POSITION OVERVIEW
The Senior Network & Virtual Security Engineer implements and sustains the DoD-compliant Secure Computing Architecture (SCA) protecting NAVSUP's cloud hosting environments in support of the Department of the Navy. This role is responsible for architectural review, design, installation, and configuration of SCA VDSS and VDMS stacks on NAVSUP virtual hardware using Juniper SRX, Palo Alto, Cisco, and F5 BIG-IP platforms; evaluating and implementing new Cloud Service Provider services; monitoring and auditing NAVSUP cloud service usage; onboarding customer and mission partner applications onto SCA VDSS software; and resolving complex network and traffic-flow faults including SSL handshake and termination issues. Work is performed remotely from within the United States. This position requires an active Top Secret clearance, privileged system access, and an IT-I security designation.
DUTIES AND RESPONSIBILITIES
- Evaluate, design, perform architectural reviews of, and implement new Cloud Service Provider (CSP) services as they become available to NAVSUP BSC or are identified as Mission Owner requirements
- Monitor and audit NAVSUP cloud service usage, including usage monitoring, performance monitoring, user activity auditing, alert management, and issue tracking
- Execute the architectural reviews, design, installation, and configuration required to implement and sustain NAVSUP BSC cloud environment tools — including Juniper SRX, Palo Alto firewalls, Cisco software, and F5 BIG-IP — to provide a DoD-compliant Secure Computing Architecture (SCA) VDSS stack
- Perform analysis, design, architectural reviews, installation, and configuration to implement DoD-compliant SCA VDSS and VDMS stacks on NAVSUP virtual hardware
- Execute installations including Cisco, Juniper, Palo Alto, and F5 BIG-IP platforms, including required add-on modules
- License, configure, manage, and sustain SCA software operations
- Execute onboarding of customer and mission partner applications and services leveraging SCA VDSS software
- Resolve SCA issues including SSL handshake and termination, traffic flow, network and server performance, and unique configurations
- Sustain BIG-IP and BIG-IQ across multiple NAVSUP enterprise-approved hosting environments
- Deliver test plans and execute testing of installations and configurations to verify compliance with operational specifications
- Execute required interoperability testing and draft interoperability waiver requests as required by the Government
- Deliver internal testing results for all NAVSUP BSC Brokerage NTA-provided services and tools
- Execute monthly knowledge transfer and mentoring to NAVSUP BSC Government personnel, and document each event in the Monthly Knowledge Transfer Log
QUALIFICATIONS
- Active Top Secret clearance
- IT-I security designation and privileged system access
- DoD 8570.01-M IAT Level II baseline certification: CompTIA Security+ CE, or an approved substitute — CCNA Security with CEs, CCNA Cybersecurity, CySA+, GICSP, GSEC, CND, or SSCP. Certification must be current at the contract period start date; there is no grace period
- Active enrollment and participation in the certification maintenance program
- Information Assurance Technical Level I training and certification, with certification on the operating system or computing environment maintained
- Computing environment certification, current no later than six (6) months after start: AWS Certified Solutions Architect, AWS Certified Cloud Practitioner, AWS Certified Developer, AWS Certified Advanced Networking, Cisco Certified Network Associate, a Juniper Networks certification, F5 Certified Technical Professional, or equivalent
- Five (5) years of experience with network and virtual security engineering, including Infrastructure as Code (IaC)Â
- Hands-on experience installing, configuring, and sustaining F5 BIG-IP/BIG-IQ, Palo Alto firewalls, Cisco Firepower, and Juniper SRX in a DoD or Federal environment
- Demonstrated experience implementing DoD-compliant VDSS and/or VDMS architectures
- Ability to work remotely from a U.S. location and to complete DoD onboarding, security, and mandatory annual training requirements on schedule
- Preferred: prior NAVSUP or Department of the Navy experience; experience drafting DoD interoperability waiver requests
Learn more about this Employer on their Career Site
