Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Network Security Engineer

Ignite IT

The Senior Network Security Engineer supports our program with the U.S. Census Bureau by designing, implementing, operating, troubleshooting, and improving enterprise network security services across on-premises, hybrid-cloud, and cloud-connected environments. The role focuses on firewall engineering, VPN and remote access services, RSA SecurID or equivalent MFA/token services, content filtering, network access control, edge security services, monitoring and logging integration, vulnerability remediation, security documentation, and policy compliance for TCO-managed systems.

The engineer serves as a senior technical resource for secure network architecture, operations support, incident response coordination, and compliance support. This position works closely with TCO leadership, Network Infrastructure, Identity and Domain Services, cloud teams, SOC/NOC/Operations Center personnel, the Office of Information Security (OIS), Information System Security Officers (ISSOs), System Owners, and application teams.

Scope and Technology Ownership
  • Primary scope: Cisco and Palo Alto firewall platforms; firewall policy lifecycle; NAT; segmentation; remote access and site-to-site VPN; RSA SecurID or equivalent MFA/two-factor authentication server and token services; Cloudflare or equivalent DNS/DDoS/WAF/Zero Trust edge security services; content filtering; network access control; monitoring, logging, and SIEM integration; vulnerability remediation; POA&M support; and audit evidence for TCO-managed systems.
  • Coordination scope: SOC/NOC/Operations Center support, cloud and hybrid connectivity, IAM/DDI integrations, wireless/LAN dependencies, security architecture, change management, application access troubleshooting, and cross-team incident response.
  • Role boundary: This is not a primary F5 BIG-IP/LTM/GTM/ASM/Advanced WAF or load-balancer administration role. The engineer will coordinate with the dedicated F5/application delivery team when firewall, VPN, DNS, WAF, certificate, routing, or application-traffic issues require cross-team support.
  • RSA/MFA boundary: This role includes operational support for RSA SecurID or equivalent two-factor authentication services used by VPN and remote access, including server operations, software updates, token support, and troubleshooting. Broader enterprise IAM, directory services, and PKI functions remain coordinated with the Identity Management and Domain Services (IMDS) team.
Key Responsibilities
Firewall Engineering and Operations
  • Design, configure, administer, maintain, and troubleshoot enterprise firewall solutions, including Cisco and Palo Alto platforms, firewall policy rule bases, NAT, segmentation, threat prevention, logging, high availability, and secure configuration baselines.
  • Install, configure, maintain, and upgrade firewall hardware and software into new and existing network infrastructure, including cloud-connected environments.
  • Administer firewall policies and services in accordance with Census IT security policy, secure configuration standards, and change control processes.
  • Perform recurring firewall rule base reviews, rule recertification, policy cleanup, decommissioning of obsolete rules, and optimization to reduce risk and complexity.
  • Identify, diagnose, and resolve firewall issues involving connectivity, rule behavior, utilization, performance, routing, VPNs, DNS, TLS/certificates, application flows, and log/packet analysis.
VPN, Remote Access, and Secure Connectivity
  • Install, configure, maintain, monitor, and troubleshoot VPN services, including remote access VPN, site-to-site VPN, client/clientless access, partner connectivity, mobile device access, and cloud connectivity.
  • Support RSA SecurID or equivalent MFA/two-factor authentication and directory service integrations for VPN and remote access services where applicable.
  • Maintain, operate, administer, patch, upgrade, and troubleshoot RSA SecurID or equivalent MFA/two-factor authentication infrastructure supporting VPN and remote access, including authentication servers/appliances, middleware/agents, certificates, high availability, backups, logs, monitoring, and directory service integration.
  • Support RSA/MFA token lifecycle operations, including hardware and software token provisioning, assignment, activation, replacement, resynchronization, deactivation, inventory tracking, end-user/tiered support, and emergency access processes.
  • Monitor and report on VPN availability, utilization, and performance, and resolve connectivity issues affecting users, business partners, cloud networks, and mission systems.
