OverviewAbile Group has an exciting and challenging opportunity for a Lead Firewall Engineer on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission.
The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.
Responsibilities- Serves as the focal point for all firewall tasks, operations, and projects.
- Leads, directs, and manages execution of all daily operations, troubleshooting, and maintenance activities of the NSS Boundary work center.
- Designs, implements, and manages security solutions using F5, Juniper SRX, and Palo Alto for project-based requirements.
- Ensures systems, devices, and application under your responsibility and span of control meet applicable STIG/SRG and organizational configuration baselines.
- Leads regular compliance evaluations and audits.
- Develops, oversees, maintains, and enforces configuration management processes, Standard Operational Procedures (SOPs), and other documentation as needed/required.
- Monitors platform performance, logs, software version(s), and configuration drift to identify and mitigate performance, compliance, and security issues.
- Develops and maintains network architecture diagrams, inventories, and licensing status for the various capabilities within the scope of the team.
- Provides written reports and oral briefings to contract and government leadership.
- Coordinates issues with the appropriate stakeholders to ensure task completeness and overall customer satisfaction.
- Provides recommendations on newly submitted customer requests.
- Evaluates and reports on new/emerging network/communication technologies to enhance capacity, performance and reliability of the network.
- Evaluates and recommends changes and/or technology upgrades to address performance, standardization and industry best practices.
- Conducts performance assessments, mentor, and coach personnel.
This position is 100% onsite in Springfield, VA.QualificationsClearance Required: TS/SCI with ability to obtain and maintain a CI poly.
Degree and Years of Experience: BS or MS degree in Computer Science, Cyber Security, Network Security or related field.
- 8+ years related technical experience network security technologies, tools, and techniques.
- 5+ years' experience with large-scale enterprise/global networks in a high paced diverse environment.
Required Certifications: - S6DoD 8140.01 and DoD 8570.01-M IAT Level II compliant certification (current). Must be able to successfully obtain/maintain CSSP Infrastructure Support certification within 120 days.
Desired Certifications:- F5 Networks certifications.
Required Skills: - Understanding and experience with the DoD Architecture Framework and other key DoD network architecture and strategic planning instructions.
- Demonstrated knowledge in planning, directing, and managing a Firewall / Boundary Security Team in an organization similar in size.
- Firewall experience within the DoW or IC.
- Demonstrated knowledge of implementation of Perimeter and Internal Firewalls (both physical and virtual contexts)
- Demonstrated advanced experience in managing baseline configurations across numerous firewalls.
- Demonstrated advanced experience in evaluating rules to ensure maximum security while minimizing redundancy and processing overhead.
- Demonstrated experience with researching and fielding new and innovative firewall technology.
- Experience with F5 platforms/technologies (APM, AFM, SSLO, etc.)
- Experience with Palo Alto platforms/technologies (Threat Prevention, Wildfire, URL Filtering, Global Protect)
- Experience with Juniper SRX platforms/technologies.
- Experience with Online Certificate Status Protocol OCSP revocation.
- Familiar with DoD PKI, Kerberos, LDAP, Active Directory, Authentication (SAML, OAuth)
- Ability to describe and troubleshoot TLS/SSL handshake/connection issues.
- Network design, engineering, and implementation (Advanced Level)
- Creation of network related Rough Order Magnitude (ROM) equipment lists and costing, Level of Effort (LOE) estimation for labor.
- Understanding of DoW, DISA, and IC standards and processes.
- Ability to work weekends and evening hours as needed.
Desired Skills: - Juniper JNCIS/JNCIP, Palo Alto PCNSE (or equivalent)