Role: Firepower Security Firewall Engineer
Location: Mostly remote work with periodic on-site support in Austin TX
Job Description
Tier 3 Network Security Engineer, Cisco Secure Firepower (Contractor)
On-Site Support Examples include, but not limited to:
- Layer 1 / physical support activities
- Direct access during major or high-risk network changes
- Critical troubleshooting events requiring hands-on presence
Position Overview
We are seeking a highly skilled, Tier 3, Network Security Engineer with deep expertise in Cisco Secure Firepower Firewalls to support an enterprise-scale Managed Network Services environment for a State Government Agency.
Experience with Cisco Secure Firewall Management Center (FMC), strong VPN troubleshooting skills, and familiarity with large-scale enterprise or government environments are critical for success in this role. Experience with Cisco Catalyst SD-WAN is highly beneficial.
Key Responsibilities
- Serve as a Tier 3 escalation point for complex firewall and network security issues
- Provide advanced troubleshooting and root cause analysis for Cisco Secure Firepower Firewall incidents
- Perform day-to-day firewall operational support using Cisco Secure Firewall Management Center (FMC), including but not limited to:
- Creating and maintaining operational and compliance reports
- Monitoring firewall health and system performance
- Analyzing traffic flows and connection behavior
- Supporting routing protocols within secured environments
- Troubleshoot and support VPN technologies, including site-to-site and remote access VPNs
- Analyze, implement, and optimize firewall access control and security policies
- Participate in formal change management processes, including documentation, peer review, approvals, and scheduled implementations
- Execute approved changes during after-hours change windows, as required
- Participate in a team-based on-call rotation to support after-hours and emergency incidents
- Collaborate with engineering teams and operational stakeholders to meet Managed Network Services obligations
Required Technical Skills & Experience
- Strong hands-on experience with Cisco Secure Firepower Firewalls
- Advanced troubleshooting experience, including but not limited to:
- Snort 3 (IPS and File Policies)
- Traffic flow analysis and packet inspection
- NAT / PAT configuration and troubleshooting
- Security Intelligence policies
- Access control rule analysis
- OSI Layers 1 7, with particular emphasis on Layers 1 4
- Solid operational experience with Cisco Secure Firewall Management Center (FMC)
- Proven experience troubleshooting VPN technologies (Cisco AnyConnect)
- Strong understanding of routing concepts and protocols in secured network environments
Preferred / Beneficial Experience
- Experience with Cisco Catalyst SD-WAN
- Familiarity with ServiceNow or similar ITSM tools for incident and change management
- Experience creating, editing, and maintaining network topology diagrams
- Microsoft Visio experience preferred
Communication & Documentation
- Strong written and verbal communication skills
- Ability to clearly document technical findings, configurations, and change activities
- Ability to communicate effectively within structured, process-driven environments
Work Expectations
- Mostly remote work with periodic on-site support in the Austin, TX area
- Availability for after-hours maintenance and change windows
- Participation in an on-call rotation
- Adherence to formal operational, security, and change control processes
- Professional conduct appropriate for a government-supported enterprise environment
--
Asher Williams
Desk: 2o1.497.1o1o X:1o5 | Direct: 551.272.o129
asher (at) pullskill dot com