Network Security Engineer
$130k - $135kValiant Solutions
Position Description
Valiant Solutions is seeking a Network Security Engineer to join our rapidly growing and innovative cybersecurity team!
Valiant Solutions is seeking a Network Security Engineer to deploy and operate the Network Access Control and perimeter security capabilities protecting a federal agency's enterprise network. The engineer owns the Cisco Identity Services Engine deployment end to end, covering 802.1X authentication of Government Furnished Equipment, HSPD-12 credential integration, endpoint posture assessment across Windows and macOS, and TrustSec segmentation, alongside the Cisco Firepower Threat Defense firewall fleet and the remote access VPN.
The current environment runs a seven-node ISE deployment on version 3.4 with separate policy sets per organizational component, and roughly 384 network access devices await integration. This position turns that partial deployment into enforced Zero Trust access control under NIST SP 800-207, measured against a target of 80 percent of active access ports under 802.1X enforcement within the first year.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence.
This position is based in Silver Spring, MD, and allows for partial remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Required Experience
- Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or a related technical field. Four (4) additional years of specialized experience may be substituted for a Bachelor's degree.
- 6 years of dedicated experience in network security engineering and infrastructure protection.
- Hands-on experience taking a Cisco ISE deployment from partial configuration to enforced enterprise-wide 802.1X.
- Experience operating a production firewall fleet in an environment with defined availability standards.
- Cisco Identity Services Engine administration, including distributed PAN, MnT, PSN, and pxGrid node topologies.
- 802.1X, RADIUS, MAB, and certificate-based authentication in mixed Windows and macOS environments.
- Endpoint posture assessment with AnyConnect and Cisco Secure Client.
- Cisco TrustSec design using Security Group Tags and Security Group Access Control Lists.
- Cisco Firepower Threat Defense and Firepower Management Center administration, including intrusion prevention tuning.
- Remote access and site-to-site VPN engineering with posture integration and machine certificate enforcement.
- PKI concepts as they apply to machine and user certificate validation.
- Switching and routing fundamentals sufficient to troubleshoot access-layer authentication failures end to end.
Preferred Certifications
- Cisco Certified Network Professional (CCNP) Security, Certified Information Systems Security Professional (CISSP), or CompTIA Security+.
Responsibilities
Network Access Control and Identity
- Review and validate the existing Cisco ISE configuration, document the gaps, and deliver the remediation design within the first 90 days of performance.
- Configure and enforce 802.1X authentication for Government Furnished Equipment across the enterprise access layer.
- Integrate ISE with Active Directory and LDAP, and enforce HSPD-12 compliant authentication using CAC or Yubikey credentials.
- Build authorization policy that restricts service access to authenticated users and locks accounts after three consecutive failed login attempts.
- Onboard network access devices into ISE in a phased sequence that protects availability while raising enforcement coverage.
Profiling, Posture, and Remediation
- Configure the ISE profiling engine to discover, identify, and monitor every endpoint on the network.
- Deploy and tune AnyConnect and Cisco Secure Client posture agents on both Windows and macOS endpoints.
- Implement posture checks that validate antivirus and antimalware status, host firewall state, and operating system patch level before access is granted.
- Develop remediation policy with the government security team so that non-compliant endpoints are quarantined and returned to service predictably.
- Report posture metrics monthly, including the count of devices denied access for failing compliance checks.
Segmentation and Firewall Operations
- Design TrustSec Security Group Tag segmentation that enforces policy by user role rather than IP address.
- Integrate ISE with Cisco Firepower Management Center to share user and Security Group Tag context for identity-based firewall rules.
- Manage the Cisco Firepower Threat Defense appliance fleet, including rule base tuning, intrusion prevention signature management, and malware defense configuration.
- Migrate remaining FTD appliance configurations to the cloud management plane where applicable.
- Support Tier 2 and Tier 3 firewall rule analysis during incident response and change windows.
Remote Access and Continuous Operations
- Deploy and manage remote access and site-to-site VPN services, including concentrator configuration and capacity management.
- Enforce posture validation before a remote client is authorized onto the network.
- Implement machine certificate validation and equivalent technical controls that restrict client-based VPN access to Government Furnished Equipment only.
- Prepare Methods of Procedure for every security configuration change and carry them through the Change Control Board.
- Participate in the 24x7x365 on-call rotation, responding to Priority 1 incidents within 15 minutes.
Communication and Stakeholder Engagement
- Written and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.
- Ability to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.
