VPN Network Engineer
Summary
VPN & firewall network engineer supporting the U.S. Navy's NMCI intranet, designing, implementing, and maintaining global network security (Juniper firewalls, DMZs, VPNs, Cisco appliances) with Tier-III NOC support, on-call rotation, and automation via Ansible/Python. On-site in Norfolk or Pearl Harbor; requires an active DoD Secret clearance.
Job Title: VPN Network Engineer
Clearance: Secret Clearance
Location: Norfolk (NRFK) or Pearl Harbor (PRLH)
Job Type: Full-Time (M-F 8-5 on call on weekends as needed)
Target Salary Range*: $145,000 - $165,000
*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
Position Overview:
We are seeking a skilled Firewall & VPN Network Engineer proficient in network engineering appliances and technologies (i.e. Firewalls, DMZ, VPN) to join our Transport Operations team. In this role, you will be responsible for designing, implementing, and maintaining robust & mature global network security solutions.
Your expertise in configuring enterprise-grade Juniper firewalls, managing DMZ environments, engineering secure Firewall/VPN solutions, and administering Cisco network appliances will be crucial. You will collaborate closely with cross-functional engineering and project management teams to safeguard our network infrastructure against threats and vulnerabilities ensuring the highest levels of operational integrity. You will be a member of a technical team, managing customer relationships and overseeing key resources for Incident Response, Change Management, Problem Management, Operations and Maintenance (O&M), and ITSM and DevSecOps initiatives.
Primary Responsibilities:
- Support Current Operations for the United States Navy by providing VPN, DMZ, and Firewall Network Engineering Subject Matter Expertise (SME) for the largest Intranet in the world. A qualified candidate for this position would be responsible for network modification, operation, integration, maintenance, security, and implementation of services for the as-fielded NMCI network.
- Collaborates with the Network Operations Center, Network Administrators, and the Network Engineering Team to define and/or continuously improve:
- Network Security Appliances (i.e. DMZ, VPN, Firewalls)
- Test and Validate Automation and best practice insertion opportunities.
- Leads development of Network SOPs/TTPs
- Continuous Service Improvements (CSI)
- System performance tuning and enhancements
- Create and maintain Engineering Implementation Plans (EIP)
- Plans and executes network upgrades and maintenance activities with the NMCI Operations Manager, NOC Lead, Release Management team and other key stakeholders.
- Tier III escalation support and vendor engagement supporting Incident Management activities.
- Active participation in Root Cause Analysis for Problem Management activities.
Qualifications:
- Requires B.S. Degree and 8-12 years of prior relevant experience. Work experience may be substituted for degree at Hiring Manager’s discretion.
- U.S. Citizen with an active DoD Secret security clearance.
- Must currently possess an active DoD 8570.01 IAT Level III Certification i.e. CCNP Security, CISSP, or CASP+.
- Must currently possess an active Associate level Network Vendor Certification (from one of the following Vendors): Cisco, Juniper, Palo, F5 Networks.
- Ability to work or be called in to work during off-hours to meet customer mission support requirements.
- Participate in on-call rotation for Incident Management responsibilities among the Transport Operations team.
- Network Subject Matter Expert for operations providing Tier-III support to the NOC watch staff.
- Perform highly technical maintenance and configuration to firewalls, VPNs, and DMZ appliances.
- Extensive experience engineering and troubleshooting networks, including routing, switching, MPLS, VPNs, routing protocols (i.e. BGP, OSPF, IS-IS), switching protocols (i.e. Spanning Tree Protocol, VLANs, LLDP, VoIP) Multicast protocols and emerging network technologies.
- Strong understanding and in-depth knowledge of IP network/subnet addressing.
- Extensive knowledge of defense-in-depth principles, Network architecture, Modern Network Topologies, Network appliance integrity, and common networking security elements.
- Ansible, Python, IaC network automation experience.