Jobs · Information Technology · Florida

Firewall Engineer, Checkpoint & VPN Focus, Progression

Tampa Electric · Lutz, FL · 1 wk ago
Information TechnologyFull-time

This position can be hired at any level within the job family based on education and years of experience, but is ideally targeting the Senior level (Level 3).

About the Role

The Network & Systems Security Analyst (Firewall Engineer) is responsible for planning, designing, implementing, and supporting new and existing network, server, and storage infrastructure. This role ensures all network security controls—such as firewalls, web application firewalls (WAF), proxies, network segmentation, NAC, ACLs, and more—are implemented and managed per corporate information security standards. The position also involves assessing enterprise and critical assets for secure configurations and maintaining compliance with regulations like NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), and Payment Card Industry (PCI).

Key focus areas include strong hands-on experience with Palo Alto in production, Checkpoint (a plus), and proven expertise in designing and supporting VPN solutions, particularly in high-availability or large-scale enterprise environments.

Responsibilities

  • Design, plan, operate, maintain, and support TECO and NMGC network infrastructure, including route/switch, on-premise LAN/WAN, IPAM, Wi-Fi, ISP management, site-to-site VPNs, proxies (forward and reverse), perimeter firewall management, DNS, Azure cloud environments, automation, NAC/user access, hyperconverged infrastructure, and overall network security.
  • Partner with Telecommunication teams to establish or upgrade existing circuits and communication links.
  • Develop and maintain NERC Cyber Infrastructure Protection and disaster recovery plans.
  • Manage VoIP, SIP, DHCP, DNS, TCP/IP routing (including OSPF and BGP), binary mathematics, NAT, PAT, IPsec and SSL VPN technologies, GRE tunneling, route redistribution, traffic shaping, port-level filtering, SD-WAN, MPLS, and other communications technologies.
  • Install, configure, and maintain WAN and LAN connectivity, including core and campus switches, routers, firewalls, wireless access points, WAN scalers, and load balancer technologies.
  • Design, install, configure, and maintain DNP over IP and serial SCADA communications between primary/backup control centers, power plants, solar sites, and substations.
  • Configure and maintain Smart GRID communication hardware switches and routers between primary and backup control centers.

Level-Specific Responsibilities

Network & Systems Security Analyst I (Level 1)

  • Monitor and troubleshoot server, network, and security control issues under direct supervision.
  • Plan, design, and implement network, server, and storage infrastructure (20%).
  • Perform basic troubleshooting using the OSI model, equipment repairs, and problem escalation (20%).
  • Detect and correct work stoppages or errors by monitoring systems and adjusting configurations (20%).
  • Install and support network, server, and storage hardware/software (10%).
  • Participate in planning, designing, maintaining, testing, and documenting disaster recovery plans (10%).
  • Provide security consulting and support for IT infrastructure across multiple platforms (e.g., firewalls, proxies, WAFs, ACLs, NAC, load balancers, DDoS protection) (10%).
  • Provide third-level technical support for security systems and authentication mechanisms (10%).

Network & Systems Security Analyst II (Level 2)

  • In addition to Level 1 duties, monitor, troubleshoot, diagnose, and resolve server, network, DDoS protection, and security control issues (30%).
  • Install and configure server and network hardware/software to meet security standards (40%).
  • Design and plan small projects (20%).
  • Serve as a project lead, mentor Level 1 analysts, or cross-train peers (10%).

Network & Systems Security Analyst III (Level 3)

  • In addition to Level 2 duties, monitor, troubleshoot, diagnose, and resolve server, network, DDoS protection, and security control issues (20%).
  • Install and configure server and network hardware/software to meet security standards (20%).
  • Lead design and planning for small projects (40%).
  • Serve as a project lead, mentor analysts, or cross-train peers (20%).

Requirements

  • High School Diploma or GED (required). Bachelor’s degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS) (preferred).

Qualifications

Certifications

  • Level 1: At least one related certification (e.g., MCSA, VCP, CCNA, CEH, GIAC, CISSP).
  • Level 2: At least two related certifications (e.g., MCSA, MCSE, VCP, CCNA, CCNP, CEH, GNFA, CISSP).
  • Level 3: At least three related certifications, or two with a commitment to obtain a third within one year of hire (e.g., MCSA, MCSE, VCP, CCNA, CCNP, CEH, GNFA, CISSP, CSSA). Preferred certifications include ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP.

Experience

  • Level 1: Minimum 4 years of hands-on experience in Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, or Cisco Networking. In lieu of experience, 3 years with an Associate’s Degree or 2 years with a Bachelor’s Degree in a relevant field.
  • Level 2: Minimum 6 years of related experience. In lieu of experience, 4 years with an Associate’s Degree or 3 years with a Bachelor’s Degree in a relevant field.
  • Level 3: Minimum 8 years of related experience. In lieu of experience, 6 years with an Associate’s Degree or 4 years with a Bachelor’s Degree in a relevant field.

Knowledge, Skills, and Abilities

  • Working knowledge of network, server, and security controls infrastructure, regardless of complexity.
  • Proficiency in technologies such as switching, routing, DNS/DHCP, Windows Active Directory, VMware, VoIP, Storage Area Networking, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cybersecurity best practices, and networking/hardware installation and maintenance.
  • Experience with packet analysis and denial-of-service protection.
  • Strong critical thinking, analytical, problem-solving, and risk assessment skills.
  • Excellent communication (oral and written) and interpersonal skills, with the ability to present complex technical topics to non-technical audiences.
  • Working knowledge of compliance processes for regulatory or industry requirements (e.g., NERC CIP, SOX, PCI).

Working Conditions

  • Normal office and operational (Power Plant, Solar, Control Center) environment.
  • Occasional extended hours during the week and weekends.
  • Physical demands include lifting 50-pound boxes and ascending/descending ladders to service network access points.

Similar jobs

Firewall Engineer

Apex SystemsMerrifield, VA· 1 wk ago
Information Technologyapply on apexsystems.com

Firewall Engineer

GDHAustin, TX· 1 wk ago
Information Technology$50–$60/hrapply on gdhinc.com

Firewall Engineer

LeidosArlington, VA· 1 mo ago
Information Technology$92k–$167k/yrapply on careers.leidos.com