Job Title: Senior Network Security Engineer
Location: Mechanicsville, VA (Hybrid) Local Candidates Within 60 Miles Preferred
Duration: 12 Months
Interview: Onsite
Job Description
We are seeking an experienced Senior Network Security Engineer to support the Virginia Department of Transportation (VDOT). This hybrid opportunity is ideal for professionals with strong expertise in enterprise networking, cybersecurity, Azure networking, firewall technologies, and security operations.
The selected candidate will secure and support a large hybrid infrastructure consisting of approximately 300 statewide locations, including Palo Alto Firewalls, Azure Networking, ExpressRoute, Azure WAF, F5 BIG-IP, SD-WAN, SIEM platforms, and mission-critical public-facing applications.
Required Skills
- 8+ years of Enterprise Networking
- 5+ years of Enterprise Security
- 3+ years of Azure Networking
- 3+ years of WAF / NGFW experience
- Palo Alto Firewalls
- Splunk or Microsoft Sentinel (SIEM)
- Incident Response
- Threat Hunting
- Log Analysis
- Vulnerability Management
- Nessus / Tenable / Microsoft Defender
- Active Directory
- MFA & Conditional Access
- Cisco ISE, NAC, 802.1X, RADIUS, TACACS+
- Azure ExpressRoute
- Azure WAF
- Cisco VPN
- GlobalProtect
- F5 BIG-IP
- Network Security Architecture
- Firewall Rule Management
- Network Documentation & Topology
Required Knowledge
- Zero Trust Architecture
- NIST Cybersecurity Framework (CSF)
- NIST 800-53
- CIS Benchmarks
- Security Incident Investigation
- Security Monitoring
- Security Assessments
- Penetration Test Remediation
Preferred Qualifications
- Experience supporting environments with 300+ network devices
- Experience working in highly regulated environments
- Strong technical leadership and mentoring experience
- Excellent communication with technical and executive stakeholders
- Azure Security Engineer (AZ-500) Certification or ability to obtain
- Azure Network Engineer (AZ-700) Certification or ability to obtain
Responsibilities
- Design and maintain secure enterprise network architecture
- Administer Palo Alto Firewalls and Azure networking infrastructure
- Review firewall rules and maintain security compliance
- Monitor security events using SIEM platforms
- Lead security investigations and incident response
- Perform proactive threat hunting and vulnerability remediation
- Support Azure WAF, ExpressRoute, VPN, and SD-WAN environments
- Maintain network security documentation and architecture diagrams
- Support penetration testing and remediation efforts
- Collaborate with Infrastructure, Cloud Engineering, and Security teams
Additional Requirements
- Hybrid work arrangement
- Onsite interview
- Local candidates within 60 miles preferred
- Active LinkedIn profile required (must match resume)
- Valid Driver's License required
Interested candidates, please send your updated resume along with your LinkedIn profile to: