Credence Management Solutions
Posted 1mo ago

Network Security Engineer

Credence Management Solutions
McLean, Virginia, United States
$130k-$155k/yrOnsiteFull Time
Responsibilities
  • managing network
  • administering firewalls
  • maintaining compliance
Requirements
  • U.S. citizen with Bachelor's or equivalent
  • 5+ years network engineering experience
  • Hands-on Palo Alto and FortiGate firewall administration
  • GCP org governance
  • Cloud networking
  • Windows and enterprise networking knowledge
  • Documentation and compliance experience
Technical tools mentioned
Palo Alto NGFWPalo Alto VM-SeriesFortiGate VMNessusCiscoArubaUbiquitiPRTG Network MonitorNetBoxAnsibleGCPCloud RouterCloud NATWorkload Identity Federation (WIF)OIDCAWS CommercialAzure Government (GCC High)Microsoft 365PythonBash

Job description

At Credence, we support our clients’ mission-critical needs, powered by technology. We provide cutting-edge solutions, including AI/ML, secure cloud, digital transformation, and advanced intelligence capabilities, to the largest defense, health, and international development federal organizations. Through partnership and trust, we increase mission success for warfighters and secure our nation for a better future. We are privately held, are repeatedly recognized as a top place to work, and have been on the Inc. 5000 Fastest Growing Private Companies list for the last 12 years. We practice servant leadership and believe that by focusing on the success of our clients, team members, and partners, we all achieve greater success.

Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset

Responsibilities:

Network Infrastructure & Operations

  • Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management.
  • Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity.
  • Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government).
  • Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process.
  • Oversee network configuration management and backups to ensure recoverability and business continuity.
  • Analyze and resolve escalated Tier 2+ network support tickets.
  • Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning

Security & Compliance

  • Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation.
  • Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions.
  • Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening).
  • Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed.
  • Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles.

Collaboration & Support

  • Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments.
  • Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes.
  • Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions.
  • Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles.
  • Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards.

Cloud Infrastructure & GCP Governance

  • Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries.
  • Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments.
  • Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT.

Requirements

  • Must be a U.S. Citizenship
  • Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
  • Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role.
  • Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals.
  • Must have hands-on working experience with Palo Alto NGFW and FortiGate firewalls, along with Cisco or equivalent routing and switching technologies.
  • Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus).
  • Must be familiar with configuration management, monitoring, and documentation tools.
  • Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions.
  • Must be familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy.
  • Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff.

Preferred Qualifications

  • Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent.
  • Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred.
  • Familiarity with VoIP, secure mail flow, and endpoint management integration.
  • Experience contributing to IT/security-related project initiatives.
  • Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping.
  • Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments.
  • Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible.
  • Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts.
  • GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience.
  • Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred.
  • Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks.

 

Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications.

Please join us, as together we build a better world one mission at a time powered by Technology and its People!

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

About Credence Management Solutions

AI-native federal services.

