Senior Network Security Engineer
Job Title: Senior Network Security Engineer
Work Type: Hybrid
Location: Mechanicsville, VA
Start Date: 08/03/2026
End Date: 06/30/2027
Industry Category: Information Technology / Government
Employment Type: 1099 Contract
Requisition ID: 807471
Overview
We are seeking an experienced Senior Network Security Engineer to implement, secure, and support the agency's enterprise network, cloud, and computing infrastructure. This position plays a critical role in protecting a hybrid enterprise environment spanning approximately 300 statewide locations while ensuring the confidentiality, integrity, and availability of mission-critical systems and public-facing applications. The successful candidate will collaborate closely with Infrastructure, Cloud Engineering, and the Information Security Office to strengthen VDOT's cybersecurity posture across on-premises and Azure environments.
Application
Applications will be reviewed as received.
Candidates must:
• Physically reside within the United States for the duration of the assignment.
• Be legally authorized to work in the United States without employer sponsorship, now or in the future.
• Be available to attend an in-person interview.
• Meet all required technical qualifications listed below.
Job Description
The Senior Network Security Engineer is responsible for securing, designing, documenting, researching, implementing, and supporting VDOT's enterprise network and computing infrastructure. This role supports a large-scale hybrid environment that includes Palo Alto firewalls, Azure networking, ExpressRoute connectivity, Web Application Firewalls (WAF), Splunk SIEM, SD-WAN technologies, and mission-critical public-facing applications. The engineer will lead security initiatives, respond to incidents, perform proactive threat hunting, and ensure network security architecture aligns with agency standards and best practices.
Responsibilities
Technical Duties
• Design, implement, and maintain secure network architectures across on-premises and Microsoft Azure environments.
• Ensure network security architecture complies with operational security standards before and after deployment.
• Lead investigations, containment, and resolution of network security incidents.
• Review firewall rule requests and validate compliance with established security standards.
• Monitor security events using SIEM platforms and coordinate incident response activities.
• Conduct proactive threat hunting and anomaly detection across enterprise environments.
• Perform network security assessments and recommend remediation strategies.
• Identify, prioritize, and remediate network security vulnerabilities.
• Support penetration testing initiatives and remediation efforts.
• Validate Web Application Firewall (WAF) and firewall placement, integration, and connectivity.
• Lead implementation, review, and ongoing management of agency WAF solutions.
• Diagnose security threats using system logs, SIEM platforms, diagnostic tools, monitoring utilities, and test equipment.
Documentation & Security Governance
• Develop and maintain network security standards and operational documentation.
• Produce and maintain network architecture diagrams, IP addressing schemes, firewall rule documentation, and access control records.
• Ensure documentation accurately reflects enterprise security configurations and operational procedures.
Collaboration
• Partner with Infrastructure, Cloud Engineering, and Information Security teams to maintain secure enterprise operations.
• Communicate technical issues effectively to both technical teams and executive leadership.
• Mentor junior engineers and provide technical guidance on security best practices.
Operational Support
• Support a hybrid enterprise environment consisting of approximately 300 statewide locations.
• Participate in on-call support during critical security incidents.
• Independently manage assigned projects while maintaining operational excellence.
Minimum Qualifications
• Minimum 8 years of enterprise networking experience.
• Minimum 5 years of enterprise security experience.
• Minimum 3 years of Azure networking experience.
• Minimum 3 years of WAF/Next-Generation Firewall (NGFW) experience.
• Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
• Experience with SIEM platforms such as Splunk or Microsoft Sentinel.
• Experience with vulnerability management, remediation tracking, and vulnerability scanning tools such as Nessus, Tenable, or similar solutions.
• Experience with Active Directory, Multi-Factor Authentication (MFA), Conditional Access, and certificate management.
• Experience applying SEC530 guidance, CIS Benchmarks, NIST Cybersecurity Framework (CSF), NIST 800-53, and Zero Trust principles.
• Experience with Cisco ISE, Network Access Control (NAC), 802.1X, ccExperience with Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, GlobalProtect, and F5 BIG-IP technologies.
• Experience supporting highly regulated environments and leading technical troubleshooting during production outages.
• Demonstrated ability to communicate technical concepts to technical and executive audiences.
• Ability to mentor junior engineers.
• Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), or the ability to achieve these certifications.
• Must physically reside within the United States for the duration of the assignment.
• Must attend an in-person interview.
• Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Preferred Qualifications
• Minimum 3 years of experience supporting enterprise environments with more than 300 network devices.
Compensation
This is a 1099 Contract position.
Pay Rate: $69 - $89 per hour
Schedule
• Start Date: August 3, 2026
• End Date: June 30, 2027
• Assignment Duration: Approximately 11 months
• Hybrid work arrangement.
• Participation in on-call support during critical security incidents is required.
Work Location
Worksite Address:
Mechanicsville, VA
• Hybrid work arrangement with onsite presence as required.
• In-person interview is mandatory.