Haystack
← Back to Jobs
Technology

Sr. Network Security Engineer

Masterapp LabsMechanicsville, VA🇺🇸United StatesPosted 3 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Title: Sr. Network Security Engineer
Location: Mechanicsville, VA (Onsite)
Position Type: Contract
Interview Mode: In-person

Key Responsibilities:

  • Ensures network security architecture aligns with operational security standards prior to and after deployment.
  • Lead investigation and containment of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments.
  • Monitor security events using SIEM technologies and coordinate incident response activities.
  • Perform network security assessments and recommend remediation strategies.
  • Develop and maintain network security standards, diagrams, and operational documentation.
  • Support penetration testing and remediation efforts.
  • Participate in on-call support during critical security incidents.
  • Responsible for conducting proactive threat hunting and anomaly detection. 
  • Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
  • Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment. 
  • Identifies, prioritizes, and remediates network security vulnerabilities.
  • Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required. 
  • Must have the ability to work independently on assigned projects.  
Required/Desired Skills
Skill
Required /Desired
Amount
Actual Years of Experience
Enterprise Networking
Required
8
 
Enterprise Security
Required
5
 
Azure Networking
Required
3
 
WAF/NGFW
Required
3
 
Supporting environments with 300+ Network Devices
Desired
3
 
Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor
Required
 
 
Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel)
Required
 
 
Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def
Required
 
 
Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates
Required
 
 
Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles
Required
 
 
Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS
Required
 
 
Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
Required
 
 
Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
Required
 
 
Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
Required
 
 
Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),
Required
 
 

Skills

MFA
Splunk
Active Directory
Azure
Penetration Testing
WAF
Zero Trust

Similar jobs