Credence · McLean, VA

Network Security Engineer at Credence — McLean, VA

Full-timeMcLean, VA$130,000–$155,000/yearPosted 2026-07-31Apply on Workable

Full job description

Overview

Position Summary

Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset

### Responsibilities:

### Network Infrastructure & Operations

  • Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management.
  • Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity.
  • Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government).
  • Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process.
  • Oversee network configuration management and backups to ensure recoverability and business continuity.
  • Analyze and resolve escalated Tier 2+ network support tickets.
  • Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning

### Security & Compliance

  • Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation.
  • Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions.
  • Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening).
  • Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed.
  • Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles.

### Collaboration & Support

  • Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments.
  • Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes.
  • Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions.
  • Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles.
  • Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards.

### Cloud Infrastructure & GCP Governance

  • Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries.
  • Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments.
  • Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT.

Requirements

  • Must be a U.S. Citizenship
  • Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
  • Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role.
  • Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals.
  • Must have hands-on working experience with Palo Alto NGFW and FortiGate firewalls, along with Cisco or equivalent routing and switching technologies.
  • Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus).
  • Must be familiar with configuration management, monitoring, and documentation tools.
  • Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions.
  • Must be familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy.
  • Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff.

### Preferred Qualifications

  • Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent.
  • Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred.
  • Familiarity with VoIP, secure mail flow, and endpoint management integration.
  • Experience contributing to IT/security-related project initiatives.
  • Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping.
  • Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments.
  • Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible.
  • Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts.
  • GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience.
  • Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred.
  • Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks.

Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

Required skills

  • bash
  • ansible
  • google cloud platform
  • microsoft azure
  • amazon web services
  • windows
  • python