Network Security Engineer
SMART TECH SKILLS LLC Sinking Spring, Pennsylvania, United States
IT Services and IT Consulting · 11-50 employees
About the role
The Network Security Engineer designs, deploys, and optimizes enterprise network security infrastructure including firewalls, VPNs, and SD-WAN solutions. They also lead incident response efforts and ensure compliance with financial regulatory frameworks like PCI-DSS and SOX.
What they look for
Requirements
Candidates must have 5 or more years of experience in network security engineering with specific expertise in Palo Alto and Cisco security products. A strong understanding of core networking protocols and experience with ITIL-based change management frameworks is required.
Benefits
Full description
Benefits:
- Competitive salary
6-Month Contract-to-Hire (CTH)
Experience Level Senior Level (5 or more years of experience)
Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution.
Key Responsibilities
Firewall Engineering & Perimeter Defense
- Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire.
- Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades.
- Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies.
Network Access Control & Secure Connectivity
- Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access.
- Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations.
- Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport.
- Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies.
Architecture, Compliance, & Change Management
- Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks.
- Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews.
- Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs).
Required Qualifications
- 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise).
- 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama.
- Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades.
- Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling.
- Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels).
- Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation).
- Experience working within an ITIL-based change management framework.
- Must be legally authorized to work in the United States without current or future visa sponsorship.
Preferred Qualifications
- Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security.
- Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF).
- Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute).
- Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management.
Core Skills & Attributes
- Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues.
- High accountability and attention to detail when executing production changes and maintaining documentation.
- Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors.
- Self-driven approach to continuous learning and staying current with evolving cybersecurity threats.
Flexible work from home options available.