Position Overview Varmoda LLC is seeking an experienced
Senior Network Security Engineer to support a public sector client's enterprise network, cloud, and computing infrastructure. This role is responsible for securing and maintaining a large-scale hybrid environment that includes on-premises and Azure-based network services, firewalls, WAF technologies, SIEM platforms, and mission-critical public-facing applications. The Senior Network Security Engineer will work closely with infrastructure, cloud engineering, and information security teams to ensure the confidentiality, integrity, and availability of enterprise systems.
Key Responsibilities - Design, implement, and maintain secure network security architectures across on-premises and Microsoft Azure environments.
- Review and manage firewall policies, rule requests, and access controls to ensure alignment with security standards.
- Monitor and investigate security events using SIEM technologies and lead containment efforts for security incidents.
- Conduct proactive threat hunting, anomaly detection, and network security assessments.
- Manage and support Palo Alto firewalls, WAF platforms, VPN solutions, and related network security technologies.
- Identify, prioritize, and remediate network security vulnerabilities using approved assessment and scanning tools.
- Develop and maintain network diagrams, architecture documentation, IP addressing schemes, security standards, and operational procedures.
- Participate in outage response, penetration test remediation activities, and on-call support for critical security incidents.
Required Qualifications - Minimum 8 years of enterprise networking experience.
- Minimum 5 years of enterprise security experience.
- Minimum 3 years of Azure networking experience.
- Minimum 3 years of Web Application Firewall (WAF) and/or Next-Generation Firewall (NGFW) experience.
- Hands-on experience with Palo Alto firewalls.
- Hands-on experience with zure Networking, including hybrid connectivity technologies.
- Experience with SIEM platforms, such as Splunk and/or Microsoft Sentinel.
- Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
- Experience with vulnerability management and remediation, including vulnerability scanning tools such as Nessus, Tenable, or Microsoft Defender.
- Experience with ctive Directory, MFA, Conditional Access, and certificate management.
- Experience with Network Access Control (NAC), 802.1X, RADIUS, and TACACS+.
- Experience with the following technologies:
- Palo Alto
- F5 Distributed Cloud
- zure WAF
- Cisco VPN
- GlobalProtect
- F5 BIG-IP
- Experience working in highly regulated environments.
- Experience leading technical troubleshooting efforts during production outages.
- bility to communicate technical issues to both technical and executive audiences.
- bility to mentor junior engineers.
- Candidate must possess or be able to obtain:
- Microsoft Azure Security Engineer (AZ-500)
- Microsoft Azure Network Engineer (AZ-700)
- Experience with security frameworks and standards, including:
- CIS Benchmarks
- NIST Cybersecurity Framework (NIST CSF)
- NIST 800-53
- Zero Trust principles
Preferred Qualifications - Experience supporting enterprise environments with 300+ network devices and/or locations.
- Experience with ExpressRoute connectivity and large-scale hybrid network deployments.
- Experience supporting SD-WAN environments.
- Experience managing infrastructure supporting mission-critical public-facing applications.
- Experience partnering with cloud engineering, infrastructure, and information security teams in complex enterprise environments.
- Strong documentation skills, including network topology diagrams, architecture diagrams, firewall rule documentation, and IP addressing plans.
- bility to work independently and lead assigned projects with minimal supervision.