> Markdown version of [/jobs/ext/2946925-senior-firewall-engineer-sme-team-lead](https://www.wearedevelopers.com/jobs/ext/2946925-senior-firewall-engineer-sme-team-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Firewall Engineer/SME - Team Lead - **Company:** GCyber, LLC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cisco PIX, CompTIA Security+, Software Design Patterns, Network Address Translation, Data-Flow Analysis, Intrusion Detection Systems, Network Security, Routing, Packet Analyzer, Security Information and Event Management, Data Logging, Load Balancing, System Availability, Firewalls (Computer Science), Juniper, Performance Monitor, Firepower, Firewall Services Module, NetScreen, Cisco - **Published:** September 16, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9165894/senior-firewall-engineersme-team-lead ## About the Role * Active DoD TS/SCI clearance * DoD 8140 IAT II certification (i.e., Security+, CCNA-Security, CySA+, CND, GICSP, GSEC, SSCP) * Industry Firewall Certification (CCNP, Palo Alto, Juniper, etc.) * BA/BS degree or equivalent experience * Minimum 7 years experience engineering, administering, and troubleshooting enterprise firewall environments, with at least 3 years in DoD enterprise environments * Experience leading firewall engineers, network security personnel, or a comparable technical team. * Advanced knowledge of firewall architecture, security zones, DMZs, access-control policies, routing, NAT, high availability, traffic inspection, logging, and packet analysis. * Experience evaluating and optimizing complex firewall rulesets. * Experience leading major firewall changes, platform migrations, security assessments, and complex incident resolution. * Hands-on experience with Cisco ASA and Cisco Firepower technologies. * Familiarity with FireMon, Stealthwatch, enterprise SIEM capabilities, and load balancer technologies. * Working knowledge of DoD STIGs, NIST guidance, PPSM requirements, and formal Government change-management processes. * Experience supporting classified networks and mission-critical operational environments. * Strong leadership, technical writing, documentation, and customer communication skills. * Ability to provide after-hours emergency support when required. Preferred Qualifications * Experience supporting the Pentagon, DISA, or another large DoD enterprise environment. * Experience with Juniper NetScreen and Cisco PIX configuration cleanup and migration. * Relevant firewall, networking, or cybersecurity certifications. ## Description GCyber is seeking a Senior Firewall Engineer / Subject Matter Expert and Team Lead to support the J6 Pentagon enterprise. This hands-on leadership role is responsible for leading a team of firewall engineers and administrators while serving as the senior technical authority for firewall architecture, security assurance, operations, troubleshooting, and modernization across classified and unclassified environments. The ideal candidate combines deep enterprise firewall expertise with the leadership, judgment, and communication skills required to manage priorities, mentor technical staff, resolve complex issues, and work directly with Government customers and stakeholders. As the Senior Firewall Engineer, you will: * Lead a team of firewall engineers and administrators: assign and prioritize daily work, review peer configurations before implementation, and mentor junior staff on design patterns and troubleshooting methodology. * Serve as the technical authority for enterprise firewall architecture, including boundary design, security zone segmentation, high-availability pairs, and integration with routing, IDS/IPS, proxy, and remote-access infrastructure. * Own the firewall change-management process end to end, including validating rule requests, assessing risk and least-privilege impact, coordinating required Government and Risk Management approvals, and overseeing implementation and post-change verification. * Maintain rule base hygiene through recurring assessments by identifying and remediating shadowed, expired, duplicate, conflicting, and overly permissive rules. * Act as the final escalation point for complex connectivity and performance issues, using packet captures, session and traffic-flow analysis, and log correlation to isolate faults across the network path. * Manage firewall platform lifecycle activities, including upgrades, patching, failover testing, performance monitoring, and planning and executing end-of-life hardware migrations. * Ensure firewall configurations meet applicable STIG, NIST, PPSM, DISA, NSA, and organizational security requirements and produce supporting artifacts for assessments and accreditation activities. * Lead the configuration, migration, integration, and monitoring of Cisco ASA and Firepower platforms and associated FireMon, Stealthwatch, and enterprise SIEM capabilities. * Author and maintain SOPs, assessment reports, After Action Reports, change records, logical configuration diagrams, and other technical documentation required to support secure and consistent operations. * Interface directly with the Government customer and stakeholder teams on requirements, status reporting, metrics, outage communications, and long-range technical roadmap input. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)