VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agencys IT network cloud and computing infrastructure. The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.
The Sr NSE performs day-to-day activities related to securing documenting performing research analysis design and implementation of VDOTs network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations Palo Alto firewalls Azure networking ExpressRoute connectivity WAF technologies Splunk SIEM SD-WAN and mission-critical public-facing applications. The role partners closely with Infrastructure Cloud Engineering and the Information Security Office to maintain the confidentiality integrity and availability of VDOTs network infrastructure.
Key Responsibilities:
Ensures network security architecture aligns with operational security standards prior to and after deployment.
Lead investigation and containment of network security incidents.
Review firewall rule requests and ensure compliance with security standards.
Design and maintain secure hybrid network architecture across on-premises and Azure environments.
Monitor security events using SIEM technologies and coordinate incident response activities.
Perform network security assessments and recommend remediation strategies.
Develop and maintain network security standards diagrams and operational documentation.
Support penetration testing and remediation efforts.
Participate in on-call support during critical security incidents.
Responsible for conducting proactive threat hunting and anomaly detection.
Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation review and management of agency WAF(s).
Identifies and diagnoses system problems and threats by using system logs line monitors SIEM diagnostic software and test equipment.
Identifies prioritizes and remediates network security vulnerabilities.
Must have the ability to provide documentation network architecture topology diagrams IP schemes firewall rules and access controls when required.
Must have the ability to work independently on assigned projects.
Skill
Required / Desired
Amount
of Experience
Enterprise Networking
Required
8
Years
Enterprise Security
Required
5
Years
Azure Networking
Required
3
Years
WAF/NGFW
Required
3
Years
Supporting environments with 300 Network Devices
Desired
3
Years
Candidate must have experience in the following areas: Incident response Security investigations Log analysis Threat intelligence Security monitor
Required
Candidate must have experience with the SIEM products (e.g. Splunk Microsoft Sentinel)
Required
Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus Tenable Def
Required
Candidate must have experience in the following areas: Active Directory MFA Conditional Access Certificates
Required
Candidate must have experience with; SEC530 CIS Benchmarks NIST CSF NIST 800-53 Zero Trust principles
Required
Candidate must have experience with the following: Cisco ISE NAC 802.1X RADIUS TACACS
Required
Candidate must have experience with the following products: Palo Alto F5 Distributed Cloud Azure WAF Cisco VPN Global Protect F5 BIG-IP
Required
Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
Required
Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
Required
Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500) Azure Network Engineer (AZ-700)
Required
VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agencys IT network cloud and computing infrastructure. The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.The Sr NSE performs day-to-day activities related to securing do...
VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agencys IT network cloud and computing infrastructure. The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.
The Sr NSE performs day-to-day activities related to securing documenting performing research analysis design and implementation of VDOTs network and computing related infrastructure.
The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations Palo Alto firewalls Azure networking ExpressRoute connectivity WAF technologies Splunk SIEM SD-WAN and mission-critical public-facing applications. The role partners closely with Infrastructure Cloud Engineering and the Information Security Office to maintain the confidentiality integrity and availability of VDOTs network infrastructure.
Key Responsibilities:
Ensures network security architecture aligns with operational security standards prior to and after deployment.
Lead investigation and containment of network security incidents.
Review firewall rule requests and ensure compliance with security standards.
Design and maintain secure hybrid network architecture across on-premises and Azure environments.
Monitor security events using SIEM technologies and coordinate incident response activities.
Perform network security assessments and recommend remediation strategies.
Develop and maintain network security standards diagrams and operational documentation.
Support penetration testing and remediation efforts.
Participate in on-call support during critical security incidents.
Responsible for conducting proactive threat hunting and anomaly detection.
Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation review and management of agency WAF(s).
Identifies and diagnoses system problems and threats by using system logs line monitors SIEM diagnostic software and test equipment.
Identifies prioritizes and remediates network security vulnerabilities.
Must have the ability to provide documentation network architecture topology diagrams IP schemes firewall rules and access controls when required.
Must have the ability to work independently on assigned projects.
Skill
Required / Desired
Amount
of Experience
Enterprise Networking
Required
8
Years
Enterprise Security
Required
5
Years
Azure Networking
Required
3
Years
WAF/NGFW
Required
3
Years
Supporting environments with 300 Network Devices
Desired
3
Years
Candidate must have experience in the following areas: Incident response Security investigations Log analysis Threat intelligence Security monitor
Required
Candidate must have experience with the SIEM products (e.g. Splunk Microsoft Sentinel)
Required
Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus Tenable Def
Required
Candidate must have experience in the following areas: Active Directory MFA Conditional Access Certificates
Required
Candidate must have experience with; SEC530 CIS Benchmarks NIST CSF NIST 800-53 Zero Trust principles
Required
Candidate must have experience with the following: Cisco ISE NAC 802.1X RADIUS TACACS
Required
Candidate must have experience with the following products: Palo Alto F5 Distributed Cloud Azure WAF Cisco VPN Global Protect F5 BIG-IP
Required
Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
Required
Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
Required
Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500) Azure Network Engineer (AZ-700)