Senior Network Security Engineer
Why This Role Stands Out
This hybrid role offers a fantastic opportunity to drive impactful security initiatives within a large-scale, hybrid enterprise environment, leveraging cutting-edge technologies like Palo Alto firewalls and Azure networking. You'll thrive here if you're a proactive security professional eager to deepen your expertise in network defense and incident response, contributing to the integrity and availability of critical infrastructure. Apply now to join a collaborative team and advance your career in network security.
Quick Overview
Job Description
The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT s network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT s network infrastructure.
Key Responsibilities:
Ensures network security architecture aligns with operational security standards prior to and after deployment.
Lead investigation and containment of network security incidents.
Review firewall rule requests and ensure compliance with security standards.
Design and maintain secure hybrid network architecture across on-premises and Azure environments.
Monitor security events using SIEM technologies and coordinate incident response activities.
Perform network security assessments and recommend remediation strategies.
Develop and maintain network security standards, diagrams, and operational documentation.
Support penetration testing and remediation efforts.
Participate in on-call support during critical security incidents.
Responsible for conducting proactive threat hunting and anomaly detection.
Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
Identifies, prioritizes, and remediates network security vulnerabilities.
Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
Must have the ability to work independently on assigned projects.
| Skill | Required / Desired | Amount | of Experience |
| Enterprise Networking | Required | 8 | Years |
| Enterprise Security | Required | 5 | Years |
| Azure Networking | Required | 3 | Years |
| WAF/NGFW | Required | 3 | Years |
| Supporting environments with 300+ Network Devices | Desired | 3 | Years |
| Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor | Required | ||
| Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) | Required | ||
| Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def | Required | ||
| Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates | Required | ||
| Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles | Required | ||
| Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS | Required | ||
| Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP | Required | ||
| Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages | Required | ||
| Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers. | Required | ||
| Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), | Required |
Skills
Similar jobs
Cybersecurity Specialist 3 - Chantilly, VA with Security Clearance
M.C. Dean · Chantilly, United States
12 minutes ago$104.1k - $156.1k/yrSr Principal Cyber Systems Engineer (S) with Security Clearance
Northrop Grumman · Jessup, United States
12 minutes ago$156.4k - $234.6k/yrSenior Associate, Privileged Access Management Delivery Engineer
KPMG · Seattle, United States
13 minutes agoSenior Associate, Privileged Access Management Delivery Engineer
KPMG · New York, United States
13 minutes ago$95.9k - $208.3k/yrSenior Associate, Privileged Access Management Delivery Engineer
KPMG · Chicago, United States
13 minutes ago$95.9k - $208.3k/yrSenior Associate, Privileged Access Management Delivery Engineer
KPMG · San Francisco, United States
13 minutes ago$95.9k - $208.3k/yr