ansible playbooks and GitLab CI/CD pipelines to automate VLAN assignments, port configuration, and dynamic DNS sinkhole blocks. - Operate packet brokers and network observability tools to capture traffic, monitor internal flows, detect anomalous lateral movement, and track perimeter performance. - Maintain accurate technical documentation of cabling, IPs, MAC addresses, VLANs, topology maps, and configuration baselines, while performing configuration drift audits. - Collaborate with Information System Security Officers (ISSOs) and vulnerability teams to run scans, apply STIGs/CIS benchmarks, and execute remediation patching. - Configure and sustain high-availability firewalls, participate in a 24/7 on-call rotation with a one-hour response window, and diagnose split-brain or ARP resolution issues.
Requirements - Bachelor's degree in Computer Science, Computer Systems Engineering, Cybersecurity, or a related field with 5+ years of relevant experience; Associate's with 8+ years; or 11+ years without a degree. - 3+ years of hands-on administration of Palo Alto Networks firewalls (PAN-OS) and Juniper core switching (Junos OS) in an enterprise environment. - Deep technical mastery of BGP (including Anycast and route-withdrawal failover), OSPF, and IPsec VPN tunneling. - Working knowledge of federal security frameworks including FISMA, NIST RMF SP 800-53 Rev. 5, and CISA Zero Trust guidelines. - Active security clearance (Secret) and ability to support Department of Commerce-aligned standards.
Nice to have - One or more role-based certifications such as ISC2 CISSP/ISSAP, Cisco CCIE Security/CCDE/CCAr, ISC2 CCSP, or an active CCNA or equivalent advanced vendor credential.
Benefits and work setup - Fully remote, full-time role based in the United States. - Projected compensation range of approximately $117,000 to $195,100 annually, depending on experience, location, and contract specifics. - Benefits package may include health insurance, life insurance, paid time off, holiday pay, short- and long-term disability, retirement savings, learning and development opportunities, and wellness programs.