This position is for the Firewall security engineering team within the Vanguard Perimeter Security Division (PSD), providing firewall engineering over multiple firewall and perimeter security appliances. The well qualified candidate must be capable of developing and evaluation firewall performance results, perform risk assessments, and recommend changes impacting the perimeter security systems. The candidate must be capable of planning and leading engineering activities to include the testing, implementation, and maintenance of perimeter security technologies and devices and must be capable of communicating and coordinating all firewall related work to the Firewall Manager to include the Government customer. The position directly supports DoS on-site to provide perimeter security protection to over 100,000 customers globally.
Build, design, test and deploy perimeter security appliances (Palo Alto, Forcepoint, CISCO ESA/ASA)
Directs compilation of records and reports concerning perimeter operations and maintenance to analyze the performance of perimeter security systems.
Provides input to the problem management process, including assessing and evaluating software and hardware anomalies. Supports the root cause analysis efforts to determine problems and develop remediation activities. Interfaces with vendor support service groups to ensure proper support during outages or periods of degraded system performance.
Manages the proper transition to operations of perimeter security devices.
Collaborate across Bureaus and Agencies to implement network changes as it relates to perimeter security
Supports the configuration testing of replacement perimeter devices
Plans, documents, and implements hardware and software build and refresh
Create and Maintain standard operating procedures and guides for new and/or existing perimeter hardware and software.
Attend weekly teleconferences, onsite meetings, and participates in working groups, as related to constant changing security environment.
Required Education, Experience, & Skills
Bachelors degree and nine (9) years or more experience; Masters degree and seven (7) years of experience; Additional training and experience may be substituted in lieu of a degree.
IT network engineering support experience (Tier II, Tier III, network infrastructure implementation and maintenance.
Strong experience in one or more of the following security devices: Palo Alto firewalls, Panorama management console, Forcepoint/StoneGate, A10 Encrypted Traffic Inspection/Application Delivery, and Cisco ESA & ASA
Experience supporting the configuration and maintenance of Firewall/DMZ infrastructure including Network and Application Firewall Packet Filtering technologies (Palo Alto, McAfee/Forcepoint Stonegate)
Firsthand experience in developing and providing quality assurance review of engineering change orders relating to the replacement or enhancement of perimeter security hardware and software
Experienced with performing root cause analysis, risk identification, and risk mitigation
Knowledgeable with configuring Cisco switches
Experienced with network monitoring devices such as NeuralStar, SPLUNK or other similar monitoring tools
Active Secret Clearance with the ability to obtain Top Secret
Desired Education, Certifications, & Skills
Experience developing and configuring SSL/TLS encryption/decryption solutions for traffic inspection
Experience with Red Hat Linux/CentOS and Ubuntu including administration scripting is a plus