Ampcus inc

Senior Network Security Engineer

Ampcus inc$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in enterprise networking
  • 5+ years in enterprise security
  • 3+ years with Azure networking
  • 3+ years with WAF/NGFW
  • Experience with SIEM products like Splunk or Microsoft Sentinel
  • Knowledge of vulnerability management tools such as Nessus or Tenable
  • Expertise in security frameworks like CIS Benchmarks, NIST CSF, and Zero Trust principles

Responsibilities

  • Ensure network security architecture meets operational standards pre- and post-deployment.
  • Lead investigations for network security incidents and take necessary containment actions.
  • Review firewall rule requests for compliance with security standards.
  • Design and maintain secure network architecture across on-premises and cloud environments.
  • Monitor security events through SIEM tools and coordinate incident response.
  • Conduct network security assessments and propose remediation strategies.
  • Develop and maintain network security standards and documentation.

Benefits

  • Opportunity to work in a hybrid enterprise environment with a wide range of technologies.
  • Close collaboration with Infrastructure, Cloud Engineering, and Information Security teams.
  • Chance to lead significant security initiatives across the organization.
  • Engagement with cutting-edge technologies like Palo Alto firewalls, Azure networking, and Splunk SIEM.
  • Involvement in proactive threat hunting and vulnerability remediation efforts.
Full Job Description
Job Title: Senior Network Security Engineer

Location(s): Mechanicsville, VA

Complete Description:
We are seeking an experienced Sr. Network Security Engineer (Sr. NSE) to implement and support the organization's IT network, cloud, and computing infrastructure. The Sr. NSE performs day-to-day activities related to securing the organization's infrastructure, including documentation, research, analysis, design, and implementation of network and computing infrastructure.

The Sr. NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of the organization's network infrastructure.

Key Responsibilities:
  • Ensure network security architecture aligns with operational security standards before and after deployment.
  • Lead investigation and containment of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments.
  • Monitor security events using SIEM technologies and coordinate incident response activities.
  • Perform network security assessments and recommend remediation strategies.
  • Develop and maintain network security standards, diagrams, and operational documentation.
  • Support penetration testing and remediation efforts.
  • Participate in on-call support during critical security incidents.
  • Conduct proactive threat hunting and anomaly detection.
  • Validate WAF and firewall placement, integration, exposure, and connectivity. Lead the implementation, review, and management of enterprise WAF solutions.
  • Identify and diagnose system problems and security threats using system logs, line monitors, SIEM platforms, diagnostic software, and test equipment.
  • Identify, prioritize, and remediate network security vulnerabilities.
  • Provide documentation, network architecture topology diagrams, IP addressing schemes, firewall rules, and access control documentation as required.
  • Work independently on assigned projects.

Skills:

Skill Required / Desired Amount of Experience Expertise Rating Move Enterprise Networking Required 8 Years Enterprise Security Required 5 Years zure Networking Required 3 Years WAF/NGFW Required 3 Years Supporting environments with 300+ Network Devices Desired 3 Years Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor Required Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) Required Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def Required Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates Required Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles Required Candidate must have experience with the following: Cisco Client, NAC, 802.1X, RADIUS, TACACS Required Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP Required Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages Required Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers. Required Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), Required

Similar Jobs

More Jobs at Ampcus inc

More Information Technology Jobs

Find similar Senior Network Security Engineer jobs: