Senior Network Security Engineer
DataStaff, Inc. is seeking a Senior Network Security Engineer for a long-term contract opportunity with one of our direct clients in the Richmond, VA area.
*This position is hybrid
Job Description:
Our client is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agency’s IT network, cloud, and computing infrastructure.
The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of the network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of the network infrastructure.
Key Responsibilities:
- Ensures network security architecture aligns with operational security standards before and after deployment.
- Lead investigation and containment of network security incidents.
- Review firewall rule requests and ensure compliance with security standards.
- Design and maintain secure hybrid network architecture across on-premises and Azure environments.
- Monitor security events using SIEM technologies and coordinate incident response activities.
- Perform network security assessments and recommend remediation strategies.
- Develop and maintain network security standards, diagrams, and operational documentation.
- Support penetration testing and remediation efforts.
- Participate in on-call support during critical security incidents.
- Responsible for conducting proactive threat hunting and anomaly detection.
- Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
- Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
- Identifies, prioritizes, and remediates network security vulnerabilities.
- Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
- Must have the ability to work independently on assigned projects.
Required Skills:
- 8 Years - Enterprise Networking
- 5 Years - Enterprise Security
- 3 Years - Azure Networking
- 3 Years - WAF/NGFW
- Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor
- Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel).
- Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable)
- Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates.
- Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles.
- Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS.
- Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP.
- Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
- Candidate must have the ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers
- Candidate should have achieved or the ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700)
Desired Skill:
- 3 Years - Supporting environments with 300+ Network Devices
This opportunity is available on a corp-to-corp basis or as a W2 position with a competitive benefits package. DataStaff, Inc. offers medical, dental, and vision coverage options as well as paid vacation, sick, and holiday leave. As many of our opportunities are long-term, we also have a 401k program available for employees after 6 months.