Sr. Firewall Engineer (Cisco ESA) Job



  full-time   employee

District of Columbia
United States

Sr. Firewall Engineer (Cisco ESA) (Job Number:429994)


SAIC has a Sr. Firewall Engineer (CISCO ESA) located in Washignton, DC with local travel to Springfield, VA.

Position Description:

The Senior Firewall Engineer will support a Department of State (DoS) Bureau of Information Resource Management (IRM) program. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. IRM provides enterprise architecture design, engineering, operations and maintenance support services for desktops, servers, networks, firewalls, and enterprise applications across the Department. Program is named "Vanguard" and is an IT consolidation consisting of the Department's servers, mainframes, network devices, network perimeter, anti-virus engineering, public key infrastructure (PKI)/biometrics/encryption, monitoring tools, telephony, mobile computing platform, virtual environment, and enclave design/security engineering.

This is a senior network management position within the Vanguard 2.2.1 Service Management Office (SMO), providing general engineering support to multiple firewall and perimeter security systems and devices. The well-qualified candidate will possess and apply comprehensive knowledge regarding perimeter security devices. The candidate must be capable of planning and leading the testing, implementation, and maintenance of perimeter security technologies and devices. The candidate must be capable of evaluating performance results, performing risk assessments, and recommending changes affecting perimeter security configuration/implementations. This position may be supervisory. The position directly supports DoS on-site to provide perimeter security protection to over 80,000 customers globally.

Description of Duties:

- Builds, designs, tests and deploys perimeter security systems to include firewalls, proxy devices, and mail transport agents.

- Facilitates the Firewall Advisory Board for the review and approval of change request affecting the enterprise perimeter.

- Plans, documents, and implements hardware and software refresh and upgrade of perimeter devices to include Cisco IronPort ESA, Palo Alto, and StoneGate firewalls.

- Conducts troubleshooting and analysis for fault identification and remediation on perimeter devices. Directs Tier 2 resources for system fault remediation.

- Directs compilation of records and reports concerning perimeter operations and maintenance to analyze the performance of perimeter security systems.

- Provides input to the problem management process, including assessing and evaluating software and hardware anomalies. Supports the root cause analysis efforts to determine problems and develop remediation activities. Interfaces with vendor support service groups to ensure proper support during outages or periods of degraded system performance.

- Manages the transition to operations of perimeter security devices.

- Collaborates with Cross-Bureaus and Agencies to implement network changes as it relates to perimeter security.

- Supports the configuration testing of replacement perimeter devices.

- Creates and maintains standard operating procedures and guides for new and/or existing perimeter hardware and software.

- Attends weekly teleconferences, onsite meetings, and participates in working groups, as related to constant changing security environment.



TYPICAL EDUCATION AND EXPERIENCE: Bachelors and five (5) years or more experience; Masters and three (3) years or more experience; PhD and 0 years related experience.

Required Experience/Skills/Attributes:

- 5-8 years IT network engineering support experience (Tier II, Tier III, network infrastructure implementation and maintenance).

- Expert level experience in managing, maintaining, and configuring Cisco IronPort Email Security Appliances (ESA) and related SMA.

- Expert experience in one or more of the following security devices: Palo Alto Firewalls, ForcePoint StoneGate Firewalls, A10 Network Proxy.

- Experience supporting the configuration and maintenance of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Stonegate, Security Appliances, Juniper).

- Firsthand experience in developing and providing quality assurance review of engineering change orders relating to the replacement or enhancement of perimeter security hardware and software.

- Experienced with performing root cause analysis, risk identification and risk mitigation.

- Expert knowledge in configuring Cisco switches.

- Experienced with network monitoring devices such as HP Openview, Nagios, Zenoss, NeuralStar or other similar monitoring tools.

Desired Experience/Skills/Attributes:

- ITIL Foundation certification

- Certifications: StoneGate Firewall/VPN Architect Certification, StoneGate Management Client (SMC) Certification, Microsoft Certified Professional (MCP), Network+, Security+

- Familiarity with DoS environment (data and voice networks, IT security systems, policies and procedures), Foreign Affairs Handbooks (FAHs), Foreign Affairs Manuals (FAMs).

- Interpersonal skills including the ability to collaborate effectively, self-awareness, and excellent written and oral communications.

Clearance Requirement: TOP SECRET clearance.
SAIC Overview:SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC has approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit

EOE AA M/F/Vet/Disability

Job Posting: Aug 16, 2017, 4:00:00 AM
Primary Location: United States-DC-WASHINGTON
Clearance Level Must Currently Possess: Top Secret
Clearance Level Must Be Able to Obtain: None
Potential for Teleworking: No
Travel: Yes, 25% of the time
Shift: Day Job
Schedule: Full-time


Save This Job

Email This Job to a Friend