VDOT Senior Network Security Engineer
About the role
Varmoda LLC is seeking an experienced Senior Network Security Engineer to support a public sector client's enterprise network, cloud, and computing infrastructure. This role is responsible for securing and maintaining a large-scale hybrid environment that includes on-premises and Azure-based network services, firewalls, WAF technologies, SIEM platforms, and mission-critical public-facing applications.
Responsibilities
- Design, implement, and maintain secure network security architectures across on-premises and Microsoft Azure environments.
- Review and manage firewall policies, rule requests, and access controls to ensure alignment with security standards.
- Monitor and investigate security events using SIEM technologies and lead containment efforts for security incidents.
- Conduct proactive threat hunting, anomaly detection, and network security assessments.
- Manage and support Palo Alto firewalls, WAF platforms, VPN solutions, and related network security technologies.
- Identify, prioritize, and remediate network security vulnerabilities using approved assessment and scanning tools.
- Develop and maintain network diagrams, architecture documentation, IP addressing schemes, security standards, and operational procedures.
- Participate in outage response, penetration test remediation activities, and on-call support for critical security incidents.
Requirements
- Minimum 8 years of enterprise networking experience.
- Minimum 5 years of enterprise security experience.
- Minimum 3 years of Azure networking experience.
- Minimum 3 years of Web Application Firewall (WAF) and/or Next-Generation Firewall (NGFW) experience.
- Hands-on experience with Palo Alto firewalls.
- Hands-on experience with Azure Networking, including hybrid connectivity technologies.
- Experience with SIEM platforms, such as Splunk and/or Microsoft Sentinel.
- Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
- Experience with vulnerability management and remediation, including vulnerability scanning tools such as Nessus, Tenable, or Microsoft Defender.
- Experience with Active Directory, MFA, Conditional Access, and certificate management.
- Experience with Network Access Control (NAC), 802.1X, RADIUS, and TACACS+.
Skills
- Palo Alto
- F5 Distributed Cloud
- Azure WAF
- Cisco VPN
- GlobalProtect
- F5 BIG-IP
Qualifications
Candidate must possess or be able to obtain: Microsoft Azure Security Engineer (AZ-500) and Microsoft Azure Network Engineer (AZ-700). Experience with security frameworks and standards, including: CIS Benchmarks, NIST Cybersecurity Framework (NIST CSF), NIST 800-53, and Zero Trust principles.
Benefits
Competitive benefits including 401k, health insurance, Paid Time Off, Life Insurance and others.