Network Security Engineer
Staffing Spot, Inc. · McLean, VA · 2 wk ago
HybridContract
About the role
We are seeking an experienced Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure.
Responsibilities
- Design, implement, and maintain enterprise network security infrastructure.
- Configure and manage next-generation firewalls, security appliances, and network security platforms.
- Develop and maintain firewall policies, NAT rules, access-control policies, and security configurations.
- Configure and troubleshoot VPNs, including site-to-site and remote-access VPNs.
- Implement and manage IDS/IPS, web application firewalls, and network security controls.
- Monitor network traffic, security events, and alerts for potential threats.
- Investigate and respond to network security incidents.
- Perform vulnerability assessments and recommend remediation strategies.
- Conduct firewall rule reviews and security configuration audits.
- Implement network segmentation, secure access controls, and zero-trust security principles.
- Collaborate with SOC, infrastructure, cloud, application, and security teams.
- Troubleshoot network connectivity and security-related issues.
- Support security architecture and network design initiatives.
- Implement security controls across on-premises and cloud environments.
- Maintain network security documentation, diagrams, procedures, and operational runbooks.
- Participate in incident response, change management, and disaster recovery activities.
- Ensure compliance with organizational security standards and regulatory requirements.
Requirements
- 8+ years of experience in Network Security Engineering or a related field.
- Strong knowledge of TCP/IP, DNS, DHCP, routing, switching, VLANs, and network protocols.
- Hands-on experience with enterprise firewalls such as Palo Alto, Fortinet, Cisco ASA/Firepower, or Check Point.
- Strong experience with firewall policy management and troubleshooting.
- Experience with IPSec and SSL VPNs.
- Experience with IDS/IPS and network security monitoring.
- Knowledge of network security technologies including NAT, ACLs, proxies, load balancers, and network segmentation.
- Experience with security monitoring and SIEM platforms.
- Understanding of common network attacks, vulnerabilities, and mitigation techniques.
- Experience with vulnerability management and security assessments.
- Strong troubleshooting and analytical skills.
Cloud & Automation
- Experience securing AWS, Azure, or GCP network environments.
- Knowledge of cloud networking, security groups, NSGs, VPC/VNet, and private connectivity.
- Experience with infrastructure automation and scripting using Python, PowerShell, or Bash.
- Familiarity with Infrastructure as Code tools such as Terraform is a plus.
- Experience with Zero Trust and cloud security architecture is preferred.
Preferred Qualifications
- Relevant certifications such as CISSP, CCNP Security, PCNSE, Fortinet NSE, or Check Point certifications.
- Experience with Splunk, QRadar, Microsoft Sentinel, or other SIEM platforms.
- Knowledge of NAC solutions and identity-based network access.
- Experience with SASE/SSE technologies.
- Familiarity with threat intelligence and security operations.
- Experience working in large enterprise environments.
- Strong communication and documentation skills.