Edge Security, Content Filtering, and Network Access Control
  • Administer or support Cloudflare and related edge security capabilities, including DNS, DDoS protection, WAF policies, CDN, Access/Gateway, Zero Trust/ZTNA, tunneling, access controls, and logging.
  • Design, implement, maintain, and troubleshoot content filtering services, including web security gateways, email security gateways, URL filtering, Data Loss Prevention (DLP) integrations, Advanced Persistent Threat (APT) integrations, malware defense integrations, and related cloud services.
  • Support network access control services, including NAC policy administration, endpoint posture or 802.1X controls, identity-aware access policies, and integrations with firewalls, wireless, LAN, and identity management systems.
  • Perform policy reviews for content filtering and NAC services as threats, requirements, and enterprise standards change.
Cloud, Hybrid Architecture, and Zero Trust
  • Implement and manage network security controls across AWS, Azure, and hybrid environments, including VPCs/VNets, security groups, NACLs/NSGs, route tables, cloud firewalls, Transit Gateway, ExpressRoute, Direct Connect, VPN, DNS, monitoring, and logging.
  • Provide technical guidance on Zero Trust principles, network segmentation, microsegmentation, least-privilege access, secure data transmission, threat detection, and compliance monitoring across on-premises and cloud environments.
  • Evaluate proposed network and cloud changes for security impact, operational risk, compliance impact, and maintainability.
Monitoring, Logging, Incident Support, and Operations
  • Ensure core network security capabilities are integrated into enterprise monitoring, alerting, logging, and SIEM platforms for availability, diagnostics, traceability, operational insight, and incident response.
  • Review logs, alerts, vulnerability notices, vendor advisories, and threat information; recommend and implement improvements to reduce risk and improve network security posture.
  • Support Operations Center, SOC/NOC, and incident response teams during maintenance, outages, investigations, security events, and incident resolution.
  • Provide Tier II-IV troubleshooting support for complex network security incidents and service-impacting issues.
  • Participate in after-hours upgrades, approved maintenance windows, emergency troubleshooting, and on-call availability as needed.
Compliance, Documentation, Change Management, and Continuous Improvement
  • Support IT Security, ISSO, System Owner, and OIS activities by addressing findings and POA&Ms, supporting control implementation and validation, evaluating vulnerability scan results, and preparing evidence/artifacts for review.
  • Create and maintain comprehensive documentation for firewall, VPN, RSA/MFA token services, content filtering, NAC, and edge security services, including topology diagrams, equipment inventories, token lifecycle procedures, configurations, SOPs, runbooks, code/IaC repositories, implementation plans, rollback plans, and build/upgrade procedures.
  • Follow and document configuration management, change management, and release management policies, methods, and procedures.
  • Use automation and Infrastructure as Code (IaC) where practical for repeatable provisioning, configuration, deployment, documentation, monitoring, and operational efficiencies.
  • Provide status input, technical briefings, metrics, root-cause analysis, knowledge transfer, and mentoring to government staff and other contractor personnel.
Key Work Products and Deliverables
  • Firewall, VPN, RSA/MFA token services, content filtering, NAC, Cloudflare/edge security, and cloud security configurations implemented through approved change processes.
  • RSA/MFA server operations documentation, patch/upgrade records, token inventory/lifecycle procedures, troubleshooting notes, and user-support coordination artifacts.
  • Firewall rule reviews, recertification results, policy cleanup recommendations, and decommissioning plans.
  • Technical diagrams, SOPs, runbooks, configuration documentation, build/upgrade procedures, implementation plans, rollback plans, and knowledge articles.
  • Monitoring and logging integration updates, alert tuning recommendations, operational metrics, and incident support artifacts.
  • Vulnerability remediation documentation, POA&M support, control evidence, audit artifacts, and risk/impact analysis for TCO-managed systems.
  • Status updates, ticket updates, JIRA/task updates, and input to weekly, bi-weekly, or monthly reporting as required.

