Network Security Engineer

Valiant Solutions, LLCSilver Spring, NC
$130,000 - $135,000Hybrid

About The Position

Valiant Solutions is seeking a Network Security Engineer to deploy and operate the Network Access Control and perimeter security capabilities protecting a federal agency's enterprise network. The engineer owns the Cisco Identity Services Engine deployment end to end, covering 802.1X authentication of Government Furnished Equipment, HSPD-12 credential integration, endpoint posture assessment across Windows and macOS, and TrustSec segmentation, alongside the Cisco Firepower Threat Defense firewall fleet and the remote access VPN. The current environment runs a seven-node ISE deployment on version 3.4 with separate policy sets per organizational component, and roughly 384 network access devices await integration. This position turns that partial deployment into enforced Zero Trust access control under NIST SP 800-207, measured against a target of 80 percent of active access ports under 802.1X enforcement within the first year. This position is based in Silver Spring, MD, and allows for partial remote work.

Requirements

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Systems, or a related technical field. Four (4) additional years of specialized experience may be substituted for a Bachelor's degree.
  • 6 years of dedicated experience in network security engineering and infrastructure protection.
  • Hands-on experience taking a Cisco ISE deployment from partial configuration to enforced enterprise-wide 802.1X.
  • Experience operating a production firewall fleet in an environment with defined availability standards.
  • Cisco Identity Services Engine administration, including distributed PAN, MnT, PSN, and pxGrid node topologies.
  • 802.1X, RADIUS, MAB, and certificate-based authentication in mixed Windows and macOS environments.
  • Endpoint posture assessment with AnyConnect and Cisco Secure Client.
  • Cisco TrustSec design using Security Group Tags and Security Group Access Control Lists.
  • Cisco Firepower Threat Defense and Firepower Management Center administration, including intrusion prevention tuning.
  • Remote access and site-to-site VPN engineering with posture integration and machine certificate enforcement.
  • PKI concepts as they apply to machine and user certificate validation.
  • Switching and routing fundamentals sufficient to troubleshoot access-layer authentication failures end to end.

Nice To Haves

  • Cisco Certified Network Professional (CCNP) Security, Certified Information Systems Security Professional (CISSP), or CompTIA Security+.

Responsibilities

  • Review and validate the existing Cisco ISE configuration, document the gaps, and deliver the remediation design within the first 90 days of performance.
  • Configure and enforce 802.1X authentication for Government Furnished Equipment across the enterprise access layer.
  • Integrate ISE with Active Directory and LDAP, and enforce HSPD-12 compliant authentication using CAC or Yubikey credentials.
  • Build authorization policy that restricts service access to authenticated users and locks accounts after three consecutive failed login attempts.
  • Onboard network access devices into ISE in a phased sequence that protects availability while raising enforcement coverage.
  • Configure the ISE profiling engine to discover, identify, and monitor every endpoint on the network.
  • Deploy and tune AnyConnect and Cisco Secure Client posture agents on both Windows and macOS endpoints.
  • Implement posture checks that validate antivirus and antimalware status, host firewall state, and operating system patch level before access is granted.
  • Develop remediation policy with the government security team so that non-compliant endpoints are quarantined and returned to service predictably.
  • Report posture metrics monthly, including the count of devices denied access for failing compliance checks.
  • Design TrustSec Security Group Tag segmentation that enforces policy by user role rather than IP address.
  • Integrate ISE with Cisco Firepower Management Center to share user and Security Group Tag context for identity-based firewall rules.
  • Manage the Cisco Firepower Threat Defense appliance fleet, including rule base tuning, intrusion prevention signature management, and malware defense configuration.
  • Migrate remaining FTD appliance configurations to the cloud management plane where applicable.
  • Support Tier 2 and Tier 3 firewall rule analysis during incident response and change windows.
  • Deploy and manage remote access and site-to-site VPN services, including concentrator configuration and capacity management.
  • Enforce posture validation before a remote client is authorized onto the network.
  • Implement machine certificate validation and equivalent technical controls that restrict client-based VPN access to Government Furnished Equipment only.
  • Prepare Methods of Procedure for every security configuration change and carry them through the Change Control Board.
  • Participate in the 24x7x365 on-call rotation, responding to Priority 1 incidents within 15 minutes.
  • Written and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.
  • Ability to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.
  • Clear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.
  • Ability to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.
  • Working knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.
  • Familiarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.
  • Understanding of HSPD-12 identity credentialing and its enforcement in network access decisions.
  • Awareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.
  • Experience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.
  • Willingness to complete required customer training, including annual cybersecurity awareness, records management, privacy, safety, and harassment prevention training.

Benefits

  • Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
  • Valiant contributes 25% towards Health Coverage for Family and Dependents
  • 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
  • 100% Paid Certifications
  • 401K Matching up to 4%
  • Paid Time Off
  • Paid Federal Holidays
  • Wellness & Fitness Program
  • Valiant University – Online Education and Training Portal
  • FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
  • Referral Bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service