Firewall Network Security Engineer

Intel Intel · Semiconductors · Arizona, Phoenix, United States

Network Security Engineer role focused on designing, architecting, and building secure classified network products for USG operations, involving firewall configuration, network hardening, and security assessments.

What you'd actually do

  1. Assist with architecting network and network security products in secured enclaves, including product testing, validation, and selection.
  2. Assist with design and long-term roadmap planning for new and future scalability in secure enclaves.
  3. Play a supporting role with the definition of system security requirements, including but not limited to the authorization boundary, security domains, classification of data, etc.
  4. Assist with design the security interfaces, security interconnections, and the trust relationship between system components and external systems.
  5. Implement system security designs using commercial-off-the-shelf (COTS), government-off-the-shelf (GOTS), and open-source hardware and software.

Skills

Required

  • Deploying, configuring, Fortinet FortiGate firewalls (FortiOS, VDOMs, High Availability)
  • Building and deploying FortiManager and FortiAnalyzer in cloud or on premises.
  • Routing (BGP/OSPF), NAT, and network segmentation, IP address subnetting
  • Designing and managing firewall policies, IPS/IDS, and threat controls
  • Ability to obtain an active US Government Security Clearance
  • Bachelor's degree with 3+ years of information technology experience

Nice to have

  • Active US Government Top Secret (TS) Security Clearance with the skill to obtain and maintain SCI access.
  • Experience with DoD security implementation (e.g. STIG) and security tools for managing the environment.
  • Experience with building and managing network infrastructure using automation tools. (Ansible, Python, APIs)
  • Integration with SIEM, NAC (ISE), and enterprise network/security tools
  • Understanding of NIST/STIG/compliance-driven environments
  • Develop and maintain operational processes and documentation for ongoing support
  • Ability to support security operations: monitoring, analysis, incident response, and vulnerability management
  • Experience with network analysis software such as SD Elements, Splunk, Sniffer, Wireshark, or Microsoft Network Monitor.
  • Certifications in cybersecurity to include Certified Cloud Security Professional (CCSP) or Certified Information Systems Security Professional (CISSP).
  • Experience with scripting in the UNIX environment.
  • Experience utilizing Ansible as a configuration management tool, for system administration of users or devices, or as a security compliance automation tool.
  • Experience with operational monitoring with SNMP or other Enterprise Network Management Systems
  • Familiar with VPN implementation (IPSec, SSL) with identity integration (AD/MFA)
  • Experience with troubleshooting tools from CLI, packet capture, and log analysis

What the JD emphasized

  • U.S. citizenship
  • active US Government Security Clearance
  • Fortinet FortiGate firewalls