Network Security Engineer at Credence — McLean, VA
Full job description
Overview
Position Summary
Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset
### Responsibilities:
### Network Infrastructure & Operations
- Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management.
- Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity.
- Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government).
- Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process.
- Oversee network configuration management and backups to ensure recoverability and business continuity.
- Analyze and resolve escalated Tier 2+ network support tickets.
- Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning
### Security & Compliance
- Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation.
- Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions.
- Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening).
- Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed.
- Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles.
### Collaboration & Support
- Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments.
- Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes.
- Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions.
- Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles.
- Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards.
### Cloud Infrastructure & GCP Governance
- Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries.
- Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments.
- Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT.
Requirements
- Must be a U.S. Citizenship
- Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
- Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role.
- Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals.
- Must have hands-on working experience with Palo Alto NGFW and FortiGate firewalls, along with Cisco or equivalent routing and switching technologies.
- Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus).
- Must be familiar with configuration management, monitoring, and documentation tools.
- Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions.
- Must be familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy.
- Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff.
### Preferred Qualifications
- Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent.
- Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred.
- Familiarity with VoIP, secure mail flow, and endpoint management integration.
- Experience contributing to IT/security-related project initiatives.
- Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping.
- Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments.
- Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible.
- Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts.
- GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience.
- Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred.
- Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks.
Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications.
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Family Leave (Maternity, Paternity)
- Short Term & Long Term Disability
- Training & Development
- Wellness Resources
Required skills
- bash
- ansible
- google cloud platform
- microsoft azure
- amazon web services
- windows
- python