Microsegmentation Engineer
Apex Systems · Merrifield, VA · Yesterday
EngineeringContract
Role Overview
We are seeking an experienced Network Security Microsegmentation Engineer to advance our enterprise Zero Trust security strategy. This role will focus on designing, implementing, and supporting microsegmentation controls using Illumio to reduce lateral movement risk and enforce least-privilege access across enterprise workloads. This is a hands-on engineering role for an individual who understands the technical depth of network security and the operational discipline required to implement segmentation safely in production environments.
Responsibilities
- Design, implement, and maintain microsegmentation policies using Illumio.
- Analyze application communication flows and define dependencies.
- Enforce least-privilege access aligned to Zero Trust principles.
- Deploy segmentation policies across hybrid and on-prem environments.
- Collaborate with application and infrastructure teams.
- Troubleshoot blocked or unexpected traffic.
- Support change management and policy lifecycle operations.
- Document segmentation design and procedures.
Required Qualifications
- 5+ years of experience in network security or cybersecurity engineering.
- Hands-on experience with Illumio.
- Strong understanding of Zero Trust principles.
- Solid networking fundamentals (TCP/IP, DNS, routing, firewalls).
- Experience with firewall policy design and traffic analysis.
- Strong understanding of network security technologies including firewalls, routing, ACLs, traffic analysis, and policy enforcement across on-premises and cloud environments.
- Experience analyzing network traffic and security logs to troubleshoot application connectivity and segmentation-related issues.
- Strong troubleshooting skills.
- Experience with Windows and Linux.
Preferred Qualifications
- Experience implementing microsegmentation policies at enterprise scale.
- Cloud security experience in Azure, AWS, and/or GCP environments.
- Hands-on experience with Palo Alto Networks and/or Check Point firewall administration, policy management, and traffic analysis.
- Experience using Splunk or similar SIEM and log analytics platforms (e.g., Microsoft Sentinel, QRadar, Elastic, LogRhythm) for security monitoring, troubleshooting, and traffic investigation.
- Familiarity with security tools including SIEM, EDR, vulnerability management, and network visibility platforms.
- Scripting or automation experience using PowerShell, Python, or similar languages.
- Relevant security certifications such as CISSP, CCNP Security, PCNSE, CCSM, Security+, or equivalent.
Benefits
- Supplemental benefits including medical, dental, vision, life, disability, and other insurance plans.
- Employee Stock Purchase Program (ESPP).
- 401K program with company match after 12 months of tenure.
- Health Savings Account (HSA) on the HDHP plan.
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions.
- Corporate discount savings program and other discounts.
- On-demand training program and access to certification prep.
- Library of technical and leadership courses/books/seminars (available after 6+ months of tenure).
- Certification discounts and perks through associations including CompTIA and IIBA.
- Dedicated customer service team for Consultants to address benefits and resource questions.
- Access to a certified Career Coach.
- Welcome Packet with full details on benefits, programs, support teams, and resources.