Sr. Network Security Architect

3 weeks ago


Arlington, Virginia, United States AES Corporation Full time
We are seeking a skilled and seasoned Senior Security Network Engineer to join our network team. The successful candidate will play a critical role in architecting, designing, deploying, monitoring, maintaining, and refreshing secure global IT/OT network infrastructures to protect digital assets from leakage, unauthorized access, and cyber-attacks.

The Senior Security Network Engineer will collaborate with cross-functional and multi-cultural global teams to prevent, detect, and respond to threats to the organization's critical information assets. .

Responsibilities

  • Analyze existing network security controls and strengthen the controls that could make vulnerability exploitation more likely - such as Data Loss Protection, technical debt, etc.
  • Design and implement a global NAC solution (e.g. Cisco ISE) to control and authenticate network access including port-based network access control 802.1X.
  • Research and propose new VPN, ZTNA, and VPN-less access solutions to provide secure remote access for authorized users and site-to-site remote access.
  • Design, architect, and deploy Zscaler cloud-based solution infrastructure across SDWAN-based sites.
  • Manage implementation plans and operations supervision of Zscaler solutions (ZIA, ZPA, ZDX, etc.).
  • Proactively monitor reporting and consumption information along with policy configurations of Zscaler technologies and make ongoing recommendations to improve the overall experience.
  • Review and architecture restricted access to contractors and third-party employees to ensure security and reliability in a self-service environment.
  • Develop and automate tools and techniques to scale and accelerate network offensive emulation, anomaly detection, and vulnerability discovery using AI technology. Collaborate with teams to influence implementation, measurement, and mitigation of these vulnerabilities.
  • Develop, improve, and communicate a compelling strategy and roadmap for network vulnerability and data leak prevention management.
  • Design, implement, maintain, monitor, and support company-wide network security best practices. Draft and share network services configuration hardening standards.
  • Build relationships with cyber security teams, network operations, digital assets support, and business areas in support of the global data protection initiative.
  • Measure, report, and automate the network security team's performance against objectives, policy compliance targets, and network security goals (e.g., SLAs, KPIs, KRIs, OKRs)
  • Install security measures and operate software to protect systems and information infrastructure, including assisting with firewalls security rules, and data security implementation. Regularly review and request updates of firewall rules and configurations to address emerging security risks.
  • Collaborate with analysis and responses to alerts generated by IDPS tools.
  • Conduct regular security audits of network infrastructure and devices.
  • Understand secured web traffic flow standards and custom application-based traffic and design firewall and proxy services.
  • Expect to assist as L3 SME for critical business impact P0/P1 network security escalations during operational and non-operational hours.
  • Provide data and root cause analysis of network security incidents with corrective actions for improvement. Fix detected vulnerabilities.
  • Closely working with compliance and internal audit departments to ensure network security standards are in place, enforced, and maintained, and provide evidence samples according to the requirement.
  • Research upcoming trends in information technology and security, stay updated on potential threats and attacks, and come up with preventive roadmaps.
  • Help develop and maintain network security content in the internal Knowledge Base.
  • Develop and provide network-related Cyber Security Training and improve network Cyber Security Awareness around the global network teams.

Qualifications

  • Demonstrable experience in defining, reviewing, analyzing, and creating cybersecurity documentation, including actionable security standards, implementation procedures, cyber risk assessments, cyber security audits, remediation plans, and cyber control guidelines.
  • Solid grasp of security controls in Physical (network, platforms) and Cloud environments (i.e., IaaS, PaaS, SaaS, multi-cloud).
  • Familiarity with Cloud Security Alliance (CSA) guidelines.
  • Extensive experience in the development and delivery of security-level agreements and metrics via real-time reporting and alerting dashboards (SharePoint, Power BI, SQL, Office 365, Microsoft Teams).
  • Proficient with a broad array of security software applications and data leak protection tools with an emphasis on Zscaler and Cisco security technologies.
  • Detailed understanding of network-related modern systems including firewalls, encryption, network access control, wireless and wired secure access, SD-WAN, SD-Access, secure remote network access, and password protection and authentication.
  • Understanding of cyber security frameworks for the OT environment including Industrial control systems (ICS) the devices, controls, and networks that handle different industrial processes , supervisory control and data acquisition (SCADA) systems, and distributed control systems (DCS).
  • Solid understanding of cyber-security technologies like AV, Sandbox, IPS, IDS, NGFW, and WAF.
  • Very solid background with vulnerability discovery and demonstration of exploitations.
  • Ability to see through bad actors' eyes and find ways to break open the cyber security protocols and technologies embraced within the organization.
  • A data-driven, problem-solving, curious candidate with strong analytical skills and who is not afraid to challenge the status quo.
  • A self-starter with a goal-oriented, can-do attitude who is comfortable communicating cyber concepts, and risk management to all levels of personnel.
  • Ability to influence other IT professionals, including network engineers, digital support, application owners, project managers, and system managers, to integrate security network controls into existing systems and processes.
  • Proven ability to communicate effectively across all levels of the organization, including the delivery and explanation of complex security-related concepts in clear, concise, and understandable terms.

