The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT’s network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.
REQUIRED SKILLS:
• Enterprise Networking
• Enterprise Security
• Azure Networking
• WAF/NGFW
• Cisco ISE, NAC, 802.1X, RADIUS, TACACS
Key Responsibilities:
• Ensures network security architecture aligns with operational security standards prior to and after deployment.
• Lead investigation and containment of network security incidents.
• Review firewall rule requests and ensure compliance with security standards.
• Design and maintain secure hybrid network architecture across on-premises and Azure environments.
• Monitor security events using SIEM technologies and coordinate incident response activities.
• Perform network security assessments and recommend remediation strategies.
• Develop and maintain network security standards, diagrams, and operational documentation.
• Support penetration testing and remediation efforts.
• Participate in on-call support during critical security incidents.
• Responsible for conducting proactive threat hunting and anomaly detection.
• Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).
• Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
• Identifies, prioritizes, and remediates network security vulnerabilities.
• Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
• Must have the ability to work independently on assigned projects.