| 807471 |
Senior Network Security Engineer |
Yakshna Solutions, Inc., (YSI) is a CMMI Level 3 assessed, ISO 9001, 20000:1, 27001 certified, woman-owned small business enterprises, headquartered in Herndon, Virginia, USA. YSI provides professional IT solutions and services to business corporations and government organizations. YSI is committed to serve its business communities as a leading IT vendor providing innovative, quality, and cost-effective IT business solutions and services.
We offer a competitive benefits package that includes the following: 401(k), health, dental, and vision insurance, Life insurance, short-term and long-term disability insurance, paid time off, training, and professional development assistance.
VDOT is seeking an experienced Senior Network Security Engineer (Sr. NSE) to implement and support the agency’s IT network, cloud, and computing infrastructure. The Sr. NSE is responsible for daily activities that help secure VDOT’s infrastructure. The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT’s network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.
Key Responsibilities:
- Ensures network security architecture aligns with operational security standards prior to and after deployment.
- Lead investigation and containment of network security incidents.
- Review firewall rule requests and ensure compliance with security standards.
- Design and maintain secure hybrid network architecture across on-premises and Azure environments.
- Monitor security events using SIEM technologies and coordinate incident response activities.
- Perform network security assessments and recommend remediation strategies.
- Develop and maintain network security standards, diagrams, and operational documentation.
- Support penetration testing and remediation efforts.
- Participate in on-call support during critical security incidents.
- Responsible for conducting proactive threat hunting and anomaly detection.
- Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
- Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
- Identifies, prioritizes, and remediates network security vulnerabilities.
- Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
- Must have the ability to work independently on assigned projects.
Required Skills
- 8+ years of experience in enterprise networking, supporting large-scale, complex network infrastructures and environments with 300+ network devices.
- 5+ years of experience in enterprise security, including incident response, security investigations, log analysis, threat intelligence, security monitoring, and SIEM platforms such as Splunk and Microsoft Sentinel.
- 3+ years of experience designing and managing Azure networking and cloud security solutions, including Azure WAF, Conditional Access, MFA, certificates, and Azure security best practices.
- 3+ years of experience implementing and administering Web Application Firewalls (WAF) and Next-Generation Firewalls (NGFW), including Palo Alto, F5 Distributed Cloud, F5 BIG-IP, Cisco VPN, and GlobalProtect.
- Proven experience with vulnerability management, remediation tracking, and vulnerability scanning tools (e.g., Nessus, Tenable, Defender), as well as Cisco ISE, NAC, 802.1X, RADIUS, TACACS, and Zero Trust security architectures aligned with NIST CSF, NIST 800-53, CIS Benchmarks, and SEC530.
- Demonstrated ability to lead technical troubleshooting in highly regulated environments, communicate effectively with both technical and executive stakeholders, mentor junior engineers, and obtain or maintain Azure Security Engineer (AZ-500) and Azure Network Engineer (AZ-700) certifications.
Location: 9120 Lockwood Boulevard Mechanicsville, VA 23116 (Hybrid)
$125,000-130,000 annually with benefits
US Citizen or Green card holder only
YSI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
|