Requirements

  • 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role.
  • 5+ years of hands-on experience designing, implementing, administering, and troubleshooting enterprise firewall platforms in production environments.
  • Hands-on experience with Cisco firewall technologies such as Cisco FTD/FMC, ASA, AnyConnect/Secure Client, or equivalent Cisco security platforms.
  • Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, App-ID/User-ID, security profiles, and policy optimization.
  • Experience with firewall policy design, NAT, segmentation, remote access VPN, site-to-site VPN, IDS/IPS integrations, high availability, logging, and operational troubleshooting.
  • Working knowledge of Cloudflare or equivalent DNS, DDoS, WAF, CDN, Zero Trust, or edge security platforms.
  • Experience with VPN services, secure remote access, RSA SecurID or equivalent MFA/two-factor authentication services, hardware and software token support, directory integration, partner tunnels, cloud tunnels, and cloud connectivity troubleshooting.
  • Experience supporting MFA server operations, including software updates, patching, certificate/configuration changes, backups, log review, monitoring, vulnerability remediation, and vendor/support escalation.
  • Working knowledge of TCP/IP, DNS, DHCP, IPAM, BGP, routing, subnetting, TLS/certificates, VPN protocols, packet capture, NetFlow/traffic analysis, and common network diagnostic tools.
  • Experience supporting network security in AWS and/or Azure environments.
  • Experience integrating network security controls with enterprise monitoring, logging, SIEM, SOC/NOC, or incident response workflows.
  • Experience working within formal change management, configuration management, release management, incident management, and vulnerability remediation processes.
  • Ability to develop clear technical documentation, diagrams, SOPs, runbooks, implementation plans, rollback plans, status updates, and audit evidence.
  • Strong communication and collaboration skills, including the ability to explain technical risk, operational impact, and recommended actions to technical and non-technical stakeholders.
  • Ability to obtain and maintain a Public Trust / Background Investigation and complete required DOC/Census security processing, security/privacy training, and non-disclosure requirements.
Preferred Qualifications
  • Deep experience administering Cloudflare DNS, DDoS protection, WAF, CDN, Access, Gateway, Tunnel, Magic Transit, or Zero Trust services.
  • Experience with content filtering platforms, secure web gateways, email security gateways, URL filtering, DLP integrations, APT/malware defense integrations, and related cloud security services.
  • Deep experience with RSA SecurID/RSA Authentication Manager or equivalent MFA platforms, including token administration, agent/middleware upgrades, high availability, disaster recovery, reporting, and integration with VPN and directory services.
  • Experience with Network Access Control technologies such as Cisco ISE, 802.1X, endpoint posture, wireless/LAN access controls, and identity-aware access policies.
  • Experience with AWS security and networking services such as VPC, Transit Gateway, Security Groups, NACLs, Route 53, Network Firewall, Direct Connect, VPN, GuardDuty, Security Hub, IAM, and CloudWatch.
  • Experience with Azure security and networking services such as VNets, NSGs, Azure Firewall, Application Gateway/WAF, VPN Gateway, ExpressRoute, Private Link, Defender for Cloud, Entra ID, and Azure Monitor.
  • Experience supporting federal cybersecurity and compliance requirements such as NIST, FISMA, FedRAMP, ATO support, POA&M remediation, continuous monitoring, audit evidence packages, and security control validation.
  • Experience with automation and IaC tools such as Terraform, Ansible, Python, PowerShell, Git, APIs, CI/CD pipelines, or vendor automation frameworks.
  • Experience with Zero Trust architecture, SASE/SSE, ZTNA, secure segmentation, policy-as-code, microsegmentation, or identity-aware network access.
  • Familiarity with F5/load-balancing/application-delivery concepts for cross-team coordination; hands-on F5 administration is not required for this role.
  • Experience leading technical projects, coordinating across matrixed teams, mentoring junior engineers, and supporting Agile/Scrum or JIRA-based task tracking.
Desired Certifications

Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications.

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible schedule
  • Flexible spending account
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Tuition reimbursement
  • Vision insurance
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Network Security Engineer in Suitland, MD vacancy
  •  ...strengthen our work. Veterans, transitioning service members, and military spouses are strongly encouraged to apply. Senior Network Security Engineer Tria Federal is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy... 
    Senior

    Tria Federal

    Suitland, MD
    3 days ago
  • 4256 Senior Network Security Engineer 4256 | US Citizen Job Description: OVERVIEW: We are seeking a highly skilled and experienced Sr. Network Security Engineer to support a federal law enforcement customer in Washington, D.C. The ideal candidate will... 
    Senior

    Procession Systems

    Washington DC
    10 hours ago
  •  ...As a Sr. Network Security Engineer III, you'll provide hands-on expertise securing mission-critical networks for a high-visibility customer with the goal of making an impact across the federal government. Our team is responsible for designing, operating, and hardening... 
    Senior
    Immediate start

