Senior Network Security Engineer
Location: Mechanicsville, VA (Hybrid) Note: Local candidates to Ohio are highly preferred. Candidates should be able to work in a hybrid environment and attend onsite meetings as required.
Job Summary
We are seeking an experienced Senior Network Security Engineer to design, implement, and support enterprise network security solutions in a hybrid on-premises and Microsoft Azure environment. The ideal candidate will have extensive experience with enterprise networking, Palo Alto firewalls, Azure networking, SIEM technologies, incident response, and vulnerability management.
This role is responsible for securing mission-critical network infrastructure, supporting cloud connectivity, managing firewall policies, monitoring security events, investigating security incidents, and ensuring compliance with enterprise security standards.
Key Responsibilities
- Design and maintain secure enterprise network architecture across on-premises and Azure environments.
- Configure, administer, and optimize Palo Alto Firewalls, Azure WAF, and F5 BIG-IP solutions.
- Review firewall rule requests and ensure compliance with security policies.
- Monitor security events using SIEM tools such as Splunk or Microsoft Sentinel.
- Lead incident response, security investigations, threat hunting, and anomaly detection activities.
- Perform network security assessments and recommend remediation strategies.
- Conduct vulnerability scanning, remediation tracking, and security risk assessments.
- Support penetration testing and implement security improvements.
- Develop and maintain network topology diagrams, firewall documentation, IP schemes, and operational procedures.
- Collaborate with Infrastructure, Cloud, and Information Security teams.
- Participate in on-call support during critical security incidents.
- Mentor junior engineers and provide technical leadership.
Required Qualifications
- 8+ years of Enterprise Networking experience.
- 5+ years of Enterprise Network Security experience.
- 3+ years of Azure Networking experience.
- 3+ years of Web Application Firewall (WAF) and Next-Generation Firewall (NGFW) experience.
- Hands-on experience with Palo Alto Firewalls and GlobalProtect VPN.
- Experience with Azure Firewall, Azure WAF, ExpressRoute, and Virtual Networks.
- Experience with F5 BIG-IP and enterprise load balancing.
- Experience using SIEM platforms such as Splunk or Microsoft Sentinel.
- Strong knowledge of Incident Response, Threat Hunting, Security Investigations, and Log Analysis.
- Experience with Vulnerability Management tools such as Nessus, Tenable, or Microsoft Defender.
- Experience with Active Directory, MFA, Conditional Access, and Certificates.