Senior Network Engineer - Firewall Engineering
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Network Security, Systems Engineer, Network Engineer
Select how often (in days) to receive an alert:
Senior Network Engineer - Firewall EngineeringOak Ridge National Laboratory (ORNL) is currently seeking qualified applicants to serve as a Senior Network Engineer supporting unclassified operations. The successful candidate will possess advanced knowledge of network engineering, firewall architecture, network security policy, enterprise network design, and the interactions among complex information systems.
This position will emphasize the engineering, architecture, implementation, and lifecycle management of enterprise firewall services. The candidate will collaborate with teams across the laboratory, including Enterprise Networking, Information Technology, the Classification Office, Cybersecurity, Laboratory Enterprise Risk, Internal Audit, and other organizations as appropriate.
The Senior Network Engineer will assist Enterprise Networking in developing secure, reliable, and scalable solutions that support the laboratory’s long-term growth. The engineer will evaluate complex technical and security requirements and develop enterprise-class network and firewall solutions that improve service availability, operational efficiency, and ORNL’s overall cybersecurity posture.
The position requires the ability to apply industry standards and government security requirements within ORNL’s environment. The engineer will serve as a technical leader and subject-matter expert for firewall architecture.
Major Duties/Responsibilities:
- Work with multiple divisions within ORNL’s Information Technology Directorate to design, implement, maintain, and improve complex information systems that comply with U.S. Department of Energy (DOE), other applicable government, and local cybersecurity policies.
- Evaluate how existing information systems integrate with one another and determine how new technologies can be securely incorporated into the enterprise environment.
- Develop solutions that balance cybersecurity, availability, performance, maintainability, and mission requirements.
- Design and maintain enterprise firewall architectures supporting campus, data center, internet-edge, remote-access, and segmented network environments.
- Serve as a subject-matter expert for firewalls, firewall management, VPN clients, and associated security services.
- Translate business, mission, technical, and cybersecurity requirements into secure firewall designs and implementation plans.
- Lead firewall deployments, migrations, upgrades, hardware refreshes, policy conversions, and platform-standardization initiatives.
- Troubleshoot complex connectivity, routing, application, performance, high-availability, and security-policy issues across multiple network and system layers.
- Monitor firewall capacity, system health, software lifecycle status, security advisories, and emerging threats; recommend upgrades or architectural changes when appropriate.
- Participate in scheduled maintenance activities and provide escalation or on-call support for critical network-security services as required.
- Deliver ORNL’s mission by aligning behaviors, priorities, and interactions with our core values of Impact, Integrity, Teamwork, Safety, and Service. Promote equal opportunity by fostering a respectful workplace – in how we treat one another, work together, and measure success.
Basic Qualifications:
- BS degree in computer science, information technology, cybersecurity, engineering, or a related discipline, with 8 years of professional experience. An equivalent combination of education and experience may be considered.
- Significant experience designing, implementing, and supporting enterprise network and firewall environments.
- Advanced hands‑on experience with Next-Gen firewalls and centralized management.
- Strong knowledge of TCP/IP, IPv4 and IPv6, subnetting, routing, switching, network segmentation, access control, NAT, VPN technologies, and high‑availability design.
- Knowledge of network‑security architecture, defense‑in‑depth, least privilege, zero trust, and secure network‑design principles.
- Experience working within structured change‑control, configuration‑management, and incident‑management processes.
Preferred Qualifications:
- Abili…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).