Sr. Network Security Engineer
Senior
Azure Networking
Cloud Platforms
Cybersecurity Tools
Data Security
Engineer
Facilities Management
Identity and Access Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Microsoft Sentinel
Nessus
Network Security
Palo Alto Networks
Project Management
Risk Management
Security
Security Compliance
Security Information And Event Management
Security Operations
Security Testing
Solution Architecture
Splunk
Tenable
Zero Trust Architecture
Job Description
Senior Network Security Engineer role supporting a hybrid enterprise network and cloud security program for an agency in the Richmond/Mechanicsville, VA area.
- Implement and support the agency’s IT network cloud and computing infrastructure
- Deliver day-to-day network security activities and ongoing operational support
- Ensure network security architecture aligns with operational security standards before and after deployment
- Lead investigation, containment, and coordination for network security incidents
- Review and validate firewall rule requests for compliance with security standards
- Design and maintain secure hybrid network architecture across on-premises and Azure environments
- Monitor security events using SIEM technologies and coordinate incident response activities
- Conduct network security assessments and recommend remediation strategies
- Develop and maintain network security standards diagrams and operational documentation
- Support penetration testing and remediation efforts
- Participate in on-call support during critical security incidents
- Perform proactive threat hunting and anomaly detection
- Validate WAF and firewall placement and integration exposure/connectivity
- Lead implementation review and management of agency WAFs
- Identify and diagnose system problems and threats using system logs, line monitors, SIEM diagnostic software, and test equipment
- Identify, prioritize, and remediate network security vulnerabilities
- Provide documentation including network architecture topology diagrams, IP schemes, firewall rules, and access controls when required
- Work independently on assigned projects
Requirements
- Enterprise Networking: 8 years (Required)
- Enterprise Security: 5 years (Required)
- Azure Networking: 3 years (Required)
- WAF/NGFW: 3 years (Required)
- Supporting environments with 300+ network devices: 3 years (Desired)
- Incident response, security investigations, log analysis, threat intelligence, and security monitoring experience (Required)
- SIEM products experience (e.g., Splunk, Microsoft Sentinel) (Required)
- Vulnerability management, remediation tracking, and vulnerability scanning tools (e.g., Nessus, Tenable, Def) (Required)
- Active Directory, MFA, Conditional Access, and Certificates experience (Required)
- Experience with SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, and Zero Trust principles (Required)
- Experience with Cisco ISE, NAC, 802.1X, RADIUS, TACACS (Required)
- Experience with products including Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP (Required)
- Experience working in highly regulated environments and leading technical troubleshooting during outages (Required)
- Ability to communicate technical issues to technical and executive audiences and mentor junior engineers (Required)
- Certifications: Azure Security Engineer (AZ-500) and/or Azure Network Engineer (AZ-700) (Required, or ability to achieve)
Technologies
- Palo Alto firewalls
- Azure networking
- ExpressRoute connectivity
- WAF technologies
- SD-WAN
- Splunk SIEM
- SIEM technologies
- Splunk
- Microsoft Sentinel
- Nessus, Tenable, Def
- Active Directory, MFA, Conditional Access, Certificates
- SEC530, CIS Benchmarks, NIST CSF, NIST 800-53
- Zero Trust principles
- Cisco ISE, NAC, 802.1X, RADIUS, TACACS
- F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
- Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700)
- SIEM diagnostic software, system logs, line monitors, test equipment
Contract, Location, and Pay
- Job type: Contract (Full-time listed)
- Location: Mechanicsville, VA 23116 (hybrid remote)
- Salary: $70.00 - $75.00 per hour
- Local requirement: Richmond/Mechanicsville, VA area only
Benefits
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Application Notes
- Proper email communication will only be done using @astyra.com addresses
- Ensure messages are sent/received through approved Astyra recruiters for quickest interview consideration
Application Questions
- Are you a U.S. Citizen or Permanent Resident?
- How many years of Enterprise Networking experience do you have?
- How many years of experience do you have with: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP?
- Do you have either or both certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700)?
- How many years of experience do you have with Azure Networking?
- How many years of WAF/NGFW experience do you have?