    Mount Indie

    Washington DC
    1 day ago
  •  ...service IT Infrastructure Solutions Company focused on building, securing and supporting our clients' mission critical enterprises....  ...supporting federal customers. We're seeking an experienced Senior Network Engineer who enjoys hands-on technical work, takes ownership of... 
    Senior
    Permanent employment
    Full time

    VAE

    Washington DC
    2 days ago
  • $166k - $220k

     ...Senior Network Security Engineer Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative... 
    Senior
    Full time
    Work experience placement
    Immediate start

    anduril

    Washington DC
    3 days ago
  • $146k - $234k

     ...Senior Network Security Engineer (SDN / Multi-Enclave) Job Locations US-MD-College Park Requisition ID 2026-166726 Position Category Cyber Security Clearance Top Secret/SCI w/Poly Responsibilities Peraton Labs is... 
    Senior
    Full time
    Contract work
    Shift work

    Peraton

    College Park, MD
    2 days ago
  •  ...Senior Network Security Engineer II As a Senior Network Security Engineer II you will lead the design, implementation, and maintenance of our organization's network security infrastructure. The ideal candidate will have a strong background in network security, a passion... 
    Senior
    Remote work
    Flexible hours

    Aledade, Inc.

    Washington DC
    7 days ago
  •  ...Senior Network Security Engineering Consultant RedSeal, a pioneer in proactive exposure management and winner of the SC Award for Best CTEM Solution, helps organizations see, understand, and secure their hybrid digital environments across IT (on-prem, cloud, and remote... 
    Senior
    Remote work

    RedSeal

    Washington DC
    4 days ago
  •  ...DC is looking for an experienced cybersecurity engineer. The role involves implementing and operating advanced security solutions for governmental and commercial clients...  ...administration experience, strong knowledge of network engineering, and active TS/SCI clearance. The... 
    Senior

    ENS Solutions, LLC

    Washington DC
    3 days ago
  • A technology services provider is seeking a Senior Network Security Engineer to lead the secure design and implementation of network architectures. The role requires extensive experience in network security engineering, with a focus on Software Defined Networking (SDN)... 
    Senior
    Full time

    Peraton

    College Park, MD
    1 day ago
  • A leading security consultancy is seeking an experienced Information Systems Security Expert (ISSE) in Suitland, Maryland. The role involves performing technical security assessments, designing security architectures, and ensuring compliance with Information Assurance... 
    Senior

    Full Scope

    Suitland, MD
    2 days ago
  •  ...metropolitan area, specializes in providing network and network security solutions in complex environments to...  ..., is composed of an elite team of engineers and business consultants, each of...  ...Description Ashburn is seeking a Senior Security Tools Engineer to support a... 
    Senior
    Work at office

    Ashburn Consulting

    District Heights, MD
    3 days ago
  •  ...the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining...  ...Security. Demonstrated track record of engagement with senior-level DS personnel and contract leadership.... 
    Senior
    Contract work
    Work at office

    Dexis Online

    Washington DC
    2 days ago
  • Valid8 Financial, Inc. is seeking a Cybersecurity Engineer specializing in network packet broker to provide delivery leadership in security engineering. The candidate will design and collaborate on initiatives to enhance network stability and reliability across various... 
    Senior

    Valid8 Financial, Inc.

    Washington DC
    3 days ago
  •  ...We are in search of a highly motivated candidate to join our talented Team. Job Title: Senior Identity, Credential, and Access Management (ICAM) Security Engineer Location: Washington, DC Responsibilities: Support the deployment and management of... 
    Senior
    Work at office

    Ampcus

    Washington DC
    3 days ago
  •  ...Senior Security Engineer Location: Washington, DC | (Hybrid - 3 days in office with travel as required) Clearance: Must be eligible to obtain a DoD security clearance The Role We are seeking a Senior Security Engineer to strengthen cloud and software environments... 
    Senior
    Work at office

    Executive Recruiting

    Washington DC
    2 days ago
  •  ...Title: Senior Security Engineer Location : Arlington, VA Duration: 12 months Enterprise Security Architecture and Innovation works to...  ...Information Security Engineer to join our team to work closely with Network and Security Engineering, Cloud Security, and Enterprise... 
    Senior

