freehire launches on Product Hunt on 26 August.

Follow →

Network Security Engineer

Summary

Owns and secures enterprise network infrastructure (firewalls, WAN/LAN, cloud) while maintaining CMMC Level 2 and SOC 2 compliance for a defense-focused federal contractor.

Overview

Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose.

We’ve been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges.

Position Summary

Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset

Responsibilities:

Network Infrastructure & Operations

  • Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management.
  • Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity.
  • Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government).
  • Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process.
  • Oversee network configuration management and backups to ensure recoverability and business continuity.
  • Analyze and resolve escalated Tier 2+ network support tickets.
  • Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning

Security & Compliance

  • Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation.
  • Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions.
  • Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening).
  • Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed.
  • Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles.

Collaboration & Support

  • Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments.
  • Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes.
  • Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions.
  • Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles.
  • Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards.

Cloud Infrastructure & GCP Governance

  • Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries.
  • Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments.
  • Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT.

Requirements

  • Must be a U.S. Citizenship
  • Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
  • Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role.
  • Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals.
  • Must have hands-on working experience with Palo Alto NGFW and FortiGate firewalls, along with Cisco or equivalent routing and switching technologies.
  • Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus).
  • Must be familiar with configuration management, monitoring, and documentation tools.
  • Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions.
  • Must be familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy.
  • Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff.

Preferred Qualifications

  • Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent.
  • Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred.
  • Familiarity with VoIP, secure mail flow, and endpoint management integration.
  • Experience contributing to IT/security-related project initiatives.
  • Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping.
  • Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments.
  • Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible.
  • Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts.
  • GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience.
  • Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred.
  • Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks.

Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications.

Please join us, as together we build a better world one mission at a time powered by Technology and its People!

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

What this application asks

workable

First name, Last name, Email, Headline, Please list your full legal first and last name (e.g., John L. Smith II), Please provide your preferred first name, Phone, By providing a phone number and submitting this form you consent to receive SMS text messages from Credence LLC in accordance with our SMS Privacy Policy (https://credence-llc.com/careers/sms-privacy/) Message and data rates may apply. Message frequency may vary. Reply No, to STOP and opt out., Address, Photo, Education, Experience, List any work related certifications or licenses you currently possess, Please comment on how your prior education and experiences qualify you for the type of employment you are seeking., Summary, Resume, Please indicate which active clearances you have, If you have a security clearance not listed, please fill in., Cover letter, Type of work desired, What is your annual salary expectation? (Ranges are welcomed- non-answers may delay your consideration), What date are you available to join Credence as a new hire?, Are you legally authorized to work in the U.S. as a U.S. citizen or Fully Naturalized U.S. Citizen?
, Do you currently or will you in the future, require an immigration sponsorship and/or a host for a work visa authorization (e.g., F1 or H-1B)?  (if hired, verification will be required consistent with federal law.)
, Are you at least 18 years old?  (if no, you may be required to provide authorization to work)
, How did you hear about us? Was it a job board or an employee? Do tell...., Have you ever worked for Credence before?
If yes, what year and in what role?, Credence honors our Service Members and wonder if you are a Veteran or have Veteran status?, Credence honors our Service Members and their spouses, have you ever been a Military Spouse?, Do you have any relatives employed by this organization?, I have disclosed all information that is relevant and should be considered applicable to my candidacy for employment. 

I understand, where permissible under applicable state and local law, I may be subject to a pre-employment drug test after receiving a conditional offer of employment, and must receive a negative result for illegal drug use before being permitted to commence work with Company. I understand, where permissible under applicable state and local law, I may be subject to a pre-employment medical examination after receiving a conditional offer of employment, and must meet the qualifications for the position, with or without reasonable accommodation, before being permitted to commence work with Company. I understand, where permissible under applicable state and local law, I may be subject to a pre-employment background check after receiving a conditional offer of employment to investigate my criminal background and other matters related to my suitability for employment. Initial to agree., I hereby certify that the information given by me is true in all respects. I authorize Company and its representatives to contact my prior employers and all others (with the exception of my current employer, only if I have marked "May we contact your present employer" on this application as "No") for the purpose of verification of the information I have supplied and release same from any liability resulting from the information released. I authorize employers, schools and other persons named on this application to provide any information or transcripts requested. Initials to agree, I understand employment with Company is also contingent on my providing sufficient documentation necessary to establish my identity and eligibility to work in the United States. 

If employed, I understand that as a condition of employment that I may be required to agree to and sign a non-solicitation, non-disclosure, and/or other similar agreements. I also agree to notify the organization during the pre-employment process of any non-solicitation, non-disclosure, and/or other similar agreements that I may have already signed with current and former employers. 

I expressly understand and agree that, if employed, my employment, having no specified term, is based upon mutual consent and may be terminated at-will, with or without cause, by either party (Company or me) without prior notice to the other, unless otherwise prohibited by law. 

I understand that no representation, whether oral or written, by any representative or agent of Company, at any time, can constitute an implied or express contract of employment. I further understand no representative or agent of Company has the authority to enter into an agreement for employment for any specified period of time or to make any change in any policy, procedure, benefit or other terms or condition of employment other than in a document signed by an authorized representative. 

I understand that the technical processing and transmission of the application, including my personal information, may involve (a) transmissions over various networks, including the transfer of this information to the United States and/or other countries for storage, processing and use by Company, its affiliates, and their agents; and (b) changes to conform and adapt to technical requirements of connecting networks and devices. Accordingly, I agree to permit such parties to make such transmissions and changes, and hereby provide the necessary consent for the same. Initial to agree., Do you currently meet the worksite location requirements for being On-site or Hybrid as defined in the job description?, If “No”, are you willing to relocate to meet this requirement? Please note that candidates who are unable to work onsite or relocate will not meet the position requirements.

  • Are you legally authorized to work in the United States? yes / no
  • Are you a U.S. Citizen and do you meet the citizenship requirement for this role? yes / no
  • What are your annual salary expectations in USD?
  • Do you have an Associates or Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience) from an acreditated college? yes / no
  • How many years of hands-on experience do you have in network engineering, IT administration, or a related technical role?
  • Do you 5 years or more of hands-on working experience in network engineering, IT administration, or a related technical role? yes / no
  • Do you have hands-on working experience with Palo Alto NGFW and FortiGate firewalls, along with Cisco or equivalent routing and switching technologies? yes / no
  • How many years of hands-on experience do you have maintaining network security documentation such as firewall rule baselines, network diagrams, and SSP-related control documentation?
  • Can you describe your hands-on experience with Palo Alto NGFW and FortiGate firewalls, including the kinds of environments you've supported? written answer
  • Are you proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus)? yes / no
  • Do you have 5 years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions? yes / no
  • Do you experience working to support GCP organization-level governance including IAM, org policies, and folder hierarchy? yes / no
  • Do you hold any of the follow certifications: Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent? yes / no
  • Do you have experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High? yes / no
  • Do you have any prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping? yes / no
  • Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. yes / no
  • Do you have experience working as a federal contractor familiar with government compliance frameworks (CMMC, FedRAMP)? yes / no
  • What is your comfort level with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks? choose any

See also