Network Security Engineer
Listed on 2026-06-15
-
IT/Tech
Cybersecurity, Systems Engineer, IT Specialist -
Engineering
Cybersecurity, Systems Engineer, IT Specialist
SECTION III.SCOPEOFWORK (SOW)
A. SUMMARY
We need one Network Security Engineer to support a five year contract. The Network Security Engineer will actively participate in planning and coordinating the design, installation, and connectivity of computer and network systems to ensure stable, scalable, redundant, and secure 24x7 network operations.
Some Telework Permitted
. Network Security Engineer may work two days per week remotely and three days per week on site in Annapolis Maryland. See details in Place of Performance section below.
1.
Minimum required qualification:
a. Associate degree in an Information Technology (IT) related field; and
b. Active certifications as follows:
(1) Palo Alto Networks Certified Network Security Engineer (PCNSE) Certification.
(2) Cisco Certified Network Professional (CCNP) Enterprise or (CCNP) Security Certification.
2.
Preferred (not required) qualifications:
a. Ten years of technical experience acquired in the Continental United States in IT networking and network security.
b. Bachelor’s degree in an Information Technology (IT) related field.
c. Active Certifications as follows:
(1) Prisma Certified Cloud Security Engineer (PCCSE) Certification from Palo Alto Networks.
(2) Cisco Certified Inter-network Expert (CCIE) in Enterprise Infrastructure or Security Certification.
C. SCOPE OF WORKResources shall be responsible for the following:
1. Pro-actively identifying organization requirements, and helping to design and engineer implementations that best serve the needs.
2. Performing project-based engineering, design, installation and troubleshooting of data security networks.
3. Providing assessment, design and implementation services of data and secure networking environments.
4. Developing comprehensive graphical and text-based design documentation and effectively managing the implementation process from design to acceptance.
5. Assisting internal groups through capacity planning, maintaining, monitoring and reviewing secure data communications networks.
6. Leading migrations or assisting a team of engineers who will migrate traditional/legacy network security platforms to current/next-generation technologies and expose customers to the full lifecycle of defense in depth solutions.
7. Assisting network engineers in troubleshooting critical problems or threat remediation relating to network security products.
8. Working with the engineering team to successfully implement configuration guidelines, change management, and standard operating procedures for secure network solutions.
9. Leading, scheduling, providing guidance and coordinating the activities with other team members to resolve end user problems in a timely and accurate fashion.
10. Generating weekly status reports including project progress, key milestones, and tasks accomplished.
11. Hosting weekly status meetings/calls with team or on-the-need basis.
D. PREFERRED SKILLS, EXPERIENCE & CAPABILITIES1. Resource must possess the following preferred skills, experience, and capabilities:
a. Five years of experience with:
(1) Palo Alto Networks next generation firewall services.
(2) Intrusion Detection and Prevention with Palo Alto networks.
(3) Content Filtering Palo Alto networks.
(4) Virtual Private Networks using Palo Alto network systems.
(5) Data Loss Prevention.
(6) TLS/SSL Inspection.
b. Four years of experience in complex switching, routing, wireless with Cisco Systems.
c. Three years of experience in Reverse Proxies, Load Balancing with A10 networks.
d. Two years of experience in Network Access Control - Cisco Identity Services Engine (ISE), Free RADIUS, and Access Control Lists (ACLs).
e. General experience with the following:
(1) Implementing multi-factor authentication solutions with Microsoft.
(2) Cloud-based virtual networking and security services.
(3) Authentication standards (802.1x) in wired and wireless applications.
(4) Scalable routing protocols (EIGRP), Open Shortest Path First (OSPF), and Border Gateway Protocol (BGP).
(5) Enterprise Data Center implementing Microsegmentation.
(6) Certificate Management, Public Key Infrastructure (PKI).
(7) Vulnerability management using Nessus, NMAP, Windows, Unix, and Linux…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).