Senior Network Security Engineer
Location: Richmond, VA Metro Area
Work Arrangement: Hybrid
Onsite: 1–2 days per week after initial training and knowledge transfer
Candidate Preference: Local candidates preferred; candidates must be willing to relocate to the Richmond, VA metro area
Employment Type: Contract
Client: Virginia Department of Transportation (VDOT)
Job Overview
The Virginia Department of Transportation (VDOT) is seeking an experienced Senior Network Security Engineer (Sr NSE) to implement, secure, and support the agency''s enterprise network, cloud, and computing infrastructure.
The Senior Network Security Engineer will work within a large hybrid enterprise environment supporting approximately 300 statewide locations. The role requires strong hands-on experience with Palo Alto firewalls, Azure networking, ExpressRoute, WAF technologies, Splunk SIEM, SD-WAN, network security architecture, threat hunting, and incident response.
The Sr NSE will work closely with Infrastructure, Cloud Engineering, and Information Security teams to maintain the confidentiality, integrity, and availability of VDOT''s network infrastructure and mission-critical public-facing applications.
Key Responsibilities
Design, implement, secure, and maintain enterprise network security infrastructure.
Ensure network security architecture aligns with established security standards before and after deployment.
Design and maintain secure hybrid network architecture across on-premises and Microsoft Azure environments.
Administer and support Palo Alto firewalls, firewall policies, and security configurations.
Review firewall rule requests and validate compliance with security standards.
Lead investigation, containment, and remediation of network security incidents.
Monitor security events using Splunk SIEM and other security monitoring technologies.
Coordinate incident response activities with Infrastructure, Cloud Engineering, and Information Security teams.
Conduct network security assessments and recommend appropriate remediation strategies.
Perform proactive threat hunting and anomaly detection across enterprise network environments.
Identify, prioritize, and remediate network security vulnerabilities.
Support penetration testing activities and coordinate remediation of identified vulnerabilities.
Design, implement, review, and manage Web Application Firewall (WAF) technologies.
Validate WAF and firewall placement, connectivity, exposure, and integration with public-facing applications.
Support Azure networking and ExpressRoute connectivity between on-premises and cloud environments.
Support and secure SD-WAN infrastructure across statewide locations.
Analyze system logs, SIEM events, network traffic, diagnostic tools, and monitoring data to identify threats and system problems.
Develop and maintain network security standards, architecture documentation, and operational procedures.
Create and maintain network topology diagrams, IP addressing schemes, firewall rules, access controls, and security documentation.
Research emerging network security technologies, vulnerabilities, and threats.
Participate in on-call support during critical security incidents.
Independently manage assigned security engineering projects and technical initiatives.
Collaborate with cross-functional teams to implement secure infrastructure solutions.
Required Skills & Experience
7+ years of experience in Network Security Engineering or Cybersecurity Engineering.
Strong hands-on experience with enterprise network security architecture.
Extensive experience with Palo Alto Networks firewalls.
Strong knowledge of firewall policies, NAT, VPN, access control, and security rules.
Hands-on experience with Microsoft Azure networking.
Experience with Azure ExpressRoute and hybrid cloud connectivity.
Experience implementing and managing WAF technologies.
Experience with Splunk SIEM or similar SIEM platforms.
Strong understanding of security monitoring, incident response, and threat detection.
Experience with SD-WAN technologies.
Strong knowledge of TCP/IP, DNS, DHCP, routing, switching, VPN, and network protocols.
Experience conducting network security assessments and vulnerability remediation.
Experience with penetration testing support and remediation.
Strong understanding of network security threats and attack techniques.
Experience with threat hunting and anomaly detection.
Ability to analyze firewall, network, endpoint, and SIEM logs.
Strong documentation and network diagramming skills.
Ability to work independently and manage complex technical projects.
Preferred Qualifications
Palo Alto Networks certifications such as PCNSE.
Microsoft Azure networking/security certifications.
CCNP Security, CCIE Security, or equivalent networking certification.
CISSP, Security+, CySA+, GSEC, or other cybersecurity certifications.
Experience supporting large government or enterprise network environments.
Experience supporting geographically distributed enterprise networks.
Experience with public-facing, mission-critical applications.
Experience with cloud security architecture and hybrid connectivity.
Technical Environment
Network Security: Palo Alto Firewalls, WAF, VPN, Network Access Controls
Cloud: Microsoft Azure, Azure Networking, ExpressRoute
SIEM: Splunk
WAN: SD-WAN
Networking: TCP/IP, DNS, DHCP, Routing, Switching, VPN
Security: Threat Hunting, Incident Response, Vulnerability Management, Penetration Testing
Documentation: Network Architecture, Topology Diagrams, IP Schemes, Firewall Rules, Access Controls
Ideal Candidate
The ideal candidate will be a hands-on Senior Network Security Engineer with strong enterprise experience in:
Palo Alto Firewall
Azure Networking
ExpressRoute
WAF
Splunk SIEM
SD-WAN
Network Security Architecture
Incident Response
Threat Hunting
Vulnerability Remediation
Network Security Assessments
Candidates should be comfortable working independently, troubleshooting complex network security issues, documenting enterprise architecture, and collaborating with cloud, infrastructure, and information security teams.
Palo Alto + Azure Networking + ExpressRoute + WAF + Splunk SIEM experience is highly preferred.