Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

astyra

Senior Network Security Engineer

Career Insights for Cyber Security Engineer

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Virginia data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.

$113,393 / year median in Virginia

-3% projected decline

Explore Career

Job Description

Senior Network Security Engineer •This is a hybrid position. •Local to the Richmond, VA area only, please
Description:
Our client is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agency's IT network cloud and computing infrastructure. The Sr NSE performs day-to-day activities related to securing the client's infrastructure. The Sr NSE performs day-to-day activities related to securing documenting performing research analysis design and implementation of the client's network and computing related infrastructure. The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure Cloud Engineering and the Information Security Office to maintain the confidentiality integrity and availability of client's network infrastructure.
Responsibilities :
Ensures network security architecture aligns with operational security standards prior to and after deployment. Lead investigation and containment of network security incidents. Review firewall rule requests and ensure compliance with security standards. Design and maintain secure hybrid network architecture across on-premises and Azure environments. Monitor security events using SIEM technologies and coordinate incident response activities. Perform network security assessments and recommend remediation strategies. Develop and maintain network security standards diagrams and operational documentation. Support penetration testing and remediation efforts. Participate in on-call support during critical security incidents. Responsible for conducting proactive threat hunting and anomaly detection. Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation review and management of agency WAFs. Identifies and diagnoses system problems and threats by using system logs line monitors SIEM diagnostic software and test equipment. Identifies prioritizes and remediates network security vulnerabilities. Must have the ability to provide documentation network architecture topology diagrams IP schemes firewall rules and access controls when required. Must have the ability to work independently on assigned projects.
Skills:
Enterprise Networking, Required 8 Years Enterprise Security, Required 5 Years Azure Networking, Required 3 Years WAF/NGFW, Required 3 Years Supporting environments with 300+ Network Devices, Desired 3 Years Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor, Required Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel), Required Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def, Required Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates, R equired Candidate must have experience with;
SEC530, CIS
Benchmarks, NIST
CSF, NIST
800-53, Zero Trust principles, Required Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS, Required Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP, Required Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages, Required Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers., Required Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),, Required Proper email communication will only be done to and from @ astyra.com email addresses. Please ensure you are communicating with approved Astyra recruiters by checking this point when receiving offers and messages from us. Please ensure you are communicating within these guidelines and proper channels for the quickest possible interview consideration! #AC