What are the responsibilities and job description for the Network Security Engineer position at VAILEXA?
Position: Network Security Engineer
Location: Boise, ID - Onsite
Experience: 6 Years
Duration: 12 Months
Key Responsibilities:
- Firewall operations — Configure, manage, and tune next-generation firewall policies, NAT rules, VPNs, and security profiles across Palo Alto and Cisco platforms.
- Web proxy & secure access — Administer secure web gateway/proxy services (e.g., Zscaler), including URL filtering, SSL inspection, traffic forwarding, and policy enforcement for users and locations.
- DDoS protection — Deploy, monitor, and tune DDoS mitigation controls; respond to volumetric and application-layer attacks and refine protection thresholds.
- Network detection & response — Operate network detection and response (NDR) tooling to baseline traffic, investigate anomalies, and support threat hunting and incident response.
- Incident support — Investigate security events and alerts, perform root-cause analysis, and coordinate remediation with SOC and network teams.
- Documentation & change control — Maintain accurate configuration standards, runbooks, network diagrams, and change records; participate in the change-management process.
- Hardening & lifecycle — Support firmware/software upgrades, rule-based cleanup, and recurring policy and access reviews to reduce risk and technical debt.
- Collaboration — Collaborate with internal stakeholders and vendors to troubleshoot connectivity and security issues and to onboard new sites, services, and controls.
Required Qualifications:
- Approximately 6 years of hands-on experience in network security or network engineering with a security focus.
- Demonstrated hands-on experience administering next-generation firewalls, with practical expertise in Palo Alto and/or Cisco (ASA, Firepower) platforms.
- Working experience with secure web proxy / SWG solutions — Zscaler (ZIA/ZPA) strongly preferred — including SSL inspection and policy configuration.
- Practical knowledge of DDoS mitigation concepts and tooling, and experience responding to attack scenarios.
- Experience with NDR or network traffic analysis platforms for detection, investigation, and threat hunting.
- Solid grasp of TCP/IP, routing and switching, VPNs (IPsec/SSL), DNS, and network segmentation.
- Familiarity with SIEM/log analysis and a structured approach to incident investigation.
- Strong troubleshooting skills and the ability to work independently in a fast-paced, delivery-oriented contract environment.
- Clear written and verbal communication, with disciplined documentation habits.