
Senior Network Security Engineer
MANTECH
Visa & sponsorship
- Reserved for United States nationals (a nationalization requirement such as Saudization/Emiratization) — not open to expatriates.
- A US security clearance is required, which effectively means citizens only.
Job description
MANTECH seeks a motivated, career and customer-oriented Senior Network Security Engineer to join our team in either Fairmont, WV, Boulder CO, or REMOTE (US-Based).
The Senior Network Security Engineer will serve as a technical anchor, driving network modernization efforts, eliminating operational silos, and leading the transition from legacy, colocation-dependent architectures to a secure, cloud-integrated Trusted Internet Connection (TIC) 3.0 framework. The candidate must possess a strong, proactive problem-solving mindset and be comfortable working in a high-tempo, availability-first environment.
Responsibilities include but are not limited to:
-
Perimeter Architecture & TIC 3.0 Transition: Design, configure, and maintain our geographically distributed network boundaries. Architect and engineer secure site-to-site IPsec VPN tunnels and related components to modernize our boundary from TIC 2.0 colocation centers to cloud-integrated TIC 3.0 secure overlays.
-
Multi-Vendor Firewall & Switching Engineering: Perform expert-level administration, configuration, and troubleshooting of our enterprise firewall and switching planes. This includes configuring and managing products that may include, Palo Alto Networks Next-Generation Firewalls, Fortinet FortiGate appliances, as well as Juniper and Brocade switches.
-
GitOps & Automation Integration: Maintain and enforce network configuration baselines using Infrastructure as Code (IaC) techniques. Collaborate with our tools development team to write and execute Ansible playbooks and GitLab CI/CD pipelines to automate VLAN assignments, port configuration, and dynamic DNS sinkhole blocks.
-
Network Observability & Traffic Analysis: Utilize packet brokers to capture and route packet streams. Operate tools and technologies to monitor internal network flows and detect anomalous lateral movement. Integrate out-of-band network probing utilities to continuously track perimeter performance.
-
Technical Documentation & Configuration Management: Develop and maintain up-to-date, accurate documentation of network cabling, IP Addresses, MAC addresses, and VLAN assignments for critical systems. Utilize tools to generate dynamic network topology maps, execute runbooks, and automate configuration drift audits.
-
Vulnerability Remediation & Compliance: Collaborate closely with the ISSO and Vulnerability Assessment Teams. Run network vulnerability scans, analyze results, apply Security Technical Implementation Guides (STIGs/CIS), and execute directed patching or configuration changes.
-
COOP & High-Availability Operations: Configure and maintain High-Availability (HA) firewalls, actively diagnosing active-active split-brain states or persistent ARP resolution bugs. Participate in a 24/7 on-call rotation with a strict one-hour response window for service-impacting network events.
Minimum Qualifications:
-
Bachelor’s degree in Computer Science, Computer Systems Engineering, Cybersecurity, or a related field with 5+ years of direct Systems or Network Engineering experience or Associate’s degree in a related field with 8+ years of relevant experience or 11+ years of relevant experience with no degree.
-
Firewall & Networking Ecosystem: Minimum of 3 years of hands-on administration of Palo Alto Networks firewalls (PAN-OS) and Juniper core switching infrastructure (Junos OS) in an enterprise environment.
-
Dynamic Routing & Tunneling: In-depth technical mastery of BGP routing (including BGP Anycast configurations and route-withdrawal failover scripts), OSPF, and IPsec VPN tunneling.
-
Security Frameworks: Proven working knowledge of federal security compliance standards, including FISMA, the NIST Risk Management Framework (RMF) SP 800-53 Rev. 5, and CISA Zero Trust guidelines.
Preferred Qualifications:
-
Possession of one or more of the following professional, role-based security certifications is highly desired to align with Department of Commerce (DOC) CAT Standards:
-
ISC2 CISSP (Certified Information Systems Security Professional) or ISSAP (Information Systems Security Architecture Professional)
-
Cisco CCIE Security, CCDE, or CCAr
-
ISC2 CCSP (Certified Cloud Security Professional)
-
-
Networking Baselines: Active CCNA or Advanced Palo or Juniper-equivalent certifications.
-
Infrastructure Automation: Experience scripting in Python or Bash and building custom playbooks in Ansible to manage network configurations.
-
Cloud Architecture: Experience setting up secure transit gateways and VPC routes within Amazon Web Services (AWS) or Microsoft Azure environments.
Clearance Requirements:
- Must be a US citizen with a current/active Secret clearance.
Physical Requirements:
-
Must be able to remain in a stationary position more than 50% of the time.
-
Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.