Senior Network Security Engineer
Intellibee Inc · Mechanicsville, VA · 3 wk ago
Full-time
VDOT is seeking an experienced Senior Network Security Engineer to implement and support the agency’s IT network, cloud, and computing infrastructure in a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.
Responsibilities
- Ensures network security architecture aligns with operational security standards prior to and after deployment.
- Lead investigation and containment of network security incidents.
- Review firewall rule requests and ensure compliance with security standards.
- Design and maintain secure hybrid network architecture across on-premises and Azure environments.
- Monitor security events using SIEM technologies and coordinate incident response activities.
- Perform network security assessments and recommend remediation strategies.
- Develop and maintain network security standards, diagrams, and operational documentation.
- Support penetration testing and remediation efforts.
- Participate in on-call support during critical security incidents.
- Conduct proactive threat hunting and anomaly detection.
- Validate WAF and firewall placement and integration exposure/connectivity.
- Lead implementation, review, and management of agency WAF(s).
- Identify and diagnose system problems and threats using system logs, line monitors, SIEM, diagnostic software, and test equipment.
- Identify, prioritize, and remediate network security vulnerabilities.
- Provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
- Work independently on assigned projects.
- Communicate technical issues to technical and executive audiences and mentor junior engineers.
Requirements
- 8 years of enterprise networking experience.
- 5 years of enterprise security experience.
- 3 years of Azure networking experience.
- 3 years of WAF/NGFW experience.
- Experience supporting environments with 300+ network devices (desired).
- Experience in incident response, security investigations, log analysis, threat intelligence, and security monitoring.
- Experience with SIEM products (e.g., Splunk, Microsoft Sentinel).
- Experience in vulnerability management, remediation tracking, and vulnerability scanning tools (e.g., Nessus, Tenable).
- Experience with Active Directory, MFA, Conditional Access, and Certificates.
- Experience with SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, and Zero Trust principles.
- Experience with Cisco ISE, NAC, 802.1X, RADIUS, and TACACS.
- Experience with Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, and F5 BIG-IP.
- Experience working in highly regulated environments and leading technical troubleshooting during outages.
- Ability to achieve or has achieved the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700).
Benefits
- Long-term stability with multi-year opportunities and room to grow.
- Comprehensive health coverage.
- 401(k) program for financial security.
- Green Card assistance for immediate processing, if required.