Professional Technology Integration, Inc.

Network Security Engineer (Ref: 18558)

Mechanicsville, VA • Posted Today
Hybrid Contract General

Position: Network Security Engineer (Ref: 18558)
Location: Mechanicsville, VA USA, 23116
Salary: DOE
Duration: 10 Months 27 Days - Contract
Openings: 1
Deadline: 08/07/2026
Description:
***Local Candidate
***Hybrid

We are seeking an experienced Senior Network Security Engineer to implement, support, and secure enterprise IT network, cloud, and computing infrastructure. In this role, you will lead day-to-day security operations, perform network research, design secure architecture, and handle threat mitigation across on-premises and cloud environments.

You will support a high-availability, hybrid enterprise environment comprising roughly 300 locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, Web Application Firewalls (WAF), Splunk SIEM, SD-WAN, and critical public-facing applications.

Key Responsibilities
• Architecture & Design: Design and maintain secure hybrid network architecture across on-premises and Azure environments. Ensure network security architecture aligns with operational security standards before and after deployment.
• Firewall & WAF Management: Validate WAF and firewall placement, integration, exposure, and connectivity. Lead implementation, review, and management of WAF solutions and review firewall rule requests for compliance.
• Incident Response & Operations: Lead the investigation, containment, and coordination of network security incidents. Participate in on-call support for critical incidents.
• Threat Detection & Hunting: Conduct proactive threat hunting and anomaly detection using SIEM technologies (Splunk), system logs, line monitors, diagnostic software, and test equipment.
• Assessments & Vulnerabilities: Identify, prioritize, and remediate network security vulnerabilities and support penetration testing efforts.
• Documentation: Develop and maintain network security standards, network architecture topology diagrams, IP schemes, firewall rules, and access controls.

Qualifications & Key Requirements
• Extensive experience in Network Security Engineering within a hybrid enterprise environment.
• Strong expertise with Palo Alto Firewalls, Azure Networking, ExpressRoute, and SD-WAN.
• In-depth hands-on experience with WAF technologies and Splunk SIEM.
• Demonstrated ability to conduct proactive threat hunting, log analysis, and incident containment.
• Proven track record of creating detailed network architecture diagrams and access control documentation.
• Ability to work independently on assigned projects and collaborate effectively across cloud, infrastructure, and information security teams.

Work Details
• Interview Process: In-Person Only.
• Work Arrangement: Hybrid (requires on-site presence at the designated worksite in Mechanicsville, VA).

Required / Desired Skills
• Enterprise Networking Required - 8 Years
• Enterprise Security Required - 5 Years
• Azure Networking Required - 3 Years
• WAF/NGFW Required - 3 Years
• Supporting environments with 300+ Network Devices Required - 3 Years
• Experience in the following areas: Incident response, Security investigations, Log analysis, Threat intelligence, Security monitor Required - 3 Years
• Experience with the SIEM products (e.g. Splunk, Microsoft Sentinel) Required - 3 Years
• Experience in vulnerability management and remediation tracking as well as vulnerability scanning tools (e.g. Nessus, Tenable, Def) Required - 3 Years
• Experience in the following areas: Active Directory, MFA, Conditional Access, Certificates Required - 3 Years
• Experience with; SEC530, CIS Benchmarks, NIST CSF, NIST 800-53, Zero Trust principles Required - 3 Years
• Experience with the following: Cisco ISE, NAC, 802.1X, RADIUS, TACACS Required - 3 Years
• Experience with the following products: Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, Global Protect, F5 BIG-IP Required - 3 Years
• Experience working in highly regulated environments and leading technical troubleshooting during outages Required - 3 Years
• Ability to communicate technical issues to technical and executive audiences and an ability to mentor junior engineers. Required - 3 Years
• Ability to achieve the following certifications: Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), Required - 3 Years

Back to Job Search