Network Security Engineer III

Invictus International ConsultingColorado Springs, CO
Onsite

About The Position

Responsible for the deployment, configuration, and operational support of enterprise firewall infrastructure. This role requires a strong understanding of enterprise networking fundamentals, including routing, switching, and end-to-end traffic flow, as well as hands-on experience with eBGP, VLANs, and Palo Alto APP-ID. The engineer will design, implement, and maintain Next-Generation Firewall (NGFW) security policies for both physical and virtual firewalls, and perform Intrusion Detection/Intrusion Prevention System (IDS/IPS) configuration, tuning, and alert triage. Additionally, the role involves network security monitoring, traffic analysis, anomaly detection, and troubleshooting complex connectivity issues. Collaboration with network, Security Operations Center (SOC), and engineering teams is essential during incidents and routine operations. The position also requires the creation and maintenance of network diagrams, configurations, runbooks, and post-incident findings.

Requirements

  • Bachelor's degree from an accredited institute in a technical discipline (an additional four (4) years of experience may be substituted in lieu of a degree)
  • Minimum six (6) years of relevant experience in addition to education level
  • Must possess current DoD 8570 IAT II and CCNP (or equivalent) certifications
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Nice To Haves

  • Experience working in a DoD or Intelligence Community Environment

Responsibilities

  • Deployment, configuration, and operational support of enterprise firewall infrastructure
  • Execution of enterprise networking fundamentals, including routing, switching, and end-to-end traffic flow
  • LAN and WAN troubleshooting
  • Hands-on experience with eBGP, VLANs, and Palo Alto APP-ID
  • Design, implementation, and maintenance of NGFW security policies (physical and virtual firewalls)
  • IDS/IPS configuration, tuning, and alert triage
  • Reading, producing, and maintaining accurate network diagrams (Visio or equivalent)
  • Network security monitoring, including traffic analysis and anomaly detection
  • Troubleshooting routing, VLAN, and policy-related issues impacting data flow
  • Performing packet captures and traffic analysis to isolate and resolve complex connectivity issues
  • Monitoring and refining Splunk dashboards and alerts for firewall operations and incident investigation
  • Collaborating with network, SOC, and engineering teams during incidents and routine operations
  • Documenting configurations, runbooks, and post-incident findings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service