Preferred Qualifications

  • Bachelor's degree required in technology, information security or related fields or equivalent work experience.
  • Demonstrated ability in computer systems with some specialization in computer security highly preferred.
  • Knowledge of foundational security controls and how they protect an enterprise environment.
  • Relevant certifications (e.g., Certified Information Systems Security Professional - CISSP, Certified Information Security Manager - CISM).
  • Very strong capacity to create new exploits or craft existing exploits to identify security loopholes in the network control cyber security plane.
  • Experience with PowerShell and SQL query creation and modification.
  • Scripting - Working knowledge of computer programming language.
  • This is a remote position; however, we require that the candidate be located close to one of the AES locations.
  • Some travel required (~15-20%)

Read the full posting.



  • Arlington, Virginia, United States Two Six Technologies Full time

    Two Six Technologies is looking to add a Principal Network Security Analyst to our team. This role will be responsible for developing and deploying capabilities for our customers. You will also be responsible for discovering, signaturing, and developing controls for malicious behavior against critical communication systems.Job Responsibilities & Duties:Serve...


  • Arlington, Virginia, United States SAIC Career Site Full time

    Description SAIC is looking for a talented Enterprise Architect to our ABMS Family of Systems as part of the Air Force Combatant Command Business Group to spearhead alignment for technology road map development and strategic planning. The ideal candidate possesses expertise in Enterprise Architecture development, IRAD investment planning, Systems...

  • Eng Sr Prin

    2 weeks ago


    Arlington, Virginia, United States BAE Systems USA Full time

    BAE is looking for a Senior Linux Engineer to lead a team of Infrastructure engineers to plan, install, operate and maintain the enterprise Linux environment supporting a government partner enterprise IT infrastructure.Responsible to support the solutions architect and enterprise architect in service design, service transition and service operations and...


  • Arlington, Virginia, United States Two Six Technologies Full time

    Two Six Technologies is looking to add a Senior Network Operator to our team. As a network operator, you'll use your technical experience to solve some of the most challenging technical and intelligence issues via performing in-depth protocol analysis for computer network operations.Job Responsibilities & Duties:Provide cutting-edge analytic expertise...


  • Arlington, Virginia, United States AES Corporation Full time

    At AES, we raise the quality of life around the world by changing the way energy works. Everyone makes an impact every day in our small, global teams. Apply here to start an extraordinary career today. The candidate must have a strong working knowledge of the NERC CIP Standards as well as audit controls and testing methodologies. In addition a strong working...


  • Arlington, Virginia, United States SecuriGence LLC Full time

    SecuriGence is seeking an experienced Cyber Security Engineer to help contribute to our success.Responsible for analyzing the security of hardware (SoC, MCU, etc.)Implementation of technology that supports network defense, vulnerability management, and incident response based on our client's unique mission needs.Implement and maintain security stack...


  • Arlington, Virginia, United States Department Of State Full time

    Summary This serves as public notice for the use of OPM's Direct Hire Authority.This vacancy announcement will be open from April 22nd, 2024 to April 26th, 2024 or when 100 applications have been received. The vacancy will close on whichever day the first of these conditions are met. If the application limit is reached on the same day the announcement...


  • Arlington, Virginia, United States Department Of Homeland Security Full time

    Summary This announcement is issued under the Direct Hire Authority (DHA) to recruit for positions for which there is a critical hiring need. Selectee(s) will receive a career or career-conditional appointment in the competitive service and may be required to serve a one-year probationary period.Who May Be Considered:U.S. CitizensView common definitions of...


