Apply Now
Location: Mechanicsville, Virginia (VA)
Contract Type: C2C
Posted: 7 hours ago
Closed Date: 08/04/2026
Skills: WAF/NGFW
Visa Type: Any Visa

Senior Network Security Engineer

Location: HYBRID in Mechanicsville, VA 23116 (3 days onsite)

Duration: 12 months

MOI: F2F  

 

Candidate should be local to Richmond

 

  • Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),
  • Enterprise Networking
  • Enterprise Security
  • Azure Networking
  • WAF/NGFW
  • Supporting environments with 300+ Network Devices
  • Candidate must have experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor
  • Candidate must have experience with the SIEM products (e.g. Splunk, Microsoft Sentinel)
  • Candidate must have experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def
  • Candidate must have experience in the following areas: Active Directory, MFA, Conditional Access, Certificates
  • Candidate must have experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles
  • Candidate must have experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS
  • Candidate must have experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP
  • Candidate must have experience working in highly regulated environments and leading technical troubleshooting during outages
  • Candidate must have ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers.
  • Candidate should have achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700),

 

JD:

VDOT is seeking an experienced Sr Network Security Engineer (Sr NSE) to implement and support the agency’s IT network, cloud, and computing infrastructure. The Sr NSE performs day-to-day activities related to securing VDOTs infrastructure.The Sr NSE performs day-to-day activities related to securing, documenting, performing research, analysis, design, and implementation of VDOT’s network and computing related infrastructure.

The Sr NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT’s network infrastructure.


Key Responsibilities:

• Ensures network security architecture aligns with operational security standards prior to and after deployment.

• Lead investigation and containment of network security incidents.

• Review firewall rule requests and ensure compliance with security standards.

• Design and maintain secure hybrid network architecture across on-premises and Azure environments.

• Monitor security events using SIEM technologies and coordinate incident response activities.

• Perform network security assessments and recommend remediation strategies.

• Develop and maintain network security standards, diagrams, and operational documentation.

• Support penetration testing and remediation efforts.

• Participate in on-call support during critical security incidents.

• Responsible for conducting proactive threat hunting and anomaly detection. 

• Validates WAF and firewall placement and integration exposure/connectivity. Also leads implementation, review, and management of agency WAF(s).

• Identifies and diagnoses system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment. 

• Identifies, prioritizes, and remediates network security vulnerabilities.

• Must have the ability to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required. 

• Must have the ability to work independently on assigned projects.