Quick Overview
Job Description
R-00194243 Description Leidos is seeking an experienced Principal Network Security Engineer to design, engineer, and implement enterprise network security capabilities across a large, distributed network environment. The role is responsible for advancing network security architecture through the execution of strategic design and implementation efforts that improve the security posture, segmentation, access control, and resiliency of the enterprise network.
This position is responsible for overall network security engineering support across a broad range of efforts, including planning, designing, and evaluating the security components of the network. Duties include providing specifications for network security architecture, evaluating and recommending new technologies to enhance current capabilities, performing needs assessments, and directing the installation, configuration, testing, and tuning of network security infrastructure.
The successful candidate serves as a technical leader and subject matter expert — assessing the current security architecture, defining the controls and segmentation model the enterprise needs, building practical implementation plans with realistic risk and rollback provisions, and directing a team of engineers to deliver them under aggressive timelines.
Scope and Impact Impact: Influences development of solutions that impact strategic project and program goals and business results. Recommends and develops new technical solutions, products, and security standards. Leads and manages the work of other technical staff that has significant impact on project results and outputs.
Complexity: Resolves highly complex problems through significant application of technical knowledge, conceptualization, reasoning, and interpretation. Develops solutions that are highly innovative and achieved through research and integration of best practices.
Communication: Communicates with government, program, cybersecurity, and technical leadership on matters of significant technical importance. Presents security architecture recommendations, implementation plans, risks, dependencies, and status to technical leadership, cybersecurity authorities, stakeholders, and approval boards, and works to build consensus around new concepts, practices, and approaches.
Knowledge: In-depth understanding of network security principles, theories, and concepts and their application across a range of programs. Serves as a subject matter expert within the network security domain.
Primary Responsibilities: Network Security Engineering and Architecture
- Design, engineer, and implement enterprise network security architecture spanning next-generation firewalls, intrusion detection and prevention, web and TLS proxies, VPN and encryption services, network access control, DNS security, and east-west security controls.
- Evaluate the current network security architecture, identify gaps and improvement opportunities, estimate level of effort, assess implementation risk, and develop practical engineering plans to strengthen enterprise security capabilities.
- Lead network segmentation and secure connectivity efforts, including data-flow mapping, security-zone and enclave design, firewall rule set and ACL review and rationalization, routing and security policy coordination, cutover sequencing, validation, and stakeholder approval.
- Design and implement network access control and device-posture enforcement (Comply-to-Connect style), including identity and device authentication, posture assessment, policy enforcement points, remediation workflows, and phased enforcement rollout.
- Advance zero-trust-aligned networking, micro-segmentation, least-privilege access policy, and encrypted-transport strategies across the enterprise.
- Provide specifications for network security architecture, evaluate and recommend emerging security technologies, and perform needs assessments to inform design and investment decisions.
- Engineer secure connectivity between on-premises, cloud, and remote environments, including IPsec and TLS VPN, secure cloud interconnects, and perimeter and boundary protection designs.
- Tune and optimize security controls to reduce false positives, close coverage gaps, and improve detection and enforcement without degrading network performance or availability.
- Drive security engineering projects from concept through implementation, including architecture evaluation, requirements analysis, dependency identification, design coordination, planning, execution, validation, and transition to operations.
- Develop and manage implementation plans, schedules, cutover strategies, contingency plans, rollback procedures, validation steps, stakeholder communications, and change documentation for mission-critical security changes.
- Coordinate change windows, maintenance activities, test validation, and rollback procedures for high-impact security policy and infrastructure changes.
- Partner with network architecture, cybersecurity, operations, project management, and technical SME teams to resolve blockers, manage dependencies, and reduce delivery risk.
- Support accreditation and compliance activities, including security control implementation, STIG application, vulnerability remediation, POA&M support, and the technical artifacts required for authorization.
- Serve as the senior technical authority for network security design decisions, providing technical direction, mentoring, and day-to-day guidance to network and security engineers, administrators, and analysts.
- Organize technical priorities, track details across concurrent efforts, manage competing demands, and maintain accountability against aggressive schedules.
- Provide clear, well-reasoned technical information and recommendations to government stakeholders and approval authorities.
- Continuously improve engineering processes, documentation standards, implementation playbooks, migration runbooks, technical standards, and execution models to accelerate delivery, reduce rework, improve operational handoff, and lower sustainment burden.
- Network security architecture and logical/physical design diagrams
- Data-flow diagrams, security-zone models, and segmentation designs
- Firewall policy standards, rule set baselines, and ACL documentation
- Port, protocol, and services (PPS) requirements
- Implementation and cutover plans with rollback and contingency procedures
- Test and validation plans
- Risk, dependency, and decision registers
- Security control implementation statements and accreditation artifacts
- Technical standards, playbooks, runbooks, and standard operating procedures
- As-built and operations transition documentation Required Qualifications:
- Bachelor's degree or equivalent experience and 12+ years of prior relevant experience, or Master's degree with 10+ years of experience. Specific experience, education, and training may be considered in lieu of a degree.
