Cybersecurity Infrastructure Engineer
Job Description
The U.S. Securities and Exchange Commission is seeking a cybersecurity-focused engineer to design, operate, and maintain its defensive network infrastructure from a centralized enterprise perspective. This on-site role in Washington, DC centers on building resilient security controls around next-generation firewalls, SASE/ZTNA, and SD-WAN while leading capability initiatives and guiding contractor work to strengthen defenses.
Compensation and Location
Salary range: USD 153,114 to 259,402 per year. Location: Washington, DC (onsite).
Minimum experience: 1 year.
Responsibilities
- Engineer, deploy, and sustain the SEC's enterprise network security stack, including next-generation firewalls, SASE/ZTNA, and SD-WAN, to maintain availability and a defensible posture.
- Operate and maintain defensive platforms daily, covering configuration management, policy tuning, lifecycle and patching, capacity planning, and health monitoring.
- Serve as the senior technical authority for intricate infrastructure issues, providing advanced troubleshooting and directing the work of supporting contractor staff.
- Lead end-to-end engineering projects for new and upgraded capabilities such as SASE/ZTNA and SD-WAN across on-premises and cloud environments.
- Develop and sustain secure configuration baselines, standard operating procedures, and engineering documentation, and automate repetitive tasks to improve consistency and reduce manual effort.
- Translate threat intelligence into infrastructure-level improvements, including firewall policy, segmentation, access control, and traffic inspection to harden the environment against adversary tactics.
- Collaborate with the SOC, logging and observability, network operations teams, and product vendors to integrate capabilities, resolve issues, and align with mission requirements.
- Operate and support intrusion detection sensor infrastructure to ensure reliable security telemetry delivery to the SOC and observability teams.
- Identify gaps in defensive coverage and processes, recommend improvements, and provide technical input to architecture and roadmap decisions.
Requirements
- Citizenship: You must be a US Citizen.
- Selective Service: Males born after 12/31/59 must be registered or exempt from Selective Service.
- Security Clearance: Entrance on duty depends on a pre-employment security investigation; a favorable background may be required.
- PCS: Moving or relocation expenses are not authorized.
- Direct Deposit: Federal salary payments must be made by direct deposit.
- Probationary Period: A one-year probationary period may be required.
- Duty Station: The selectee must report to the listed duty location.
- On-Call: Duties may require carrying a cell phone and being on call 24/7 on a rotational basis.
- Basic Requirements: Attention to detail; Customer service; Oral communication; Problem solving.
- Minimum Qualification: SK-14 requires at least one year of specialized experience equivalent to GS/SK-13.
- Engineering enterprise network security controls, including hardening and configuration management.
- Designing enterprise security capabilities and operations, including automation and escalation resolution.
- Defining secure cloud guardrails and Zero Trust access patterns aligned to federal baselines.
- Evaluating emerging technologies with baseline updates and security impact analysis.
Accomplishment Record Competencies
- Information Systems/Network Security — implements methods, tools, and standards to prevent vulnerabilities and protect privacy and security of applications, systems, and networks.
- Cybersecurity Engineering — creates and manages hardware, software, and privacy and security policies for system protection.
- Cloud Architecture — designs and develops cloud-based infrastructure aligned with best practices and requirements, including data organization and knowledge of industry developments.
- Technology Awareness — applies emerging technologies and their integration into processes to meet organizational requirements.
Technologies
- Next-generation firewalls
- SASE/ZTNA
- SD-WAN
- Intrusion detection sensor infrastructure
- Zero Trust (ZTNA) architecture
How to Apply
To apply, submit an online application and the required documents via USAJOBS by the stated deadline. The package must be complete to be considered. Create or sign into your USAJOBS account, upload your resume and any supporting documents, and submit before the closing date. You can track your application status in USAJOBS after submission.