  • Arlington, Virginia, United States AES Corporation Full time

    The Analyst-ISOC, Infrastructure Security position directly supports the AES Infrastructure Security organization for all ongoing activities that serve to provide access to and protect the confidentiality, integrity, and availability of employee and business information. This follows compliance with organizational policies and procedures along with...

  • Cyber Engineer II

    4 weeks ago


    Arlington, Virginia, United States Solutions3 Full time

    Cyber Security EngineerThe Cyber Security Engineer may be involved with commercial, custom and/or government computer product vendors in the design, evaluation, and architecture of state-of-the-art secure GOTS/COTS applications, operating systems, networks, databases, and custom built technology.Provide technical leadership for an engineering team...


  • Arlington, Virginia, United States BAE Systems Full time

    Job Description BAE is looking for a Senior Windows Engineer for Microsoft Windows Infrastructure team. The Senior Windows Engineer will plan, install, operate, and maintain the enterprise Windows server and identity Management environment supporting a government partner enterprise IT infrastructure. Responsible to support the solutions architect and...


  • Arlington, Virginia, United States Virginia Hospital Center Full time

    Technical Systems AdministratorPurpose & Scope:The Technical Systems Administrator is responsible to provide systems engineering and administrative support across a wide array of software and hardware systems and components used to deliver production services. The incumbent provides technical leadership and direction for the automation and improvement of...


  • Arlington, Virginia, United States IT Full time

    Nestlé Information Technology is the digital arm of the world's largest nutrition, health, and wellness company. With 150+ years in business, 2,000+ brands, and 270,000+ diverse team members-you're joining an organization that's revolutionizing food and championing global humanitarian efforts with technology at its core.Joining Nestlé IT means you'll never...

  • Cyber Engineer

    2 weeks ago


    Arlington, Virginia, United States Solutions³ LLC Full time

    Cyber Engineer - Principal I - SCE0- Full PerformanceThe successful Cyber Security Engineer applies current analytical and logical thinking to the design, architecture, development, evaluation, testing, and integration of computer systems, appliances, and networks to elevate the security posture of the program. The Cyber Security Engineer may be involved...


  • Arlington, Virginia, United States SAIC Career Site Full time

    Description SAIC is seeking an Executive Assistant to provide executive level management and analytical support to senior DoD officials within the Office of the Under Secretary of Defense for Research and Engineering (OUSD(R&E)). This is an exciting position that requires close interaction with top department leadership within the Pentagon and across the...


  • Arlington, Virginia, United States Department Of Defense Full time

    Summary This position is being recruited under 10 USC 1599f into the Cyber Excepted Service and does NOT convey eligibility to be converted to the Competitive Service. It has been identified as a position necessary to carry out and support the mission of the US Cyber Command. It is in the PROFESSIONAL Work Category at the SENIOR Work Level within the CES...


  • Arlington, Virginia, United States Knak Digital Full time

    Summary:Digital agency specializing in web/user experience design, build, and marketing. 20+ years of experience, with clients ranging from government, non-profit, advocacy, and education.Offerings:Insurance (Health, Dental, Vision), 401k, tuition reimbursement, Generous PTO, staff retreats, fully remote, rewarding high-profile client workAre you a visionary...

  • Sr Action Officer

    4 weeks ago


    Arlington, Virginia, United States SAIC Career Site Full time

    Description SAIC is seeking a Senior Action Officer to support the Principal Deputy Assistant Secretary of Defense in Critical Technologies (PDASD(CT) within the Office of the Under Secretary for Research and Engineering (OUSD(R&E)) to support developing and maintaining work products that enable management decision making, strategy development, initiative...


  • Arlington, Virginia, United States Department Of Defense Full time

    Summary This position is being recruited under 10 USC 1599f into the Cyber Excepted Service and does NOT convey eligibility to be converted to the Competitive Service. It has been identified as a position necessary to carry out and support the mission of the US Cyber Command. It is in the PROFESSIONAL Work Category at the FULL PERFORMANCE Work Level within...

  • IT Specialist

    2 weeks ago


    Arlington, Virginia, United States Department Of The Army Full time

    Summary About the Position: This position is in the Defense Civilian Intelligence Personnel System (DCIPS). Employees occupying DCIPS positions are in the Excepted Service and must adhere to U.S. Code, Title 10, as well as Department of Defense Instruction This position is located at the Office of the Chief of Staff of the Army, G-2, Information Management...