Lead Firewall Engineer
Abile Group, Inc.
Springfield, United States of America
5 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Shift work Languages
English Experience level
SeniorJob location
Springfield, United States of America
Tech stack
Microsoft Active Directory
Application Firewall
Systems Engineering
User Authentication
Configuration Management
Computer Security
Information Systems
Computer Networks
Internet Security
Intrusion Detection and Prevention
Kerberos (Protocol)
Network Security
Lightweight Directory Access Protocols (LDAP)
Network Architecture
Network Planning and Design
Network administration
OAuth
Public Key Infrastructure
Security Assertion Markup Language (SAML)
Transport Layer Security
Firewalls (Computer Science)
Juniper
Information Technology
BIG-IP Advanced Firewall Manager (AFM)
DODAF
Job description
- Serves as the focal point for all firewall tasks, operations, and projects.
- Leads, directs, and manages execution of all daily operations, troubleshooting, and maintenance activities of the NSS Boundary work center.
- Designs, implements, and manages security solutions using F5, Juniper SRX, and Palo Alto for project-based requirements.
- Ensures systems, devices, and application under your responsibility and span of control meet applicable STIG/SRG and organizational configuration baselines.
- Leads regular compliance evaluations and audits.
- Develops, oversees, maintains, and enforces configuration management processes, Standard Operational Procedures (SOPs), and other documentation as needed/required.
- Monitors platform performance, logs, software version(s), and configuration drift to identify and mitigate performance, compliance, and security issues.
- Develops and maintains network architecture diagrams, inventories, and licensing status for the various capabilities within the scope of the team.
- Provides written reports and oral briefings to contract and government leadership.
- Coordinates issues with the appropriate stakeholders to ensure task completeness and overall customer satisfaction.
- Provides recommendations on newly submitted customer requests.
- Evaluates and reports on new/emerging network/communication technologies to enhance capacity, performance and reliability of the network.
- Evaluates and recommends changes and/or technology upgrades to address performance, standardization and industry best practices.
- Conducts performance assessments, mentor, and coach personnel.
This position is 100% onsite in Springfield, VA.
Requirements
Clearance Required: TS/SCI with ability to obtain and maintain a CI poly.
Degree and Years of Experience: BS or MS degree in Computer Science, Cyber Security, Network Security or related field.
- 8+ years related technical experience network security technologies, tools, and techniques.
- 5+ years' experience with large-scale enterprise/global networks in a high paced diverse environment.
Required Certifications:
- S6DoD 8140.01 and DoD 8570.01-M IAT Level II compliant certification (current). Must be able to successfully obtain/maintain CSSP Infrastructure Support certification within 120 days.
Desired Certifications:
- F5 Networks certifications., * Understanding and experience with the DoD Architecture Framework and other key DoD network architecture and strategic planning instructions.
- Demonstrated knowledge in planning, directing, and managing a Firewall / Boundary Security Team in an organization similar in size.
- Firewall experience within the DoW or IC.
- Demonstrated knowledge of implementation of Perimeter and Internal Firewalls (both physical and virtual contexts)
- Demonstrated advanced experience in managing baseline configurations across numerous firewalls.
- Demonstrated advanced experience in evaluating rules to ensure maximum security while minimizing redundancy and processing overhead.
- Demonstrated experience with researching and fielding new and innovative firewall technology.
- Experience with F5 platforms/technologies (APM, AFM, SSLO, etc.)
- Experience with Palo Alto platforms/technologies (Threat Prevention, Wildfire, URL Filtering, Global Protect)
- Experience with Juniper SRX platforms/technologies.
- Experience with Online Certificate Status Protocol OCSP revocation.
- Familiar with DoD PKI, Kerberos, LDAP, Active Directory, Authentication (SAML, OAuth)
- Ability to describe and troubleshoot TLS/SSL handshake/connection issues.
- Network design, engineering, and implementation (Advanced Level)
- Creation of network related Rough Order Magnitude (ROM) equipment lists and costing, Level of Effort (LOE) estimation for labor.
- Understanding of DoW, DISA, and IC standards and processes.
- Ability to work weekends and evening hours as needed.
Desired Skills:
- Juniper JNCIS/JNCIP, Palo Alto PCNSE (or equivalent), Authentication, Best Practices, Coaching, Community Support, Computer Science, Configuration Management, Construction Support, Customer Satisfaction, Defense Information Systems Agency (DISA), Department of Defense Architecture Framework (DoDAF), Documentation, F5 Network Software, Federal Government, Fire Prevention, Firewall Administration, Firewalls, Government Contracts, Identify Issues, Industry Standards, Information Technology & Information Systems, Integrated Circuits (ICs), Intelligence Community, Internet Security, Juniper Networks Product Family, Kerberos, LDAP (Lightweight Directory Access Protocol), Leadership, Licensing, Mentoring, Microsoft Active Directory, Network Administration/Management, Network Architecture/Engineering, Network Design, Network Security, OAuth, Operations, Operations Processes, People Management, Performance Analysis, Performance Reviews, Project/Program Management, Public Key Infrastructure (PKI), Reporting Skills, Research Skills, SSL-TLS (Secure Socket Layer - Transport Layer Security), Sales/Support Engineering (SE), Security Assertion Markup Language (SAML), Security Compliance, Security Monitoring, Sensitive Compartmented Information (SCI), Standard Operating Procedures (SOP), Strategic Planning, Systems Engineering, Technical/Engineering Design, Top Secret Clearance, United States Department of Defense (DoD)
About the company
Abile Group has an exciting and challenging opportunity for a Lead Firewall Engineer on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission., About Abile Group, Inc.:
Abile Group, founded in July 2004 to support the Intelligence Community and its contractors across Enterprise Analytics, IT & Systems Engineering, and Program & Project Management, merged with Valiant Solutions in January 2026 - an established provider of cybersecurity technologies and services for Federal Agencies since 2005. Together, this partnership creates a stronger, more integrated cybersecurity organization with expanded opportunities for employees, deeper technical collaboration, and a unified mission. With significant experience serving the Federal Government, we remain dedicated to our employees and clients and seek high-performing professionals who excel at providing guidance, developing solutions, and delivering implementation support that blends industry best practices with client expertise and Abile's broad technical capabilities.
Hiring Statement