- Clear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.
- Ability to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.
Federal Knowledge
- Working knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.
- Familiarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.
- Understanding of HSPD-12 identity credentialing and its enforcement in network access decisions.
- Awareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.
- Experience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.
- Willingness to complete required customer training, including annual cybersecurity awareness, records management, privacy, safety, and harassment prevention training.
About Valiant Solutions
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology's Fast 50, and Washington Business Journal's Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you’ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect - and we trust them to deliver results leveraging their expertise.
Benefits Snapshot (includes, but not limited to)
- Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
- Valiant contributes 25% towards Health Coverage for Family and Dependents
- 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
- 100% Paid Certifications
- 401K Matching up to 4%
- Paid Time Off
- Paid Federal Holidays
- Wellness & Fitness Program
- Valiant University - Online Education and Training Portal
- FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
- Referral Bonuses
The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $130,000-$135,000 range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.
Remote Work Policy
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.
Equal Employment Opportunity
Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.
Physical Demands
Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Authorization to Share Resume and Personal Information
By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should the Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.
#J-18808-Ljbffr- ...The DC Office of the Chief Financial Officer (OCFO) needs a Senior Network Security Engineer to support the design, implementation, operation, and security of the OCFO network and its security infrastructure: configuring and securing network appliances, defending the perimeter...SuggestedWork at officeLocal areaRemote work
- ...Network Security EngineerBDR Solutions, LLC, (BDR) supports the U.S. Federal Government in successfully achieving its mission and goals. Our... ...and deployments. BDR is seeking a Network Security Engineer to join our growing team! This position will be performed as...SuggestedRemote work
$120k - $150k
...Act as Escalation Point of Contact: Serve as the primary Level 3 escalation point for resolving complex network infrastructure, routing, and security configuration issues across both on-premise Data Centers and AWS environments. Maintain Multi-Vendor Security...SuggestedWork at office- ...Senior Network Security Engineer -Long-Term Contract (Government) Position Title: Network Security Engineer(NSE) Worksite Address Washington, DC Interviews In Person Or Webcam Only Short Description NSE **Candidates local to the DMV area only**...SuggestedLong term contractLocal areaRemote work
- ...Sr. Network Security Engineer II The contractor is responsible for the planning, analysis, design, development, testing, quality assurance, configuration, installation, implementation, integration, maintenance, and/or management of networked systems used for the transmission...SuggestedFor contractorsLocal area
$140k - $155k
...This position is located in the Network Engineering and Operations (Networking) Directorate, House Information Resources (HIR), Office of the... ...Strategy and Planning; Information Systems/Network Security; Information Technology Support; Knowledge of Emerging Trends...Contract workWork experience placementWork at officeLocal area$140k - $170k
...government contractor position supports DOJ NSD National Security Division with work focused on firewall and IPS engineering. ITC Federal, Inc. offers a stable benefits... ...reimbursement while you help strengthen network security for critical systems. As a Senior Network...Full timeFor contractorsWork at office- ...ITC Federal, Inc. in Washington, DC is seeking a Senior Network Security Engineer (Firewall/IPS) to plan and execute information security activities and design rule structures that meet standards. This role requires hands-on Cisco firewall/IPS expertise and an active...
$320k - $405k
...whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About The Role Corporate Security protects the environment Anthropic's people work in every day:...Work at officeVisa sponsorshipFlexible hours$90.3k - $189.6k
Job Title: Security EngineerJob Category: Information TechnologyTime Type: Full timeMinimum... ...:CACI is seeking a dedicated Security Engineer to support the Department of Homeland Security... ...access management (Entra ID/Azure AD), network security, encryption services, and...Contract workWork experience placementWork at officeFlexible hours- ...Native owned corporation, our work helps secure an enduring future for our shareholders.... ...™ ASRC NetCentric is seeking a Security Engineer to support a DHS program.Work location:... ...secure solutions across cloud, data centers, networks, applications; interpret security...For contractorsWork at office
$146k - $234k
ResponsibilitiesPeraton is seeking an Information Systems Security Engineer - Vulnerability Remediation Team (VRT) - based to support its Federal Strategic Cyber programs.Location: Washington, DCIn this role, you will: Identify, track and remediate vulnerabilities within...Contract workFor contractorsShift work$130k - $140k
.... Together We Grow – One Mission, One Team – With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time | Exempt Travel Requirement: Up to...Full timeContract workTemporary workFor contractorsLocal areaImmediate startFlexible hours$237.6k - $297k
...We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering - you won't just investigate incidents, you'll build...Full time- ...deliver quality, professional services to supportthe missions and strategic business goals of our clients. PositionTitle: Security Engineer Location: U.S. Department of Agriculture 1400 Independence Ave., SW Washington, DC 20250 Period of Performance:...Local area
- ...Description The security engineering position provides support to a Security Operation Center of a federal agency. Ideal candidate will have... ...knowledge of Windows and UNIX-based system administration, network management and enterprise systems management and the ability...
