Firewall Engineer
Role details
Job location
Tech stack
Job description
SDA Solutions is seeking an experienced Firewall Engineer to support a critical Department of Defense enterprise environment in Arlington, VA. The selected candidate will play a key role in designing, implementing, securing, and maintaining enterprise firewall and network security solutions supporting mission-critical operations.
This position is ideal for a hands-on engineer with extensive experience supporting complex enterprise networks, Palo Alto technologies, and secure DoD environments. The successful candidate will work closely with technical teams and government stakeholders to improve network security, optimize firewall performance, and ensure compliance with DoD cybersecurity requirements.
This position is 100% onsite in Arlington, VA, with occasional travel throughout the Washington Metropolitan area as required.
Primary Responsibilities Engineer, configure, maintain, and troubleshoot Palo Alto firewall infrastructure supporting enterprise operations. Identify security gaps, firewall misconfigurations, inefficient rule sets, and performance issues while recommending and implementing corrective actions. Optimize firewall policies and load balancing configurations to strengthen overall network security and performance. Provide Tier III engineering support for complex firewall and network security incidents. Maintain firewall hardware and software at vendor-supported versions and coordinate upgrades as necessary. Support Continuity of Operations (COOP) requirements for mission-critical environments. Perform recurring security assessments of enterprise firewalls and document findings with recommendations for remediation. Generate monthly reports on firewall health, network performance, and traffic utilization. Participate in root cause analysis and After Action Reports following operational events. Serve as a subject matter expert for Palo Alto technologies and provide technical guidance on architecture, design, and best practices. Collaborate with government customers to evaluate current network security architecture and recommend improvements. Support cybersecurity initiatives by identifying technology gaps and assisting with future security strategies. Participate in technical working groups and engineering meetings with government stakeholders. Ensure compliance with applicable DoD STIGs, DISA policies, JSIG requirements, and cybersecurity standards.
Requirements
Bachelor's degree and 8+ years of relevant experience. Additional years of directly related experience may be considered in lieu of a degree. Minimum 5 years of hands-on experience engineering and supporting Cisco and Palo Alto firewall environments. Strong working knowledge of: Panorama deployment and administration Panorama High Availability Templates and Template Stacks Centralized policy management and policy deployment Palo Alto routing configuration IPSec Site-to-Site VPN configuration and troubleshooting Palo Alto virtual firewalls in AWS Intrusion Prevention (IPS) Virtual Routers and Virtual Systems High Availability (HA) firewall deployments Experience supporting enterprise network security within high-security DoD environments. Strong troubleshooting and analytical skills. Excellent written and verbal communication skills. Required Certifications
Must possess a current DoD 8570 IAT Level II certification such as:
Security+ CE CySA+ CCNA Security, Active DoD Top Secret Clearance Ability to obtain and maintain TS/SCI Willingness to successfully complete and maintain a Counterintelligence (CI) Polygraph Preferred Qualifications Previous experience supporting DISA enterprise environments. Experience supporting large-scale DoD network infrastructure. Familiarity with cloud-hosted firewall deployments and hybrid enterprise environments. Experience working within ITIL and/or DevSecOps operational environments. Why SDA Solutions?