Network Security Engineer - Firewalls, DNS Security, IPS (REMOTE)

Ferguson Enterprises Inc.
Richmond, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$65,337.0 - $114,444.0
Working hours
Regular working hours
Job source

Tech stack

Border Gateway Protocol Cyber Security DDoS Mitigation Domain Name System Security Extensions Intrusion Detection and Prevention Virtual Private Networks (VPN) Network Security Wireless Security Routing Network Segmentation Systems Development Life Cycle Akamai
+10 more
Value Engineering Wide Area Networks Transport Layer Security In-Plane Switching (IPS) Firewalls (Computer Science) Information Technology Palo Alto Networks Enterprise Integration Firewall Services Module Cisco

Job description

  • Operation and administration of global Network Security platforms supporting enterprise and data center environments.
  • Act as a technical authority and support point for complex network security issues involving customer concerns impacting enterprise, data center, and hybrid environments.
  • Drive secure-by-design outcomes by partnering with Architecture, Infrastructure, SOC/NOC, and Application teams to influence designs, standards, and implementation approaches.
  • Ensure network security services are reliable, scalable, well-documented, and aligned with business and risk objectives.
  • Contribute to the evolution of network security capabilities through technology evaluation, service enhancement, and process optimization.
  • Engineer, administer, and optimize next-generation firewall environments, including security policy management, network segmentation, intrusion prevention, and SSL/TLS decryption.
  • Administer and enhance DNS security services, including policy design, threat protection, and reporting.
  • Lead or support the deployment and operation of SD-WAN security controls, wireless intrusion prevention, and DDoS protection platforms.
  • Develop and execute security test plans based on architectural designs; identify deficiencies and implement improvements while minimizing production impact.
  • Serve as a subject-matter expert for firewall, DNS security, SD-WAN, and related network security technologies.
  • Respond to security incidents, service requests, and escalations, ensuring resolution within defined service levels.
  • Create and maintain runbooks, operational documentation, and workflows to improve consistency, reliability, and operational maturity.
  • Support mergers and acquisitions through network security assessments, discovery activities, remediation planning, and secure integration design.
  • Advocate for new or enhanced network security services and contribute technical requirements to technology selection and evaluation processes.
  • Drive operational efficiencies and automation that enable the team to focus on higher-value engineering work.
  • Deliver assigned initiatives on time and in alignment with service level expectations.
  • Adhere to all applicable policies, standards, and procedures, and perform other duties as assigned by management.

Requirements

  • Bachelor’s degree in computer science, Information Security, MIS, or a related field, or equivalent practical experience.
  • 4 - 7 years of hands-on experience in network security engineering within large enterprise environments.
  • Demonstrable experience managing and operating large-scale next-generation firewall policies for complex enterprises; experience with Palo Alto Networks Panorama and/or Versa Director preferred (other NGFW platforms considered).
  • Strong practical experience with DNS security (Cisco & Palo Alto Networks), DDoS protection (Akamai Prolexic), wireless security (Cisco Meraki), VPNs, and SD-WAN technologies.
  • Deep understanding of network and web protocols, routing (e.g., BGP), firewall architectures, intrusion prevention, and network segmentation.
  • Experience supporting enterprise security assessments, remediation efforts, and modernization initiatives.
  • Strong analytical and troubleshooting skills, with the ability to resolve sophisticated, ambiguous problems.
  • Excellent written and verbal communication skills, including the ability to explain technical concepts to non-technical audiences.
  • Demonstrated ability to work independently, take initiative, and provide technical leadership through mentoring, documentation, and fostering collaboration.
  • Certifications are not required but are valued (e.g., CCNA, SSCP, CISSP).
  • Working understanding of the SDLC and QA lifecycle, and how network security integrates into modern delivery practices.
  • Demonstrated integrity, curiosity, adaptability, and a strong customer-focused approach.

Benefits & conditions

Paid parental leave, Parental leave, Health insurance, 401(k) matching, Paid time off, Vision insurance, Dental insurance, Life insurance, At Ferguson, we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!, Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience.

$5,444.76 - $9,537.00

Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles.

This role is Bonus or Incentive Plan eligible.

Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.

The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability. Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/Sexual Orientation/Gender Identity. Equal Employment Opportunity and Reasonable Accommodation Information

About the company

Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.

The Network Security Engineer - Firewalls, DNS Security, IPS role is a key part of our Network Security Team, focused on making sure only trusted users and traffic can access our enterprise networks. In this hands-on technical role, you’ll help operate and improve the security platforms that protect our global environment - including firewalls, intrusion prevention, DNS security, wireless security, and DDoS protection. You’ll work across all operating companies to solve complex issues, strengthen our security posture, and enhance the reliability and performance of our network services. This role is ideal for someone who enjoys tackling undefined problems, improving processes, and partnering with teams to drive secure-by-design outcomes.

AREAS OF IMPACT: Establishes service-oriented relationship patterns, for service delivery across all operating companies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil Ā· LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark Ā· LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos Ā· LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas Ā· Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

Videos

See all

Related articles

See all