Sr Network Security Engineer

Oxenham Group LLC

  • Reston, VA
  • 30+ days ago
  • $190,000–$220,000 Per Year

Highlights

In this seat you'll stand up and run a sophisticated firewall estate PA-1400, PA-3400, and PA-5500 PQC-capable hardware administered through a Panorama M-700 carrying 1,000 device licenses, alongside VM Series instances powered by VM Flex Credits. Working shoulder to shoulder with the networking and security groups, you'll migrate, tune, and sustain a next-generation firewall footprint supporting a mission-critical DoD environment.

Numbers & Facts

LocationReston, VA
Salary$190,000–$220,000 Per Year

Description

Sr Network Security Engineer
On-Site | Reston, VA
Our client, a mission-focused defense program, is adding a capable firewall engineer to an on-site team based in Reston, VA. In this seat you'll stand up and run a sophisticated firewall estate PA-1400, PA-3400, and PA-5500 PQC-capable hardware administered through a Panorama M-700 carrying 1,000 device licenses, alongside VM Series instances powered by VM Flex Credits. Working shoulder to shoulder with the networking and security groups, you'll migrate, tune, and sustain a next-generation firewall footprint supporting a mission-critical DoD environment. If deep hands-on Palo Alto Networks expertise and enterprise-scale security are where you do your best work, we'd like to hear from you.
About the Opportunity
You'll own the deployment and ongoing care of a demanding, multi-appliance firewall environment inside a classified defense setting migrating off legacy platforms, optimizing policy, and keeping a next-generation footprint healthy and audit-ready.
Day-to-Day Scope
  • Stand up, tune, and sustain the security operating stack within a demanding defense setting
  • Lead the transition of firewall rulesets and objects off legacy platforms and onto current-generation appliances
  • Roll out and administer the PA-3400, PA-5500, PA-1400, and PA-7000 hardware lines through a centralized Panorama M-700 console
  • Oversee virtualized firewall instances built on VM Series, drawing against VM Flex Credits for capacity
  • Build staging environments, confirm migration integrity, and schedule the move into production
  • Advise on software version upgrades and help drive the creation of fresh threat and application signatures
  • Open and push support tickets through the vendor's TAC channel toward resolution
  • Map each stakeholder's infrastructure, needs, and forward-looking security plans, then match solutions accordingly
  • Keep clear lines of communication open with clients, account teams, engineering, and fellow support staff
  • Partner with the networking and security groups to build trust among the units affected by planned changes
  • Occasional travel possible, subject to site needs
Experience We're Looking For
  • Roughly seven to nine years spanning networking and security technologies
  • At least five years across routing and switching fundamentals plus BGP, VXLAN, and SD-WAN
  • Three-plus years directing security initiatives inside sizable, intricate infrastructures
  • Deep practical command of the vendor's product family, covering the VM Series alongside the PA-3400 Series, PA-5500 Series, and PA-7000 Series
  • Advanced familiarity operating Panorama together with log collectors
  • Working command of GlobalProtect and NGFW
  • Hands-on depth setting up, tuning, and running enterprise-grade firewall hardware
  • Seasoned across LAN, WAN, and broader internetworking disciplines
  • Firm grasp of application-layer behavior and internet protocols
  • Polished writing and speaking skills, at ease briefing both technical colleagues and senior leadership
  • Capacity to juggle concurrent workstreams while staying composed under deadline pressure
  • Undergraduate degree in MIS, Computer Science, Business, or a comparable blend of schooling and field experience
Nice-to-Haves
  • Prior work on classified networks with exposure to defense security frameworks
  • Track record standing up sizable firewall migrations across government or enterprise programs
  • Direct time on PQC-capable units such as the PA-1400 and PA-5500
Eligibility & Credentials
  • Full-time, fully on-site presence is mandatory
  • Candidates must live within commuting range of Reston, VA or be open to relocating
  • An active TS-SCI with CI Polygraph must already be in place at the time of application
  • Security+ is the baseline credential; SecurityX or CASP+ is accepted in its place
  • CNSE certification nice to have
  • CISSP, CCNA, or JNCIE-SEC are viewed favorably as additional credentials
  • Sharp written and spoken communication paired with a careful eye for detail
  • Comfortable operating both independently and as part of a team on mission-driven work
  • Availability to travel when the assignment calls for it

Similar Jobs