Lead Firewall Engineer
D2 Consulting · Springfield, VA · Yesterday
On-siteEngineering$140/hrFull-time
Responsibilities
- Serve as the focal point for all firewall tasks, operations, and projects
- Lead, direct, and manage execution of all daily operations, troubleshooting, and maintenance activities of the NSS Boundary work center.
- Design, implement, and manage security solutions using F5, Juniper SRX, and Palo Alto for project-based requirements.
- Ensure systems, devices, and application under your responsibility and span of control meet applicable STIG/SRG and organizational configuration baselines.
- Lead regular compliance evaluations and audits.
- Develop, oversee, maintain, and enforce configuration management processes, Standard Operational Procedures (SOPs), and other documentation as needed/required.
- Monitor platform performance, logs, software version(s), and configuration drift to identify and mitigate performance, compliance, and security issues.
- Develop and maintain network architecture diagrams, inventories, and licensing status for the various capabilities within the scope of the team.
- Provide written reports and oral briefings to contract and government leadership.
- Cook up recommendations on newly submitted customer requests.
- Evaluate and report on new/emerging network/communication technologies to enhance capacity, performance and reliability of the network.
- Conduct performance assessments, mentor, and coach personnel.
- Security Clearance: Active TS/SCI
- 8+ years related technical experience network security technologies, tools, and techniques
- 5+ years' experience with large-scale enterprise/global networks in a high paced diverse environment
- Understanding and experience with the DoD Architecture Framework and other key DoD network architecture and strategic planning instructions
- Demonstrated knowledge in planning, directing, and managing a Firewall / Boundary Security Team in an organization similar in size
- Firewall experience within the DoW or ICD
- Demonstrated knowledge of implementation of Perimeter and Internal Firewalls (both physical and virtual contexts)
- Demonstrated advanced experience in managing baseline configurations across numerous firewalls
- Demonstrated advanced experience in evaluating rules to ensure maximum security while minimizing redundancy and processing overhead
- Demonstrated experience with researching and fielding new and innovative firewall technology
- Experience with F5 platforms/technologies (APM, AFM, SSLO, etc.)
- Experience with Palo Alto platforms/technologies (Threat Prevention, Wildfire, URL Filtering, Global Protect)
- Experience with Juniper SRX platforms/technologies
- Familiar with DoD PKI, Kerberos, LDAP, Active Directory, Authentication (SAML, OAuth)
- Able to describe and troubleshoot TLS/SSL handshake/connection issues
- Network design, engineering, and implementation (Advanced Level)
- Creation of network related Rough Order Magnitude (ROM) equipment lists and costing, Level of Effort (LOE) estimation for labor
- Understanding of DoW, DISA, and IC standards and processes
- Able to work weekends and evening hours as needed
- Must be able to successfully obtain/maintain CSSP Infrastructure Support certification within 120 days