Open Talent Network: Senior Network/Security Engineer
About the role
This is a remote position at Ad Hoc, a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people’s needs and transform their experience of government. Our collaborations have shaped defining moments in public-sector service delivery, including products that connect Veterans to tailored services, help millions access affordable health care, and support important programs like Head Start.
Our culture, communications, and tools are built for remote work, enabling us to bring together top talent nationwide. We value acceptance, accountability, and humility, fostering small, inclusive teams to collaborate closely with partners and deliver software that works.
The Federal Civilian business unit supports customers spanning federal, commercial, and nonprofit spaces, including NASA, the General Services Administration, Office of Personnel Management, Library of Congress, Health & Human Services, and the FDIC. We partner with these agencies to build new capabilities, modernize legacy systems, and establish digital service infrastructure to scale mission impact.
Responsibilities
- Experience with Palo Alto, Panorama OS (PAN-OS), Firewalls, SIEM, Security Configuration Management (SCM), migration, security and compliance, RBAC and access models, Data Loss Prevention (DLP), and Strata Cloud Manager.
- Operate and engineer enterprise web proxy, deliver reliable policy changes, and diagnose issues down to packet level.
- Configure Network ACLs, firewalls, and security groups to enforce policy and isolate sensitive workloads.
- Design secure network infrastructure enforcing Zero Trust principles for the DXP.
- Ensure 100% compliance with IRS/NIST boundary protection standards.
- Proxy Engineering: Forward/reverse proxy modes; explicit vs transparent; PAC/WPAD design and distribution.
- SSL/TLS inspection: cert chains, pinning impacts, ALPN, HTTP/2 behavior, auth flows (Kerberos/NTLM, SAML/OIDC).
- Safe bypass strategies (domain/SNI/IP/risk-based) without degrading coverage.
- Layer 3 & Internet Fundamentals: Routing & addressing (CIDR, MTU/fragmentation/PMTUD, NAT44/66, VRFs), basic BGP/OSPF, DNS recursion/forwarding and failure modes.
- Ports & Protocols: TCP/UDP behavior, ephemeral ranges, TLS handshake/SNI, and middlebox interactions.
- Write and review complex PCRE (lookarounds, backreferences, atomic groups) with an eye for performance (avoid catastrophic backtracking).
- Troubleshooting: tcpdump/Wireshark proficiency (TLS/HTTP analysis, TCP dynamics).
- Log correlation at scale (e.g., Splunk/ELK) to isolate issues off-box (client, network, IdP, upstream).
- Distinguish origin responses vs proxy-generated errors and document root cause.
- Clear stakeholder communication; triage correctly under load—doesn’t treat every noisy issue as P1.
Goals:
- Normalize firewall / Panorama versions.
- Get Panorama 12.x integrated with Strata Cloud Manager as the “real” central manager.
- Upgrade the DLP plug-in so it works cleanly in SCM.
Qualifications
- Current or previous Federal Government Clearance (preferred).
Benefits
- Company-subsidized health, dental, and vision insurance.
- Flexible PTO.
- 401K with employer match.
- Paid parental leave after one year of service.
- Employee Assistance Program.
Pay
The starting range for this role is $153,000-187,000. Actual compensation is influenced by skill set, level of experience, and responsibility.