GovCIO is seeking a remote Network Engineer with strong Zscaler, Palo Alto Networks firewall, Cisco routing/switching, and McAfee Web Security Proxy experience to design, implement, and maintain secure network architectures and security solutions, requiring a bachelor’s degree or equivalent with 12+ years of experience, and the ability to attain an AOUSC Public Trust clearance.
This will be fully remote Continental USA.
Responsibilities
- Design, implement, and operate next-generation firewall and web security proxy solutions, ensuring secure, high-availability network operations across data centers and nationwide field locations.
- Design, implement, and maintain Palo Alto Networks next-generation firewall solutions, including security policies, NAT, VPNs, threat prevention, URL filtering, and decryption.
- Engineer and support Cisco routing and switching infrastructure across LAN/WAN environments.
- Design and maintain secure network architectures incorporating firewalls, web proxies, VPNs, and access control technologies.
- Deploy, configure, and support McAfee Web Security Proxy (Web Gateway) to enforce web filtering, malware protection, and acceptable use policies.
- Integrate firewall and proxy solutions with authentication systems (Active Directory, LDAP, RADIUS, TACACS+).
- Monitor security platforms for threats, performance issues, and policy violations.
- Analyze logs and alerts to identify security incidents and implement mitigation strategies.
- Perform configuration reviews, rulebase optimization, and security hardening.
Qualifications
Bachelor’s degree in Computer Science, Information Technology, Engineering, or equivalent experience with 12+ years (or commensurate experience).
Required Skills and Experience
- Strong Zscaler experience.
- 5 years of IT or network security experience.
- 3 years of hands-on experience with firewall and security platforms routers and switches.
- Strong experience with:
- Palo Alto Networks firewalls.
- Cisco routers and switches.
- McAfee Web Security Proxy / Web Gateway.
- In-depth knowledge of:
- TCP/IP, routing, and switching.
- IPsec and SSL VPNs.
- DNS, DHCP, NTP.
- ACLs, NAT, QoS.
- Experience with authentication and access control technologies:
- RADIUS / TACACS+.
- Active Directory / LDAP.
- 1X.
Competencies and traits
- Strategic thinker with practical hands-on implementation experience.
- Strong problem-solving, stakeholder management, and facilitation skills.
- Ability to work across 24/7 operational teams and influence cross-functional processes.
- Detail-oriented with focus on resiliency, security, and automation.
Clearance Required: Must be able to attain and maintain an AOUSC Public Trust.
Preferred Skills and Experience
- Master’s preferred.
- TOGAF, AWS/Azure/GCP Cloud Architect, CCNP/CCIE, CISSP, or equivalent.