> Markdown version of [/jobs/ext/1093430-campus-wan-firewall-engineer-multi-vrf-focus](https://www.wearedevelopers.com/jobs/ext/1093430-campus-wan-firewall-engineer-multi-vrf-focus). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Campus & WAN Firewall Engineer (Multi-VRF Focus) - **Company:** Arion Systems Inc - **Location:** Chantilly, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Firewall, Border Gateway Protocol, Cisco IOS, Cyber Security, System Configuration, Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Multi-protocol Systems, Junos, Python (Programming Language), Network Security, Network Control, Network Connections, Routing, Packet Analyzer, Open Shortest Path First (OSPF), Ansible, Zero Trust Network Access, Security Information and Event Management, Tcpdump, Traffic Analysis, Wireshark, Encapsulation (Networking), Wide Area Networks, Data Logging, Dynamic Routing, Transport Layer Security, Network Access Control, Computer Network Operations, Firewalls (Computer Science), Juniper, Information Technology, Palo Alto Networks, Routing & Switching, Firewall Services Module, Terraform, Open Network Automation Platform, Splunk, Cisco - **Published:** June 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9004527/campus-wan-firewall-engineer-multi-vrf-focus ## About the Role Clearance: TS//SCI with CI Poly preferred Education: Bachelor's degree in Computer Science, Cybersecurity, Network Engineering, Information Technology, or a related technical field; or an equivalent combination of education and professional experience. Experience: 5-8 years of specialized enterprise networking experience focused heavily on firewall administration, WAN engineering, and multi-tenant segmentation. Mandatory Professional-Level Certification Requirement: Must hold at least one of the following professional certifications: Palo Alto Networks Certified Network Security Engineer (PCNSE) or Palo Alto Networks Certified Network Security Professional (PCNSP). Forcepoint Next Generation Firewall (NGFW) System Engineer or Forcepoint NGFW Advanced Network Operations Specialist. Required Technical Skills: Routing & Switching: Expert-level knowledge of advanced routing mechanics over WAN environments, including VRF-lite, MPLS, MP-BGP, OSPF, and strict path-isolation techniques. Hardware Interfacing: Hands-on competency configuring, monitoring, and operating Juniper Junos OS or Cisco IOS/IOS-XE/NX-OS routing environments alongside enterprise security appliances. Security Toolsets: Deep technical command over Intrusion Detection/Prevention Systems (IDS/IPS), Network Access Control (NAC), SSL decryption, and granular application identification policies. Diagnostics: Advanced proficiency using Wireshark, tcpdump, and enterprise logging fabrics (e.g., Splunk, Panorama, Forcepoint SMC) to trace packet flow across multi-layered routing zones. Preferred Qualifications Professional-level Cisco or Juniper networking certifications (e.g., CCNP Enterprise, JNCIP-ENT, JNCIP-SP). Experience utilizing Network Automation frameworks (such as Ansible, Python, PyEZ, or Terraform) to programmatically audit, manipulate, and deploy broad firewall policies and routing statements uniformly across a global WAN topology. ## Description The Campus & WAN Firewall Engineer is a senior-level security routing and infrastructure specialist responsible for the architectural design, implementation, and steady-state optimization of network security controls across a large-scale Wide Area Network (WAN) and enterprise campus environment. This role specializes in managing high-throughput firewall deployments that enforce zero-trust boundary controls across heavily segmented networks containing numerous Virtual Routing and Forwarding (VRF) instances. The ideal candidate bridges the gap between deep network engineering and advanced perimeter defense, possessing extensive hands-on experience interfacing enterprise firewalls with Juniper or Cisco routing platforms via dynamic routing protocols. The engineer ensures that security boundaries are strictly maintained without compromising high-performance WAN throughput, resiliency, or enterprise-grade network availability. Essential Duties and Responsibilities Multi-VRF & WAN Security Architecture: Design, configure, and maintain Next-Generation Firewall (NGFW) policies mapped across highly complex, multi-tenant network infrastructures utilizing multiple VRFs and secure logical systems. Routing infrastructure Integration: Establish, troubleshoot, and optimize secure dynamic routing adjacencies (including BGP, OSPF, and MP-BGP) directly between security appliances and Juniper or Cisco core/edge routers. Perimeter Policy & Rule Engineering: Construct, audit, and systematically prune centralized firewall rule sets, complex NAT pools, and advanced security profiles to prevent inter-VRF leakage while enabling legitimate cross-boundary application traffic. Enterprise Security Platform Management: Oversee the lifecycle management, patching, and policy deployment of distributed Forcepoint and Palo Alto firewall estates utilizing vendor centralized management systems. Advanced Traffic Analysis & Inter-VRF Troubleshooting: Perform high-level packet analysis, deep-packet inspections (DPI), and trace-route diagnostics across complex transit VRFs to isolate and resolve advanced network connectivity, performance drops, or asymmetric routing anomalies. Secure Encapsulation & Tunneling: Architect and maintain scalable, high-throughput site-to-site VPN networks, GRE tunnels, and IPsec implementations over the WAN fabric to safeguard remote locations and critical datalink infrastructures. Vulnerability & Compliance Audits: Ensure the perimeter defense framework complies with strict federal and organizational guidelines, leading efforts in security posture audits, config hardening, and log delivery configurations into SIEM engines. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Demystifying application networking in the cloud](https://www.wearedevelopers.com/videos/675-demystifying-application-networking-in-the-cloud) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)