Cybersecurity Network Engineer
Job Description
IPSecure, Inc. seeks a Cybersecurity Network Engineer to support design, integration, configuration, testing, and security of advanced lab-based network infrastructure.
Responsibilities
- Design, configure, integrate, secure, and troubleshoot enterprise network infrastructure in a lab and test environment
- Engineer and support Cisco ACI architectures, including Cisco APIC controllers, leaf/spine topologies, tenants, VRFs, Bridge Domains (BDs), Endpoint Groups (EPGs), contracts, and external connectivity
- Support Software-Defined Networking (SDN) technologies and network automation concepts for centrally managed and secured infrastructure
- Configure and troubleshoot Cisco routers and switches, including Layer 2 and Layer 3 networking
- Develop and maintain IP addressing and subnetting schemes, including VLANs, VRFs, routing domains, and segmentation strategies
- Configure and troubleshoot routing protocols such as BGP, OSPF, and static routing
- Engineer and support enterprise firewall and network security solutions, including security policies, access control rules, NAT, VPN connectivity, segmentation, and traffic inspection
- Analyze network traffic and connectivity using packet captures, logs, monitoring platforms, and diagnostic tools
- Perform cybersecurity hardening of network infrastructure per applicable security requirements and organizational standards
- Identify network vulnerabilities, configuration weaknesses, unnecessary services, and segmentation issues; recommend remediation
- Support Zero Trust and defense-in-depth network architectures, including segmentation and least-privilege communications between systems and security zones
- Build and maintain representative network environments for integration, testing, troubleshooting, cybersecurity validation, and engineering development
- Create and maintain network diagrams, interface documentation, IP address plans, configuration documentation, test procedures, and engineering artifacts
- Conduct configuration testing and validation prior to production or mission environment implementation
- Troubleshoot complex connectivity issues across routers, switches, firewalls, virtual networks, servers, and applications
- Coordinate with cybersecurity, systems, virtualization, application, and engineering teams to resolve cross-domain infrastructure issues
- Support change management, configuration management, technical documentation, and engineering review processes
Requirements
- Active TS/SCI security clearance
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline
- Equivalent experience may be substituted
- Security+ and CCNA certification
- 10+ years of experience in network engineering, cybersecurity engineering, network security, or a related technical field
- Hands-on experience configuring and troubleshooting enterprise routers, switches, and firewalls
- Demonstrated experience with Cisco ACI and SDN
- Strong understanding of IP networking, routing, switching, subnetting, VLANs, and network segmentation
- Experience supporting complex lab, integration, test, development, or production network environments
- Experience working with virtualized infrastructure
- Strong troubleshooting and root-cause analysis skills
- Ability to develop and maintain detailed technical and network documentation
- Hands-on Cisco ACI experience, including: APIC administration/configuration, leaf/spine architecture, tenants and VRFs, Bridge Domains (BDs), Endpoint Groups (EPGs), Application Profiles, Contracts and Filters, physical and virtual domains, VLAN pools, External L2/L3 connectivity, L3Out configuration, routing integration, network segmentation and micro-segmentation, troubleshooting and fault analysis, SDN policy-based networking, and network automation/programmable infrastructure
- Experience integrating ACI with virtualized environments, firewalls, external routing infrastructure, and traditional Cisco networks is highly desired
Technologies
- Cisco Application Centric Infrastructure (ACI), Cisco APIC
- Software-Defined Networking (SDN)
- Cisco routers, Cisco switches
- Enterprise firewalls
- IP addressing and subnetting, network segmentation, virtualization technologies
- Packet captures
- BGP, OSPF, static routing
- NAT, VPN connectivity
- Zero Trust, defense-in-depth
- Layer 2 networking, Layer 3 networking
- VLANs, VRFs, BDs (Bridge Domains), EPGs (Endpoint Groups)
- Application Profiles
- ACI Contracts and Filters, L3Out configuration
- SDN policy-based networking, network automation and programmable infrastructure concepts
- Security+, CCNA
- Cisco CCNP Enterprise, Cisco CCNP Data Center, Cisco Certified DevNet Professional
- Cisco ACI-focused training/certification
Benefits
- Medical, Dental, Vision
- Unlimited Vacation
- Sick Leave
- Paid Federal Holidays
- Education and Certification Reimbursement Program
- 401(k) retirement plan with safe harbor employer match after 3 months
- Prepaid Legal Plan and Identity Protection Plan available
- Accident Insurance
- Critical Illness Insurance
- Hospital Indemnity Insurance available
Preferred Qualifications
- Cisco CCNP Enterprise
- Cisco CCNP Data Center
- Cisco Certified DevNet Professional
- Cisco ACI-focused training/certification
Location: San Antonio, TX (onsite)
EEOC Statement: IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.