S

Network Security Engineer

SMART TECH SKILLS LLC Sinking Spring, Pennsylvania, United States

IT Services and IT Consulting · 11-50 employees

Yesterday
Remote Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Network Security Engineer designs, deploys, and optimizes enterprise network security infrastructure including firewalls, VPNs, and SD-WAN solutions. They also lead incident response efforts and ensure compliance with financial regulatory frameworks like PCI-DSS and SOX.

What they look for

Palo Alto Networks Cisco Firepower Cisco ISE Network Security Firewall Engineering VPN Infrastructure SD-WAN Identity Services Engine Incident Response PCI-DSS ITIL Network Segmentation Zero-trust Python Ansible TCP/IP

Requirements

Candidates must have 5 or more years of experience in network security engineering with specific expertise in Palo Alto and Cisco security products. A strong understanding of core networking protocols and experience with ITIL-based change management frameworks is required.

Benefits

Competitive salary Flexible work from home options

Full description

Benefits:

  • Competitive salary

6-Month Contract-to-Hire (CTH)

Experience Level Senior Level (5 or more years of experience)

Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution.

Key Responsibilities

Firewall Engineering & Perimeter Defense

  • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire.
  • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades.
  • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies.

Network Access Control & Secure Connectivity

  • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access.
  • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations.
  • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport.
  • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies.

Architecture, Compliance, & Change Management

  • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks.
  • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews.
  • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs).

Required Qualifications

  • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise).
  • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama.
  • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades.
  • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling.
  • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels).
  • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation).
  • Experience working within an ITIL-based change management framework.
  • Must be legally authorized to work in the United States without current or future visa sponsorship.

Preferred Qualifications

  • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security.
  • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF).
  • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute).
  • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management.

Core Skills & Attributes

  • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues.
  • High accountability and attention to detail when executing production changes and maintaining documentation.
  • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors.
  • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats.

Flexible work from home options available.