Novalink Solutions logo

Senior Network Security Engineer - hybrid Richmond, VA

Novalink Solutions

  • Mechanicsville, Virginia
  • 3 days ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • 802.1unmatched
    • Access Controlunmatched
    • Analysis Skillsunmatched
    • Cisco Network Systemsunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Networksunmatched
    • Computer Securityunmatched
    • Diagnostics Solutions/Softwareunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • F5 BIG-IPunmatched
    • F5 Network Softwareunmatched
    • Firewallsunmatched
    • Huntingunmatched
    • IP (Internet Protocol)unmatched
    • Identify Issuesunmatched
    • Incident Responseunmatched
    • Maintain Complianceunmatched
    • Mentoringunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Nessusunmatched
    • Network Administration/Managementunmatched
    • Network Architecture/Engineeringunmatched
    • Network Performance/Analysisunmatched
    • Network Securityunmatched
    • Network Topologyunmatched
    • On Callunmatched
    • Operations Security (OPSEC)unmatched
    • Penetration Testingunmatched
    • RADIUS (Remote Authentication Dial-In User Service)unmatched
    • Regulatory Complianceunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Software Testingunmatched
    • Splunkunmatched
    • TACACS (Terminal Access Controller Access Control System)unmatched
    • Technical Leadershipunmatched
    • Test Equipmentunmatched
    • Testingunmatched
    • VPN (Virtual Private Network)unmatched
    • Vulnerability Scannersunmatched

    Description

    VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agency’s IT network, cloud, and computing infrastructure. The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.

    The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT’s network and computing related infrastructure.

    The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.

    Key Responsibilities:

    •Ensures network security architecture aligns with operational security standards prior to and after deployment.

    •Lead investigation and containment of network security incidents.

    •Review firewall rule requests and ensure compliance with security standards.

    •Design and maintain secure hybrid network architecture across on-premises and Azure environments.

    •Monitor security events using SIEM technologies and coordinate incident response activities.

    •Perform network security assessments and recommend remediation strategies.

    •Develop and maintain network security standards, diagrams, and operational documentation.

    •Support penetration testing and remediation efforts.

    •Participate in on-call support during critical security incidents.

    •Responsible for conducting proactive threat hunting and anomaly detection. 

    •Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).

    •Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment. 

    •Identifies, prioritizes, and remediates network security vulnerabilities.

    •Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required. 

    •Must have the ability to work independently on assigned projects.  



    Requirements

    Skill
    Required / Desired
    Amount
    of Experience
    Enterprise Networking
    Required
    8
    Years
    Enterprise Security
    Required
    5
    Years
    Azure Networking
    Required
    3
    Years
    WAF/NGFW
    Required
    3
    Years
    Supporting environments with 300+ Network Devices
    Desired
    3
    Years
    Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor
    Required
     
     
    Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel)
    Required
     
     
    Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def
    Required
     
     
    Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates
    Required
     
     
    Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles
    Required
     
     
    Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS
    Required
     
     
    Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
    Required
     
     
    Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
    Required
     
     
    Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
    Required
     
     
    Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),
    Required


    Numbers & Facts

    LocationMechanicsville, Virginia
    IndustryStaffing/Employment Agencies
    Company Size20 to 49 employees
    Year Founded2004
    Websitehttp://www.novalink-solutions.com/

    About Company

    Novalink, founded in 2003 , is a leading consulting and staffing company serving clients in public and private sectors in Information Technology, Telecommunications (IT/Telecom), Technical Networks, Finance, and Administration. With government agencies as our primary clientele, our team has a proven track record of success in providing temporary personnel solutions and managing government deliverables-based projects over the past 20 years.

    Similar Jobs

    See more jobs