远程工作雷达

高级网络安全部门工程师

Senior Network Security Engineer

开发工程职能支持限定地区(需当地身份)
公司ManTech
薪资$117,000 - $195,100/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

与MANTECH一起揭开智能的奥秘!加入一支处于国家安全前沿的活力团队,为政府情报机构提供先进的解决方案。自1968年以来,我们一直通过突破性的技术解决最严峻的挑战。探索数字转型、网络安全、IT、数据分析和软件开发领域的激动人心的项目。提升你的职业生涯,创造价值。你的冒险现在开始——在MANTECH释放你的潜力!

MANTECH正在寻找一位积极进取、以职业和客户为导向的高级网络安全工程师,加入我们的团队,工作地点可在西弗吉尼亚州Fairmont、科罗拉多州Boulder或远程(美国境内)。
高级网络安全工程师将作为技术核心,推动网络现代化工作,消除运营孤岛,并领导从依赖机房的旧架构向安全、云集成的可信互联网连接(TIC)3.0框架的过渡。候选人必须具备强大的主动解决问题的思维,并能够在高节奏、以可用性为先的环境中工作。
职责包括但不限于:

  • 边界架构与TIC 3.0过渡:设计、配置和维护我们分布式的网络边界。构建和工程安全的站点到站点IPsec VPN隧道及相关组件,将我们的边界从TIC 2.0机房中心现代化为云集成的TIC 3.0安全覆盖层。
  • 多厂商防火墙与交换工程:执行企业防火墙和交换平面的专家级管理、配置和故障排除。这包括配置和管理可能包括Palo Alto Networks下一代防火墙、Fortinet FortiGate设备,以及Juniper和Brocade交换机的产品。
  • GitOps与自动化集成:使用基础设施即代码(IaC)技术维护和执行网络配置基线。与我们的工具开发团队合作,编写和执行Ansible剧本和GitLab CI/CD流水线,以自动化VLAN分配、端口配置和动态DNS蜜罐阻断。
  • 网络可观测性与流量分析:利用数据包代理捕获和路由数据包流。操作工具和技术监控内部网络流量并检测异常横向移动。集成带外网络探测工具,持续跟踪边界性能。
  • 技术文档与配置管理:制定和维护技术文档,确保配置变更的可追溯性和一致性。
查看英文原文

Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies. Since 1968, we’ve been solving the toughest challenges with groundbreaking tech. Explore thrilling projects in Digital Transformation, Cybersecurity, IT, Data Analytics and Software Development. Elevate your career and make a difference. Your adventure begins now—unleash your potential with MANTECH!

MANTECHseeks a motivated, career and customer-oriented Senior Network Security Engineer to join our team in either Fairmont, WV, Boulder CO, or REMOTE (US-Based).
The Senior Network Security Engineer will serve as a technical anchor, driving network modernization efforts, eliminating operational silos, and leading the transition from legacy, colocation-dependent architectures to a secure, cloud-integrated Trusted Internet Connection (TIC) 3.0 framework. The candidate must possess a strong, proactive problem-solving mindset and be comfortable working in a high-tempo, availability-first environment.
Responsibilities include but are not limited to:

  • Perimeter Architecture & TIC 3.0 Transition: Design, configure, and maintain our geographically distributed network boundaries. Architect and engineer secure site-to-site IPsec VPN tunnels and related components to modernize our boundary from TIC 2.0 colocation centers to cloud-integrated TIC 3.0 secure overlays.
  • Multi-Vendor Firewall & Switching Engineering: Perform expert-level administration, configuration, and troubleshooting of our enterprise firewall and switching planes. This includes configuring and managing products that may include, Palo Alto Networks Next-Generation Firewalls, Fortinet FortiGate appliances, as well as Juniper and Brocade switches.
  • GitOps & Automation Integration: Maintain and enforce network configuration baselines using Infrastructure as Code (IaC) techniques. Collaborate with our tools development team to write and execute Ansible playbooks and GitLab CI/CD pipelines to automate VLAN assignments, port configuration, and dynamic DNS sinkhole blocks.
  • Network Observability & Traffic Analysis: Utilize packet brokers to capture and route packet streams. Operate tools and technologies to monitor internal network flows and detect anomalous lateral movement. Integrate out-of-band network probing utilities to continuously track perimeter performance.
  • Technical Documentation & Configuration Management: Develop and maintain up-to-date, accurate documentation of network cabling, IP Addresses, MAC addresses, and VLAN assignments for critical systems. Utilize tools to generate dynamic network topology maps, execute runbooks, and automate configuration drift audits.
  • Vulnerability Remediation & Compliance: Collaborate closely with the ISSO and Vulnerability Assessment Teams. Run network vulnerability scans, analyze results, apply Security Technical Implementation Guides (STIGs/CIS), and execute directed patching or configuration changes.
  • COOP & High-Availability Operations: Configure and maintain High-Availability (HA) firewalls, actively diagnosing active-active split-brain states or persistent ARP resolution bugs. Participate in a 24/7 on-call rotation with a strict one-hour response window for service-impacting network events.

Minimum Qualifications:
· Bachelor’s degree in Computer Science, Computer Systems Engineering, Cybersecurity, or a related field with 5+ years of direct Systems or Network Engineering experience or Associate’s degree in a related field with 8+ years of relevant experience or 11+ years of relevant experience with no degree.

  • Firewall & Networking Ecosystem: Minimum of 3 years of hands-on administration of Palo Alto Networks firewalls (PAN-OS) and Juniper core switching infrastructure (Junos OS) in an enterprise environment.
  • Dynamic Routing & Tunneling: In-depth technical mastery of BGP routing (including BGP Anycast configurations and route-withdrawal failover scripts), OSPF, and IPsec VPN tunneling.
  • Security Frameworks: Proven working knowledge of federal security compliance standards, including FISMA, the NIST Risk Management Framework (RMF) SP 800-53 Rev. 5, and CISA Zero Trust guidelines.

Preferred Qualifications:

  • Possession of one or more of the following professional, role-based security certifications is highly desired to align with Department of Commerce (DOC) CAT Standards:
  • ISC2 CISSP (Certified Information Systems Security Professional) or ISSAP (Information Systems Security Architecture Professional)
  • Cisco CCIE Security, CCDE, or CCAr
  • ISC2 CCSP (Certified Cloud Security Professional)
  • Networking Baselines: Active CCNA or Advanced Palo or Juniper-equivalent certifications.
  • Infrastructure Automation: Experience scripting in Python or Bash and building custom playbooks in Ansible to manage network configurations.
  • Cloud Architecture: Experience setting up secure transit gateways and VPC routes within Amazon Web Services (AWS) or Microsoft Azure environments.

Clearance Requirements:
· Must be a US citizen with a current/active Secret clearance.
Physical Requirements:

  • Must be able to remain in a stationary position more than 50% of the time.
  • Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.

The projected compensation range for this position is $117,000.00-$195,100.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, MANTECH invests in its employees beyond just compensation. MANTECH’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.

MANTECH considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.

If you need a reasonable accommodation to apply for a position with MANTECH, please email us at and provide your name and contact information.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级定价分析师

ManTechUnited States$80,300 - $133,700/年Full Time今天
其他限定地区(需当地身份)

SAP 集成开发工程师

ManTechUnited States$75,800 - $127,000/年Full Time今天
开发工程限定地区(需当地身份)

技术顾问

ManTechUnited States$105,900 - $177,300/年Full Time今天
开发工程职能支持限定地区(需当地身份)

← 返回全部职位