Senior Network Security Engineer

ePATHUSAMechanicsville, VA
Hybrid

About The Position

Seeking an experienced Senior Network Security Engineer to implement and support the agency's IT network, cloud, and computing infrastructure. The resource will perform day-to-day activities related to securing VDOT's infrastructure, including securing, documenting, performing research, analysis, design, and implementations of VDOT's network and computing related infrastructure. This role supports a hybrid enterprise environment with approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The engineer will partner closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOT's network infrastructure, ensuring network security architecture aligns with operational security standards before and after deployment. Responsibilities include leading investigations and containment of network security incidents, reviewing firewall rule requests for compliance, designing and maintaining secure hybrid network architecture, monitoring security events, performing network security assessments, developing documentation, supporting penetration testing, conducting proactive threat hunting, and validating WAF and firewall placement. The role also involves leading WAF implementation and management, diagnosing system problems and threats, and identifying/remediating network security vulnerabilities. The candidate must be able to provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls, and work independently.

Requirements

  • Enterprise Networking Required 8 Years Candidate Experience
  • Enterprise Security Required 5 Years Candidate Experience
  • Azure Networking Required 3 Years Candidate Experience
  • WAF/NGFW Required 3 Years Candidate Experience
  • Supporting environments with 300+ Network Devices Required 3 Years Candidate Experience
  • Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor Required 5+ Years Candidate Experience
  • SIEM products (e.g. Splunk, Microsoft Sentinel) Required 5+ Years Candidate Experience
  • Vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def Required 5+ Years Candidate Experience
  • Active Directory, MFA, Conditional Access, Certificates Required 5+ Years Candidate Experience
  • SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles Required 5+ Years Candidate Experience
  • Cisco ISE, NAC, 802.1X, RADIUS, TACACS Required 5+ Years Candidate Experience
  • Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP Required 5+ Years Candidate Experience
  • Working in highly regulated environments and leading technical troubleshooting during outages Required 5+ Years Candidate Experience
  • Ability to communicate technical issues to technical and executive audiences Required 5+ Years Candidate Experience
  • Ability to mentor junior engineers Required 5+ Years Candidate Experience
  • Achieved or ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700) Required 5+ Years Candidate Experience

Responsibilities

  • Implement and support the agency's IT network, cloud, and computing infrastructure.
  • Perform day-to-day activities related to securing VDOT's infrastructure.
  • Secure, document, perform research, analysis, design, and implementations of VDOTs network and computing related infrastructure.
  • Support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission critical public-facing applications.
  • Partner closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of VDOTs network infrastructure.
  • Ensure network security architecture aligns with operational security standards before and after deployment.
  • Lead investigation and containment of network security incidents.
  • Review firewall rule requests and ensure compliance with security standards.
  • Design and maintain secure hybrid network architecture across on-premises and Azure environments.
  • Monitor security events using SIEM technologies and coordinate incident response activities.
  • Perform network security assessments and recommend remediation strategies.
  • Develop and maintain network security standards, diagrams, and operational documentation.
  • Support penetration testing and remediation efforts.
  • Participate in on-call support during critical security incidents.
  • Conduct proactive threat hunting and anomaly detection.
  • Validate WAF and firewall placement and integration exposure/connectivity.
  • Lead implementation, review, and management of agency WAF(s).
  • Identify and diagnose system problems and threats by using system logs, line monitors, SIEM, diagnostic software, and test equipment.
  • Identify, prioritize, and remediate network security vulnerabilities.
  • Provide documentation, network architecture topology diagrams, IP schemes, firewall rules, and access controls when required.
  • Work independently on assigned projects.
  • Communicate technical issues to technical and executive audiences.
  • Mentor junior engineers.

Benefits

  • Paid Sick Time
  • Insurance for Medical, Dental, Vision and Life Available
  • 401(k) including Employer Match
  • HSA, Short-term & Long-term Disability Available
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service