CybersecurityJobs.io
← Back to all jobs

Job Description

Senior Network Security Engineer role supporting a hybrid enterprise network and cloud security program for an agency in the Richmond/Mechanicsville, VA area.

  • Implement and support the agency’s IT network cloud and computing infrastructure
  • Deliver day-to-day network security activities and ongoing operational support
  • Ensure network security architecture aligns with operational security standards before and after deployment
  • Lead investigation, containment, and coordination for network security incidents
  • Review and validate firewall rule requests for compliance with security standards
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments
  • Monitor security events using SIEM technologies and coordinate incident response activities
  • Conduct network security assessments and recommend remediation strategies
  • Develop and maintain network security standards diagrams and operational documentation
  • Support penetration testing and remediation efforts
  • Participate in on-call support during critical security incidents
  • Perform proactive threat hunting and anomaly detection
  • Validate WAF and firewall placement and integration exposure/connectivity
  • Lead implementation review and management of agency WAFs
  • Identify and diagnose system problems and threats using system logs, line monitors, SIEM diagnostic software, and test equipment
  • Identify, prioritize, and remediate network security vulnerabilities
  • Provide documentation including network architecture topology diagrams, IP schemes, firewall rules, and access controls when required
  • Work independently on assigned projects

Requirements

  • Enterprise Networking: 8 years (Required)
  • Enterprise Security: 5 years (Required)
  • Azure Networking: 3 years (Required)
  • WAF/NGFW: 3 years (Required)
  • Supporting environments with 300+ network devices: 3 years (Desired)
  • Incident response, security investigations, log analysis, threat intelligence, and security monitoring experience (Required)
  • SIEM products experience (e.g., Splunk, Microsoft Sentinel) (Required)
  • Vulnerability management, remediation tracking, and vulnerability scanning tools (e.g., Nessus, Tenable, Def) (Required)
  • Active Directory, MFA, Conditional Access, and Certificates experience (Required)
  • Experience with SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, and Zero Trust principles (Required)
  • Experience with Cisco ISE, NAC, 802.1X, RADIUS, TACACS (Required)
  • Experience with products including Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP (Required)
  • Experience working in highly regulated environments and leading technical troubleshooting during outages (Required)
  • Ability to communicate technical issues to technical and executive audiences and mentor junior engineers (Required)
  • Certifications: Azure Security Engineer (AZ-500) and/or Azure Network Engineer (AZ-700) (Required, or ability to achieve)

Technologies

  • Palo Alto firewalls
  • Azure networking
  • ExpressRoute connectivity
  • WAF technologies
  • SD-WAN
  • Splunk SIEM
  • SIEM technologies
  • Splunk
  • Microsoft Sentinel
  • Nessus, Tenable, Def
  • Active Directory, MFA, Conditional Access, Certificates
  • SEC530, CIS Benchmarks, NIST CSF, NIST 800-53
  • Zero Trust principles
  • Cisco ISE, NAC, 802.1X, RADIUS, TACACS
  • F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
  • Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700)
  • SIEM diagnostic software, system logs, line monitors, test equipment

Contract, Location, and Pay

  • Job type: Contract (Full-time listed)
  • Location: Mechanicsville, VA 23116 (hybrid remote)
  • Salary: $70.00 - $75.00 per hour
  • Local requirement: Richmond/Mechanicsville, VA area only

Benefits

  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Application Notes

  • Proper email communication will only be done using @astyra.com addresses
  • Ensure messages are sent/received through approved Astyra recruiters for quickest interview consideration

Application Questions

  • Are you a U.S. Citizen or Permanent Resident?
  • How many years of Enterprise Networking experience do you have?
  • How many years of experience do you have with: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP?
  • Do you have either or both certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700)?
  • How many years of experience do you have with Azure Networking?
  • How many years of WAF/NGFW experience do you have?

Similar Jobs