# Senior Network Security Engineer

> TOMORROW HIRE · Mechanicsville, United States (Hybrid) · Contract · Posted 2026-07-31

**Workplace:** hybrid

**Department:** Information Technology

## Description

**Job Title**: Senior Network Security Engineer  
**Work Type**: Hybrid  
**Location**: Mechanicsville, VA  
**Start Date**: 08/03/2026  
**End Date**: 06/30/2027  
**Industry Category**: Information Technology / Government  
**Employment Type**: 1099 Contract  
**Requisition ID**: 807471

### Overview

We are seeking an experienced Senior Network Security Engineer to implement, secure, and support the agency's enterprise network, cloud, and computing infrastructure. This position plays a critical role in protecting a hybrid enterprise environment spanning approximately 300 statewide locations while ensuring the confidentiality, integrity, and availability of mission-critical systems and public-facing applications. The successful candidate will collaborate closely with Infrastructure, Cloud Engineering, and the Information Security Office to strengthen VDOT's cybersecurity posture across on-premises and Azure environments.

### Application

Applications will be reviewed as received.

Candidates must:

-   Physically reside within the United States for the duration of the assignment.
-   Be legally authorized to work in the United States without employer sponsorship, now or in the future.
-   Be available to attend an in-person interview.
-   Meet all required technical qualifications listed below.

### Job Description

The Senior Network Security Engineer is responsible for securing, designing, documenting, researching, implementing, and supporting VDOT's enterprise network and computing infrastructure. This role supports a large-scale hybrid environment that includes Palo Alto firewalls, Azure networking, ExpressRoute connectivity, Web Application Firewalls (WAF), Splunk SIEM, SD-WAN technologies, and mission-critical public-facing applications. The engineer will lead security initiatives, respond to incidents, perform proactive threat hunting, and ensure network security architecture aligns with agency standards and best practices.

### Responsibilities

### Technical Duties

-   Design, implement, and maintain secure network architectures across on-premises and Microsoft Azure environments.
-   Ensure network security architecture complies with operational security standards before and after deployment.
-   Lead investigations, containment, and resolution of network security incidents.
-   Review firewall rule requests and validate compliance with established security standards.
-   Monitor security events using SIEM platforms and coordinate incident response activities.
-   Conduct proactive threat hunting and anomaly detection across enterprise environments.
-   Perform network security assessments and recommend remediation strategies.
-   Identify, prioritize, and remediate network security vulnerabilities.
-   Support penetration testing initiatives and remediation efforts.
-   Validate Web Application Firewall (WAF) and firewall placement, integration, and connectivity.
-   Lead implementation, review, and ongoing management of agency WAF solutions.
-   Diagnose security threats using system logs, SIEM platforms, diagnostic tools, monitoring utilities, and test equipment.

### Documentation & Security Governance

-   Develop and maintain network security standards and operational documentation.
-   Produce and maintain network architecture diagrams, IP addressing schemes, firewall rule documentation, and access control records.
-   Ensure documentation accurately reflects enterprise security configurations and operational procedures.

### Collaboration

-   Partner with Infrastructure, Cloud Engineering, and Information Security teams to maintain secure enterprise operations.
-   Communicate technical issues effectively to both technical teams and executive leadership.
-   Mentor junior engineers and provide technical guidance on security best practices.

### Operational Support

-   Support a hybrid enterprise environment consisting of approximately 300 statewide locations.
-   Participate in on-call support during critical security incidents.
-   Independently manage assigned projects while maintaining operational excellence.

## Requirements

### Minimum Qualifications

-   Minimum 8 years of enterprise networking experience.
-   Minimum 5 years of enterprise security experience.
-   Minimum 3 years of Azure networking experience.
-   Minimum 3 years of WAF/Next-Generation Firewall (NGFW) experience.
-   Experience with incident response, security investigations, log analysis, threat intelligence, and security monitoring.
-   Experience with SIEM platforms such as Splunk or Microsoft Sentinel.
-   Experience with vulnerability management, remediation tracking, and vulnerability scanning tools such as Nessus, Tenable, or similar solutions.
-   Experience with Active Directory, Multi-Factor Authentication (MFA), Conditional Access, and certificate management.
-   Experience applying SEC530 guidance, CIS Benchmarks, NIST Cybersecurity Framework (CSF), NIST 800-53, and Zero Trust principles.
-   Experience with Cisco ISE, Network Access Control (NAC), 802.1X, ccExperience with Palo Alto, F5 Distributed Cloud, Azure WAF, Cisco VPN, GlobalProtect, and F5 BIG-IP technologies.
-   Experience supporting highly regulated environments and leading technical troubleshooting during production outages.
-   Demonstrated ability to communicate technical concepts to technical and executive audiences.
-   Ability to mentor junior engineers.
-   Azure Security Engineer (AZ-500), Azure Network Engineer (AZ-700), or the ability to achieve these certifications.
-   Must physically reside within the United States for the duration of the assignment.
-   Must attend an in-person interview.
-   Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

### Preferred Qualifications

-   Minimum 3 years of experience supporting enterprise environments with more than 300 network devices.

## Benefits

### Compensation

This is a **1099 Contract** position.

**Pay Rate:** **$69 - $89 per hour**

### Schedule

-   **Start Date:** August 3, 2026
-   **End Date:** June 30, 2027
-   **Assignment Duration:** Approximately 11 months
-   Hybrid work arrangement.
-   Participation in on-call support during critical security incidents is required.

### Work Location

**Worksite Address:**

Mechanicsville, VA

-   Hybrid work arrangement with onsite presence as required.
-   In-person interview is mandatory.

## Apply

[Apply at TOMORROW HIRE](https://apply.workable.com/tomorrow-hire/j/AA2A77A0DA/apply)

---
Powered by [Workable](https://www.workable.com)