Similar jobs

Network Security Engineer roles near McLean, Virginia
2d
Save
Mark Applied
Hide
Network Security Engineer
Reston or Destin
OnsiteFull Time
Titan Technologies
Titan Technologies: Privately held U.S. IT provider delivering managed IT, systems integration, AI/data solutions, and contact centers to agencies.
10+ YOERequires 10 years of network engineering experience, 3 years deploying security products, networking technology proficiency, a qualifying Cisco certification, bachelor's degree or equivalent, and Public Trust clearance eligibility.
Security Event Management, ForeScout, Tenable.io, CrowdStrike, DbProtect, Splunk, CISCO ISE, IDS, IPS, Burp Suite, Microsoft SCCM, PortSwigger Burp Suite, Fortify, Cisco Nexus, FlexPod, IOS, Identity Services Engine (ISE), StealthWatch, FirePOWER, Cisco Prime, Orion SolarWinds, NIST Special Publication 800
2w
Save
Mark Applied
Hide
Palo Alto Network Security Engineer
Fort Belvoir or Maryland
$90k-$160k/yr OnsiteFull Time
Sedulous Consulting Services
Sedulous Consulting Services: Veteran-owned cybersecurity and IT consulting firm serving government agencies, defense contractors, and commercial organizations.
3+ YOERequires 3–5+ years of network or security engineering experience, 2+ years of Palo Alto NGFW/PAN-OS experience, active Palo Alto certification, and TS/SCI clearance.
Palo Alto Networks Next-Generation Firewalls (NGFWs), PAN-OS, App-ID, User-ID, GlobalProtect, VPN/IPsec, High Availability (HA), Panorama, Strata Cloud Manager, ACAS/Nessus, Risk Management Framework (RMF), DISA, Microsoft?
2w
Save
Mark Applied
Hide
Network Security Engineer
Chantilly, Virginia, United States
$104k-$173k/yr OnsiteFull Time
ManTech International
ManTech International: Advancing the future of defense through innovative technology.
7+ YOERequires 7+ years in network security engineering or related technical work, CCNA or equivalent, DoD IAT II and IAT III certifications, and active TS/SCI clearance.
SolarWinds, Cisco Firepower FMC, Cisco ISE, Microsoft Windows, HP SANs, VMware, VPN, GRE, BGP, OSPF, VLANs, VRFs, Cisco ACI, Ansible, Desired State Configuration (DSC), Cisco Secure Firewall, BICSI, Cat 5, NSTISSAM TEMPEST/2-95, CNSSAM TEMPEST/01-13, ITIL
3w
Save
Mark Applied
Hide
Senior Network Security Engineer (Network Engineering, Associate)
Washington, District of Columbia, United States
$101k-$151k/yr OnsiteFull Time
The MIL Corporation
The MIL Corporation: Private U.S. government-services contractor providing federal agencies cyber, engineering, financial, and information-technology services.
8+ YOE8+ years enterprise networking experience with 5+ years Cisco hands-on; experience in network security, segmentation, 802.1X, VPNs, firewall administration, monitoring/SIEM, vulnerability remediation, incident response, and NIST/Zero Trust implementation.
Cisco, Cisco Identity Services Engine (ISE), SIEM, Microsoft
3w
Save
Mark Applied
Hide
Network Security Engineer
Denver or Washington or Chicago
$98k-$160k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Global financial services and banking institution.
5+ YOE5+ years hands-on BGP experience, NetScout Arbor and DDoS mitigation, cloud network security with Akamai/Cloudflare, WAF configuration, strong technical and stakeholder management skills.
BGP, NetScout Arbor, Akamai, Cloudflare, Web Application Firewall (WAF)
1mo
Save
Mark Applied
Hide
NETWORK SECURITY ENGINEER LEVEL 3
Fort Meade, Maryland, United States
OnsiteFull Time
EOA Technologies
EOA Technologies: Privately held IT, cybersecurity, cabling, and infrastructure consulting firm serving commercial, federal, and intelligence organizations.
17+ YOEActive TS/SCI with Polygraph, 17 years network security engineering experience, DoD 8570 IAT Level III, vendor certifications (PCNSA, SNSA/SNSP, ProxySG, CCNA), bachelor\u0002s in related field or equivalent experience.
1mo
Save
Mark Applied
Hide
Network Security Engineer (Zscaler)
Arlington, Virginia, United States
$140k-$165k/yr OnsiteHybrid
UltraViolet Cyber
UltraViolet Cyber: UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients.
10+ YOEUS citizen with Top Secret or DHS clearance preferred, 10+ years network/security engineering experience, Bachelor's degree, deep Zscaler suite and cloud experience, strong network and scripting skills.
Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), Zscaler Digital Experience (ZDX), Zscaler Client Connector (ZCC), Azure, AWS, GCP, SD-WAN, Linux, Windows, API
1mo
Save
Mark Applied
Hide
Network Security Engineer
Denver or Washington or Chicago
$98k-$160k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Global financial services and banking institution.
5+ YOE5+ years hands-on BGP experience, NetScout Arbor and DDoS mitigation, cloud network security (Akamai/Cloudflare), WAF experience preferred; strong technical, stakeholder, and testing skills.
BGP, NetScout Arbor, Akamai, Cloudflare, Web Application Firewall (WAF)