    Maintec Technologies

    Arlington, VA
    2 days ago
  • $65 - $75 per hour

     ...vulnerability scanning; Work Cyber related security operations ITSM (ServiceNow) assigned...  ...workstation anti-virus software, DAT, and engineer updates. Performs virus scans and...  ...identifying and facilitating remediation of Network related vulnerability, specifically... 
    Senior
    Full time

    Aditi Consulting

    Washington DC
    1 day ago
  •  ...Ensono is seeking a Security Senior Solution Architect to support clients in enhancing their security infrastructure. This remote role requires strong knowledge of security architecture and extensive experience in designing enterprise-level security solutions. The ideal... 
    Senior
    Remote work

    Ensono

    Washington DC
    3 days ago
  • $120k - $160k

     ...Description SAIC is looking for a Senior Cybersecurity Engineer to support our US Navy customer with...  ...RADIUS authentication, and firewall security engineering. This position will support...  ...framework supporting Navy enterprise networks. Engineer PKI solutions enabling... 
    Senior
    Local area
    Remote work

    SAIC

    Washington DC
    6 days ago
  • $145k - $165k

     ...Everforth ECS is seeking a Senior Security Engineer to work in our Washington, DC office. ECS Federal is a leading information security...  ..., asset security, security engineering, communications and network security, identity and access management, security assessment... 
    Senior
    Long term contract
    Permanent employment
    Full time
    Work at office
    Immediate start

    ECS Limited

    Washington DC
    4 days ago
  •  ...Senior IT Security Engineer Location: Hybrid 3 days on DC Interview Type: In-Person Number of Openings: 3 Short Description: IT Security Engineer *Hybrid position -- only submit local candidates to the DMV region* Complete Description: Strong understanding... 
    Senior
    Work at office
    Local area

    InterSources

    Washington DC
    2 days ago
  • $180k - $240k

     ...Security Lead You'll be the hands-on security lead embedded with core product teams to...  ...protected in production. We are looking for engineers who have expertise in cloud/...  ...security at scale. Hardening & operations: Network segmentation/Zero Trust, Kubernetes posture... 
    Senior
    Work at office
    Immediate start
    Flexible hours

    LangChain

    Washington DC
    1 day ago
  •  ...Senior Security Engineer Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client. The Senior Security Engineer is responsible for designing, implementing, and maintaining advanced security solutions to protect... 
    Senior
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    1 day ago
  •  ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Seattle, Washington; Jacksonville, Florida; Charlotte, North Carolina; Jersey City...  ...). Must have a solid understanding of voice and data networks, major operating systems, active directory, their... 
    Senior
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Washington DC
    4 days ago
  •  ...today! Position Overview: We are seeking an experienced Senior Security Engineer to work in Washington DC to join our team supporting an...  ...weaknesses, and ensure timely remediation to maintain network integrity. Network Monitoring : Monitor the network for... 
    Senior
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    3 days ago
  •  ...Koniag Management Solutions, LLC a Koniag Government Services company , is seeking a Senior Cyber Engineer III with a TS/SCI security clearance to support KMS and our government customer at the Pentagon, Arlington, VA.This position is for a Future New Business Opportunity... 
    Senior
    Local area
    Flexible hours

    Koniag

    Arlington, VA
    1 day ago
  • $150k - $201.6k

     ...Orrick currently has an excellent opportunity for a Senior IT Security Engineer, Threat Response. This position could be based in any of our U....  ...security defenses.Data Analysis: Analyze security alerts, network traffic, endpoint logs, and other data sources to identify... 
    Senior
    Temporary work
    Remote work
    Flexible hours

    Orrick

    Washington DC
    10 hours ago
  • Praescient Analytics is looking for a Senior Penetration Testing Engineer based in Arlington, VA, to support Army programs. This role demands 5+ years of experience in offensive security, proficiency in penetration testing, and the ability to effectively communicate findings... 
    Senior

    Praescient Analytics

    Arlington, VA
    10 hours ago
  •  ...Senior Security Engineer Washington, D.C. Metro - hybrid/remote At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams support the federal government's most critical national security and defense priorities, helping... 
    Senior
    Local area
    Remote work
    Flexible hours
    3 days per week

    Ardent Services

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Network Security Engineer. Be the first to apply!