Network Security Engineer, Lead
Job Description
Join AMERICAN SYSTEMS as a Lead Network Security Engineer supporting a critical national security mission in a highly classified environment onsite in Dallas, TX. This role combines hands-on network and firewall engineering with technical leadership, helping strengthen secure, resilient enterprise connectivity. Salary range: USD $155,000 - $180,000 per year.
What you’ll do
- Lead secure network engineering, administration, and operational support within a highly classified environment.
- Design, implement, configure, and maintain enterprise network infrastructure, including routers, switches, VLANs, ACLs, VPNs, network segmentation, and high-availability architectures.
- Administer, monitor, and troubleshoot enterprise firewall environments.
- Configure and manage firewall policies and access rules, including NAT, VPNs, security zones, logging, and monitoring.
- Support and troubleshoot Cisco Firepower and Firepower Management Center (FMC); Cisco Firepower experience is preferred.
- Troubleshoot complex Layer 2 and Layer 3 issues across routing, switching, firewalling, connectivity, and access control.
- Support AAA and network access control requirements (authentication, authorization, accounting).
- Configure and troubleshoot 802.1X, VPN, and network access control solutions.
- Support Cisco ISE environments, including authentication, authorization, policy enforcement, and network access control; Cisco ISE experience is preferred.
- Support RMF and STIG activities, including secure configuration, vulnerability remediation, and compliance.
- Develop and maintain network diagrams, implementation plans, SOPs, configuration documentation, and technical reports.
- Partner with cybersecurity, systems administration, and mission teams to deliver secure, resilient network solutions.
- Support incident response, outage resolution, root cause analysis, change implementation, and network remediation.
- Monitor network performance and recommend improvements to enhance security, availability, reliability, and performance.
- Provide technical leadership and guidance to network engineering and operations personnel.
What you bring
- U.S. citizenship required.
- Active TS/SCI clearance with SAP eligibility required.
- Bachelor’s degree in a related technical field, or additional relevant experience in lieu of a degree.
- 8+ years of experience in network engineering, network operations, or network security.
- Experience in enterprise, defense, intelligence, federal government, or highly regulated environments.
- Strong hands-on enterprise networking skills: routing and switching, Layer 2 and Layer 3 troubleshooting, VLANs and subnetting, ACLs, network addressing and design, VPN technologies, network segmentation, and resilient network architectures.
- Hands-on experience administering and troubleshooting enterprise firewalls.
- Experience with one or more firewall platforms: Cisco Firepower/FMC (preferred), Palo Alto Networks, Fortinet, Check Point, or other commercial or government enterprise firewalls.
- Experience with firewall policy administration, NAT, VPNs, security zones, logging, monitoring, and troubleshooting.
- Experience supporting AAA, 802.1X, RMF, STIG, secure configuration, and network access control requirements.
- Cisco ISE experience preferred, especially authentication, authorization, accounting, policy enforcement, and network access control.
- Active DoD 8140/8570 IAT II certification such as Security+ CE, CySA+, SSCP, or equivalent.
- Experience troubleshooting Cisco routers, switches, firewalls, and enterprise network infrastructure.
- Ability to work independently, lead technical efforts, and resolve complex network and security issues.
- Strong written and verbal communication skills.
Technologies you’ll work with
Cisco Firepower, Firepower Management Center (FMC), Palo Alto Networks, Fortinet, Check Point, Cisco ISE, 802.1X, NAT, VPN technologies, AAA (authentication, authorization, accounting), RMF, STIG, Cisco routers, Cisco switches, Security+ CE, CySA+, SSCP.
Benefits
- Healthcare benefits
- Paid leave
- Retirement plans
- Insurance programs
- Education and training assistance
Additional experience we value
- Experience supporting highly compartmented or special-access classified environments (helpful but not required).
- Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, or CCIE (helpful but not required).
- Experience with Palo Alto, Fortinet, Check Point, or other enterprise firewall technologies (helpful but not required).
- Experience with Cisco ISE, NAC, 802.1X, or related access control platforms (helpful but not required).
- Experience supporting network modernization, infrastructure upgrades, technology refresh, or network migration efforts (helpful but not required).
- Experience with incident response, change management, outage resolution, and root cause analysis in classified environments (helpful but not required).
- Familiarity with VMware or other virtualized environments (helpful but not required).
- Experience developing technical documentation, network diagrams, implementation plans, and standard operating procedures (helpful but not required).
Pay transparency: The salary range for this position is USD $155,000.00/Yr. - USD $180,000/Yr. Actual compensation will be determined based on several factors permitted by law.
EEO: EEO Race/Sex/Disability Status/Veteran Status.