Senior Network Security Engineer (Firewall/IPS)
Job Description
ITC Federal, Inc. is offering a full-time, onsite role supporting the DOJ NSD National Security Division in Washington, DC. This Senior Network Security Engineer position combines hands-on firewall and IPS work with opportunities to influence network security direction for a mission-focused environment.
Compensation: USD 140,000 - 170,000 per year
Location: Washington, DC (onsite)
Clearance: Active Top Secret (required)
Experience: 10+ years (required)
Education: Bachelor’s Degree (strongly preferred)
Why this role
- Support a government contractor program for DOJ NSD National Security Division.
- Work directly with Cisco firewall and IPS technologies, network security tools, and rule architecture.
- Be involved in research, evaluation, design, testing, and implementation of new network security technologies.
- Benefit package includes comprehensive insurance and time off, plus education reimbursement.
Responsibilities
- Plan, coordinate, and implement the organization’s information security.
- Analyze technical and economic feasibility of requirements and potential solutions.
- Design optimized firewall and IPS rule structures while ensuring standards are maintained.
- Monitor and maintain the health of all firewalls/IPS and recommend improvements.
- Develop and maintain documentation for firewall/IPS procedures.
- Develop and maintain complex network security schematics.
- Research, evaluate, recommend, design, test, and implement new network security technologies.
- Apply expert knowledge of current security tools and practices.
- Provide support to network engineers under general guidance.
Required skills and experience
- 10+ years of IT experience (required)
- Active Top Secret clearance (required)
- Bachelor’s Degree (strongly preferred)
Mandatory hands-on technology experience
- Cisco Identity Services Engine (ISE): upgrade, licensing, maintenance, and deployment
- Cisco Firepower: upgrade, maintenance, and deployment
- Cisco migration from ASA to Firepower Threat Defense (FTD) mode
- Cisco 802.1X: ongoing deployment
- DMVPN design and deployment, compliant with CNSSP-15
- Juniper ADVPN
Routing protocol knowledge (good working understanding)
- OSPF
- EIGRP
- BGP
Certifications (preferred)
- CCNP Security
- CCNP Enterprise (Routing & Switching)
- CCDP
Additional technologies
Cisco Identity Services Engine (ISE), Cisco Firepower, Cisco ASA, Firepower Threat Defense (FTD), Cisco 802.1X, DMVPN, Juniper ADVPN, OSPF, EIGRP, BGP
Benefits
- Health, Dental and Vision
- 401(k)
- Flexible Spending Account (FSA)
- 11 Paid Federal Holidays
- PTO
- education reimbursement
Working environment
- Prolonged periods of sitting at a desk and working on a computer
- Standard office environment; ability to lift 25 pounds