Position Overview
We are looking for a skilled Network Security Engineer to support enterprise network infrastructure initiatives focused on secure scalable and high-availability systems. The engineer will play a vital role in the planning design deployment and management of secure networking solutions across systems. This role requires a deep understanding of network security principles modern tools and enterprise environments along with a proactive and collaborative approach to problem-solving and project .
Responsibilities
- Contribute to the architecture and deployment of robust and secure network systems aligned with enterprise requirements.
- Manage hands-on implementations of next-gen firewall technologies and secure connectivity solutions.
- Lead or participate in transitioning legacy systems to contemporary platforms using Palo Alto Cisco and other security tools.
- Deliver ongoing security assessments and performance reviews for data communication networks.
- Generate technical documentation including network diagrams implementation plans and status updates.
- Support end-user issue resolution in coordination with other IT teams and maintain regular communication on project status.
- Coordinate and conduct weekly status meetings prepare reports and track milestones.
Required Qualifications
- Associate degree in a relevant IT discipline.
- Active certifications in:
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Cisco Certified Network Professional (CCNP) Enterprise or Security
Preferred Qualifications
- Bachelors degree in Information Technology or a related field.
- At least 10 years of hands-on experience in IT networking and cybersecurity across CONUS.
- Additional certifications highly desired:
- Prisma Certified Cloud Security Engineer (PCCSE)
- Cisco Certified Internetwork Expert (CCIE) Enterprise Infrastructure or Security
Technical Skills & Experience
- Extensive experience with:
- Palo Alto Networks (firewalls content filtering DLP VPNs IDS/IPS SSL/TLS inspection)
- Cisco switching routing wireless infrastructure
- A10 load balancers and reverse proxies
- Cisco ISE Free Radius and ACLs
- Familiarity with:
- MFA and 802.1x authentication
- Cloud-based security and networking models
- EIGRP OSPF BGP routing protocols
- PKI certificate management
- Nessus NMAP Wireshark for vulnerability and protocol analysis
- Panorama SolarWinds for centralized management
- Demonstrated ability to:
- Mentor junior engineers and work independently
- Create technical documentation and deliver professional presentations
Work Schedule and Conditions
- Hybrid work model:
- 3 days onsite at Annapolis location
- 2 days remote (subject to performance and approval)
- Standard hours: MondayFriday 8:00 AM4:30 PM EST
- Must be available for on-site support within 4 hours if needed
- Occasional extended hours weekends or holidays may be required