Network Security Engineer SME

Metric Systems LLC

  • Clarksburg, WV
  • 2 days ago
  • $115,000–$125,000

Highlights

You'll work alongside a collaborative mix of federal and contractor engineers, shaping future‑state security capabilities, solving complex enterprise‑scale challenges, and gaining deeply marketable expertise in Zscaler (ZIA/ZPA), Zero Trust, SASE frameworks, cloud security, and identity‑driven access. My client is seeking a Network Security Engineer to lead a high‑impact Zero Trust transformation for the FBI CJIS division, driving the shift from legacy network security to a modern, cloud‑first architecture powered by Zscaler.

Numbers & Facts

LocationClarksburg, WV
Salary$115,000–$125,000

Description

Network Security Engineer SME

Metric Systems LLC is a direct‑hire employer partner dedicated to helping companies connect with the right talent for their open roles. We are not a staffing agency—instead, we work alongside employers to identify strong candidates, streamline the hiring process, and support both sides through each step. Once hired, you become an employee of the client organization directly, ensuring a seamless transition into your new role and long‑term career alignment.

My client is seeking a Network Security Engineer to lead a high‑impact Zero Trust transformation for the FBI CJIS division, driving the shift from legacy network security to a modern, cloud‑first architecture powered by Zscaler. This role blends hands‑on engineering with architectural influence, contributing directly to TIC 3.0‑aligned modernization efforts within a mature SAFe Agile environment. You'll work alongside a collaborative mix of federal and contractor engineers, shaping future‑state security capabilities, solving complex enterprise‑scale challenges, and gaining deeply marketable expertise in Zscaler (ZIA/ZPA), Zero Trust, SASE frameworks, cloud security, and identity‑driven access. Candidates with Zscaler experience or comparable cloud security/SWG/ZTNA platforms are strongly preferred.

Responsibilities:

  • Participate in SAFe Agile ceremonies (daily stand-ups, sprint planning, retrospectives) and deliver work within sprint cycles
  • Lead the implementation of Zscaler ZIA and ZPA to support Zero Trust and cloud-delivered security objectives
  • Develop and execute migration strategies to transition from legacy forward proxies and VPNs to Zscaler-based architectures
  • Design direct-to-cloud connectivity solutions that eliminate on-premises traffic backhaul
  • Configure and optimize Zscaler policies (URL filtering, SSL inspection, DLP, access controls) to meet security requirements
  • Integrate Zscaler with enterprise identity providers (e.g., Active Directory, Azure AD) to enforce identity-based access
  • Collaborate with cross-functional teams (network, security, cloud) to support Zero Trust and TIC 3.0-aligned architectures
  • Manage and resolve complex network security issues, including traffic flow, access, and policy enforcement troubleshooting
  • Support Operations & Maintenance (O&M) activities such as service ticket resolution, vulnerability remediation, and system sustainment
  • Develop and maintain technical documentation, including architecture diagrams, implementation plans, and operational procedures

Required Qualifications:

  • Hands-on experience with Zscaler (ZIA/ZPA) or comparable cloud security / SWG / ZTNA platforms strongly preferred
  • 10+ years of network security or cybersecurity engineering experience required
  • Education: A degree may substitute for a portion of the required experience
  • Proven experience as a technical lead / SME on enterprise network or security projects
  • Experience supporting large-scale network security migrations (e.g., proxy/VPN to cloud-based or Zero Trust architectures)
  • Experience supporting Zero Trust architecture or modern secure access solutions
  • Experience integrating with identity providers (Active Directory, Azure AD, SAML/OIDC)
  • Strong background in enterprise networking and security, including firewalls (Palo Alto, Cisco, etc.), routing, DNS, and proxy architectures
  • Experience with SIEM/logging platforms (Splunk preferred)
  • Experience troubleshooting complex network and security issues in enterprise environments
  • Day Shift 8am - 5pm
  • US citizenship Required
  • Top Secret clearance required 

Desired Qualifications:

  • Zscaler certifications (e.g., ZDTA, ZDTE, ZCCA-IA, ZCCA-PA)
  • Experience leading or supporting a Zscaler ZIA/ZPA enterprise deployment
  • Familiarity with CISA TIC 3.0 and federal network security modernization initiatives
  • Experience replacing on-prem forward proxies and/or VPNs with cloud-delivered security solutions
  • Knowledge of Zero Trust architecture (ZTA) and SASE frameworks
  • Experience designing or implementing direct-to-cloud access architectures (avoiding traditional network backhaul)
  • Cloud experience with AWS and/or Azure, including networking and security integration
  • Security certifications (e.g., Security+, CASP/X, CISSP)
  • Cisco certifications (e.g., CCNA, CCNP)
  • Experience working in a SAFe Agile environment using Jira and Confluence

Metric Systems LLC is committed to maintaining an environment where every individual has a fair and equal opportunity to succeed. We welcome and consider all qualified applicants regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or any other characteristic protected under federal, state, or local law. We strive to foster an environment built on respect, inclusion, and equal access to opportunities—where diverse perspectives strengthen our team and drive our mission forward

Similar Jobs