What are the responsibilities and job description for the VDOT Senior Network Security Engineer position at Varmoda Tech LLC?
Position Overview
Varmoda LLC is seeking an experienced Senior Network Security Engineer to support a public sector client''s enterprise network, cloud, and computing infrastructure. This role is responsible for securing and maintaining a large-scale hybrid environment that includes on-premises and Azure-based network services, firewalls, WAF technologies, SIEM platforms, and mission-critical public-facing applications. The Senior Network Security Engineer will work closely with infrastructure, cloud engineering, and information security teams to ensure the confidentiality, integrity, and availability of enterprise systems.
Key Responsibilities
- Design, implement, and maintain secure network security architectures across on-premises and Microsoft Azure environments.
- Review and manage firewall policies, rule requests, and access controls to ensure alignment with security standards.
- Monitor and investigate security events using SIEM technologies and lead containment efforts for security incidents.
- Conduct proactive threat hunting, anomaly detection, and network security assessments.
- Manage and support Palo Alto firewalls, WAF platforms, VPN solutions, and related network security technologies.
- Identify, prioritize, and remediate network security vulnerabilities using approved assessment and scanning tools.
- Develop and maintain network diagrams, architecture documentation, IP addressing schemes, security standards, and operational procedures.
- Participate in outage response, penetration test remediation activities, and on-call support for critical security incidents.
Required Qualifications
- Minimum 8 years of enterprise networking experience.
- Minimum 5 years of enterprise security experience.
- Minimum 3 years of Azure networking experience.
- Minimum 3 years of Web Application Firewall (WAF) and/or Next-Generation Firewall (NGFW) experience.
- Hands-on experience with Palo Alto firewalls.
- Hands-on experience with Azure Networking, including hybrid connectivity technologies.
- Experience with SIEM platforms, such as Splunk and/or Microsoft Sentinel.
- Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
- Experience with vulnerability management and remediation, including vulnerability scanning tools such as Nessus, Tenable, or Microsoft Defender.
- Experience with Active Directory, MFA, Conditional Access, and certificate management.
- Experience with Network Access Control (NAC), 802.1X, RADIUS, and TACACS .
- Experience with the following technologies:
- Palo Alto
- F5 Distributed Cloud
- Azure WAF
- Cisco VPN
- GlobalProtect
- F5 BIG-IP
- Experience working in highly regulated environments.
- Experience leading technical troubleshooting efforts during production outages.
- Ability to communicate technical issues to both technical and executive audiences.
- Ability to mentor junior engineers.
- Candidate must possess or be able to obtain:
- Microsoft Azure Security Engineer (AZ-500)
- Microsoft Azure Network Engineer (AZ-700)
- Experience with security frameworks and standards, including:
- CIS Benchmarks
- NIST Cybersecurity Framework (NIST CSF)
- NIST 800-53
- Zero Trust principles
Preferred Qualifications
- Experience supporting enterprise environments with 300 network devices and/or locations.
- Experience with ExpressRoute connectivity and large-scale hybrid network deployments.
- Experience supporting SD-WAN environments.
- Experience managing infrastructure supporting mission-critical public-facing applications.
- Experience partnering with cloud engineering, infrastructure, and information security teams in complex enterprise environments.
- Strong documentation skills, including network topology diagrams, architecture diagrams, firewall rule documentation, and IP addressing plans.
- Ability to work independently and lead assigned projects with minimal supervision.