> Markdown version of [/jobs/ext/3336071-network-security-engineer](https://www.wearedevelopers.com/jobs/ext/3336071-network-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Engineer - **Company:** Valiant Solutions, LLC - **Location:** Silver Spring, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, IEEE 802.1X, Microsoft Windows, Access Control List, Access Network, Active Directory, Apple Mac Systems, Profiling, Cyber Security, Information Systems, IPv6, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Network Security, Lightweight Directory Access Protocols (LDAP), Public Key Infrastructure, Remote Access Technology, Zero Trust Network Access, Web Content Accessibility Guidelines, Privacy Controls, Identity Services Engine, Network Access Control, Firewalls (Computer Science), Information Technology, Routing & Switching, Firepower, PSN, Cisco - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5effff67bc0cb3e2 ## About the Role * Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or a related technical field. Four (4) additional years of specialized experience may be substituted for a Bachelor's degree. * 6 years of dedicated experience in network security engineering and infrastructure protection. * Hands-on experience taking a Cisco ISE deployment from partial configuration to enforced enterprise-wide 802.1X. * Experience operating a production firewall fleet in an environment with defined availability standards. * Cisco Identity Services Engine administration, including distributed PAN, MnT, PSN, and pxGrid node topologies. * 802.1X, RADIUS, MAB, and certificate-based authentication in mixed Windows and macOS environments. * Endpoint posture assessment with AnyConnect and Cisco Secure Client. * Cisco TrustSec design using Security Group Tags and Security Group Access Control Lists. * Cisco Firepower Threat Defense and Firepower Management Center administration, including intrusion prevention tuning. * Remote access and site-to-site VPN engineering with posture integration and machine certificate enforcement. * PKI concepts as they apply to machine and user certificate validation. * Switching and routing fundamentals sufficient to troubleshoot access-layer authentication failures end to end. Preferred Certifications * Cisco Certified Network Professional (CCNP) Security, Certified Information Systems Security Professional (CISSP), or CompTIA Security+., * Written and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders. * Ability to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation. * Clear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs. * Ability to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records. ## Description Network Access Control and Identity * Review and validate the existing Cisco ISE configuration, document the gaps, and deliver the remediation design within the first 90 days of performance. * Configure and enforce 802.1X authentication for Government Furnished Equipment across the enterprise access layer. * Integrate ISE with Active Directory and LDAP, and enforce HSPD-12 compliant authentication using CAC or Yubikey credentials. * Build authorization policy that restricts service access to authenticated users and locks accounts after three consecutive failed login attempts. * Onboard network access devices into ISE in a phased sequence that protects availability while raising enforcement coverage., * Configure the ISE profiling engine to discover, identify, and monitor every endpoint on the network. * Deploy and tune AnyConnect and Cisco Secure Client posture agents on both Windows and macOS endpoints. * Implement posture checks that validate antivirus and antimalware status, host firewall state, and operating system patch level before access is granted. * Develop remediation policy with the government security team so that non-compliant endpoints are quarantined and returned to service predictably. * Report posture metrics monthly, including the count of devices denied access for failing compliance checks., * Deploy and manage remote access and site-to-site VPN services, including concentrator configuration and capacity management. * Enforce posture validation before a remote client is authorized onto the network. * Implement machine certificate validation and equivalent technical controls that restrict client-based VPN access to Government Furnished Equipment only. * Prepare Methods of Procedure for every security configuration change and carry them through the Change Control Board. * Participate in the 24x7x365 on-call rotation, responding to Priority 1 incidents within 15 minutes., * Working knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07. * Familiarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection. * Understanding of HSPD-12 identity credentialing and its enforcement in network access decisions. * Awareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables. * Experience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria. * Willingness to complete required customer training, including annual cybersecurity awareness, records management, privacy, safety, and harassment prevention training. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [IoT: The road to sustainability](https://www.wearedevelopers.com/videos/557-iot-the-road-to-sustainability) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)