This job is with Encode, Inc a fully owned subsidiary of Lancesoft
Enter Job Description...
The Senior Network & Perimeter Security Engineer will own senior-level support, configuration,
security, and lifecycle management for Mesa Water's LAN, WAN, switching, routing, firewall,
wireless, remote-access, and IT/OT boundary infrastructure.
The District has disclosed a technology environment that includes Cisco switching and routing,
Palo Alto firewalls, Panorama, GlobalProtect, Meraki wireless access points, and redundant WAN
circuits using BGP.
Because these technologies are specifically known, generic “enterprise network” experience
should not be treated as sufficient when candidates with direct Cisco/Palo Alto experience are
available.
Responsibilities
The individual will be responsible for Palo Alto firewall administration, including Panorama,
GlobalProtect, security policies, NAT, logging, security profiles, firmware, VPN, troubleshooting,
lifecycle management, and hardening.
Cisco responsibilities will include switching, routing, VLANs, Layer 2/Layer 3 troubleshooting,
BGP, STP, QoS, ACLs, port security, firmware, and lifecycle planning. The engineer will also
manage and troubleshoot the District's WAN redundancy and dual-circuit BGP environment,
including ISP/carrier escalation.
Wireless responsibilities will include Meraki AP administration, firmware, coverage optimization,
performance troubleshooting, capacity planning, and replacement recommendations.
A particularly important part of the role is support for the IT/OT boundary. The engineer should
understand network segmentation and the operational implications of making changes near a
SCADA environment. Responsibilities should include maintaining the secure separation of IT and
OT networks, monitoring traffic crossing the boundary, securing the boundary firewall and
associated IT-side infrastructure, and coordinating with the District's SCADA provider as required.
The MSP is not responsible for operating the SCADA system itself. The scope is focused on the
IT-managed systems and network/security controls surrounding that environment.
Required Qualifications and Experience
Candidates should have 8–12+ years of enterprise network engineering experience, with
significant hands-on experience in Cisco switching/routing, BGP, Palo Alto, Panorama,
GlobalProtect, enterprise wireless, WAN redundancy, network change control, and lifecycle
management.
Meraki experience is strongly preferred.
Experience supporting utilities, industrial facilities, critical infrastructure, municipal government,
or another environment containing IT/OT segmentation should receive significant preference.
Preferred Certifications
The most attractive certification combination for this RFP would be:
• CCNP Enterprise
• PCNSE
Additional OT/ICS cybersecurity training or certification would strengthen the resume.
Exhibit D specifically expects knowledge of EPA Water Sector Cybersecurity guidance, CISA ICS-CERT advisories/recommended practices, and common water-sector OT/SCADA architectures.