- Significant experience designing and implementing network security architecture in complex, large-scale enterprise environments.
- Experience serving as a senior technical lead directing the work of network and security engineers, administrators, analysts, or implementation resources.
- Experience leading security engineering projects from planning through implementation, including requirements analysis, dependency management, risk reduction, contingency planning, execution oversight, validation, and operational transition.
- Hands-on engineering experience with next-generation firewalls, intrusion detection and prevention systems, proxies and TLS inspection, VPN and encryption services, and network access control platforms.
- Experience with network segmentation or similar secure connectivity efforts, including data-flow analysis, firewall and ACL policy review, routing changes, security-zone design, stakeholder coordination, and implementation planning.
- Strong working knowledge of core networking concepts, including TCP/IP, routing protocols, switching, VLANs, DNS/DHCP/IPAM, NAT, QoS, and software-defined and cloud-connected network environments.
- Hands-on experience with two or more of the following technologies: Palo Alto, Cisco, Aruba, Dell, Infoblox, and Brocade.
- Working knowledge of Federal Government application, server, and network security requirements such as NIST, FedRAMP, FISMA, RMF, DISA STIGs, and DoD cybersecurity requirements.
- Demonstrated ability to organize work, track details, manage competing priorities, meet aggressive schedules, and drive complex technical efforts to completion with a high degree of accountability.
- Experience documenting security and network designs, implementation plans, risks, dependencies, and technical recommendations using tools such as Visio, PowerPoint, Cameo, or similar.
- Excellent written and verbal communication skills, including experience briefing technical leadership, cybersecurity authorities, stakeholders, and approval boards.
- Current IAT Level II or higher certification, such as Security+ or CISSP.
- Active DoD Secret clearance.
Preferred Qualifications
- CISSP, Palo Alto PCNSE, Cisco CCNP Security, or equivalent advanced security certification.
- Experience implementing Comply-to-Connect, 802.1X, or comparable network access control and device-posture enforcement at enterprise scale.
- Experience with zero-trust architecture, micro-segmentation, SASE, or secure cloud connectivity designs.
- Experience integrating network security platforms with SIEM, SOAR, ITSM, and analytics tooling.
- Experience with security automation and infrastructure-as-code using Python, Ansible, REST APIs, or similar, including automated firewall policy management.
- Experience with certificate and PKI management, encrypted-traffic inspection, and key management in enterprise
Similar jobs
- DI
Senior Endpoint Security Systems Engineer - Adelphi, MD with Security Clearance
NewDirectViz, LLC
Adelphi, MD🇺🇸On-site21 hours agoGCPAWSAzure+4Technology - DO
IT CYBERSECURITY SPECIALIST (INFOSEC) with Security Clearance
Department of Defense
Montgomery, AL🇺🇸Hybrid2 months agoTechnology - IT
SAP Security Lead
NewInnoworx Technology Services LLC
Carlsbad, CA🇺🇸On-site21 hours agoTechnology - TC
Sr. Information Systems Security Officer with Security Clearance
NewTEKsystems c/o Allegis Group
Reston, VA🇺🇸Hybrid21 hours agoEncryptionTechnology - CB
Information Security Analyst
NewCobalt Benefits Group LLC
Manchester, New Hampshire🇺🇸Hybrid35 minutes agoEncryptionSOC 2Generative AI+2Technology - AT
Cyber Security Architect
NewAltitude Technology Solutions Inc
Jersey City, NJ🇺🇸Remote21 hours agoAPI GatewayAWSAgile+3Technology - CO
Ping security Analyst
NewConfigUSA
Seattle, WA🇺🇸On-site21 hours agoTechnology - BR
Security Operations Center Manager
NewBrinks
New York, NY🇺🇸Hybrid21 hours agoMicrosoft ExcelSchedulingTechnology - TD
Penetration Tester with Security Clearance
NewTharros Defense, Inc.
Norfolk, VA🇺🇸Hybrid21 hours agoMicrosoft OfficePenetration TestingTechnology - SA
Senior Cyber Software Engineer - Precision Fires
SAIC
Huntsville, AL🇺🇸Remote3 days agoSVNEmbedded SystemsScrum+4Technology - RT
Embedded Security Software Engineer II (Onsite) with Security Clearance
NewRTX
Tewksbury, MA🇺🇸$68.9k - $131.1k/yrHybrid21 hours agoScrumAgileC+++3Technology - NG
2027 - Associate Cyber Software Engineer - Cincinnati OH with Security Clearance
NewNorthrop Grumman
Cincinnati, OH🇺🇸$76.2k - $114.4k/yrHybrid21 hours agoMercurialShellTCP/IP+6Technology