- ...PCT partners with venture-backed technology companies looking for Security Engineers to help build secure products, infrastructure, and organizations as they scale. Security roles across our portfolio may focus on product security, application security, cloud and infrastructure...
$145k - $200k
...more. The Role Palantir's Offensive Security team probes our own products,... ...attacker would. As an Offensive Security Engineer, you will test internal applications and... ...and internal tooling. Perform external network penetration tests against internet-facing...Work experience placementWork at officeRemote workWork from homeRelocation package$70 per hour
...Overview TSGi is seeking a Security Engineer to support a large-scale federal travel and expense modernization initiative serving civilian government agencies. This role will be responsible for implementing and maintaining security controls across a cloud-based environment...Hourly payContract workLocal areaRemote work$120k - $130k
...including AI-driven insights. We specialize in engineering complex business process automation,... ...enterprise software, and ensuring security and compliance with federal standards. Additionally... ...in nature (i.e. departmental firewall/network changes). Develops or aids in the...Permanent employmentFull timeContract workWork experience placementWork at officeRemote work$162k - $200k
...search of a talented individual to join our IT team in supporting the growth of our business to mature and scale. As an Endpoint Security Systems Administrator within our organization, you will be instrumental in securing our employees and teams. Your responsibilities...Work at officeFlexible hours3 days per week$140k - $190k
...About Method Security Method Security is dedicated to reshaping cybersecurity in an era... .... Role Overview As a Security Engineer at Method Security, you will be instrumental... ...with various security tools, such as networking and penetration testing tools, and integrating...Shift work$108k
...professionals supporting the U.S. Department of State. As a Security Engineer you will help secure enterprise infrastructure and cloud environments... ...across servers, virtual machines, cloud platforms, networked systems, and enterprise services; identify security findings...Contract work- ...Join to apply for the Security Engineer role at HireCapital Join to apply for the Security Engineer role at HireCapital Direct message the... ...tools, SIEMs, and EDR platforms Familiarity with cloud security, network defense, and endpoint protection principles Experience in...Permanent employmentFull timeWork at officeRemote work
$100k - $120k
...Endpoint Security Baseline Engineer CNI seeking an Endpoint Security Baseline Engineer to support the engineering, implementation, and operational... ...of business including Civilian, Defense, Filtration, Network Services, and Research, Development, Test and Evaluation....Full timeTemporary workFor contractorsWork at officeImmediate start- ...This is a 100% Onsite Role. About the Position: The Security Operations Engineer shall be responsible for implementing new firewall architectures... ...such as carrier class Checkpoint Firewalls, Palo Alto and Network Security Policy Management. Top Secret security...For contractors
- ...Job Description Job Description Role Overview We are looking for Security Engineers to support Engineering Security initiatives across security and privacy reviews, threat modeling, and third-party AI Agent security testing. The selected engineers will work...Immediate start
- ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) – Training – Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...Contract workWork at office
$135k - $155k
...Spry Methods Web Developer Security EngineerSpry Methods is a proven provider of mission... ...Position OverviewThe Web Developer Security Engineer protects mission-critical web... ...OptionsTraditional - PPO Open Access Plus Network(2) HDHP - PPO Open Access Plus NetworkHDHP...Full timeContract workWorldwide- ...Job Description- IaC Security Scanning & Hardening: Integrate IaC security scanning tools (e.g., Checkov, TFSec, Snyk IaC, Terraform... .... Requirements: 7+ years of experience in cloud security, network security, or DevSecOps. Hands-on experience with Terraform,...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Network Security Engineer. Be the first to apply!
- rn network Silver Spring, MD
- networking Silver Spring, MD
- staffing network Silver Spring, MD
- data network cabling Silver Spring, MD
- director network services Silver Spring, MD
- computer network Silver Spring, MD
- food network Silver Spring, MD
- learning network Silver Spring, MD
- IT network Silver Spring, MD
- network operations center technician Silver Spring, MD




