Senior Network Security Engineer

ePATHUSA, Inc.

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 8 years of experience in enterprise networking
  • 5 years of experience in enterprise security
  • 3 years of experience with Azure networking
  • Proficient in WAF/NGFW technologies
  • Experience supporting environments with over 300 network devices
  • 5+ years in incident response, security investigations, and log analysis
  • Experience with vulnerability management and scanning tools including Nessus.

Responsibilities

  • Implement and support VDOT's IT network and cloud infrastructure
  • Design and maintain secure hybrid network architectures
  • Lead investigation and containment of network security incidents
  • Monitor security events using SIEM technologies
  • Review firewall rule requests for security compliance
  • Conduct proactive threat hunting and anomaly detection
  • Develop and maintain network security standards and documentation.

Benefits

  • Paid Sick Time
  • Medical, Dental, Vision, and Life Insurance available
  • 401(k) with Employer Match
  • HSA and Short-term & Long-term Disability available
Full Job Description
Job Description
Seeking an experienced Senior Network Security Engineer to implement and support the agency's IT network, cloud, and computing infrastructure. The resource will perform day-today activities related to securing VDOT's infrastructure and related to securing, documenting, performing research, analysis, design, and implementations of VDOTs network and computing related infrastructure. Additionally:

  • Support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission critical public-facing applications.
  • Partner closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOTs network infrastructure.
  • Ensure network security architecture aligns with operational security standards before and after deployment.
  • Lead investigation and containment of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments.
  • Monitor security events using SIEM technologies and coordinate incident response activities.
  • Perform network security assessments and recommend remediation strategies.
  • Develop and maintain network security standards, diagrams, and operational documentation.
  • Support penetration testing and remediation efforts.
  • Participate in on-call support during critical security incidents.
  • Responsible for conducting proactive threat hunting and anomaly detection.
  • Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
  • Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
  • Identifies, prioritizes, and remediates network security vulnerabilities.
  • Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
  • Must have the ability to work independently on assigned projects.

Requirements

Skills
Required/Preferred
Years
Candidate Experience
Enterprise Networking
Required
8

Enterprise Security
Required
5

Azure Networking
Required
3

WAF/NGFW
Required
3

Supporting environments with 300+ Network Devices
Required
3

Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor
Required
5+

Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel)
Required
5+

Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def
Required
5+

Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates
Required
5+

Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles
Required
5+

Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS
Required
5+

Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
Required
5+

Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
Required
5+

Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
Required
5+

Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),
Required
5+

Benefits

Benefit Package includes:

  • Paid Sick Time
  • Insurance for Medical, Dental, Vision and Life Available
  • 401(k) including Employer Match
  • HSA, Short-term & Long-term Disability Available

Similar Jobs

More Jobs at ePATHUSA, Inc.

More Information Technology Jobs

Find similar Senior Network Security Engineer jobs: