One of our Austin client is looking to add a Firewall Engineer to their growing team.
The preferred candidate will have a total of 10 years' experience in the Information Technology/ Information Security industry, with minimum of 5 years of experience as a Security Engineer configuring and maintaining Network Security technologies. Candidate should have strong communications skills, both written and verbal, be comfortable presenting information to teammates, customer technical personnel and Managers.
This is an engineer role and the candidate must be able to demonstrate ability to install, manage and maintain Firewalls in both on-premise and cloud environments. Demonstrated experience in supporting CISCO Firewalls as an engineer is REQUIRED. Holding one or more CISCO Security Certifications is REQUIRED. Holding one or more vendor-neutral security certifications (e.g., Security +, CISM, CISSP) is a plus for this position.
This position is based in AUSTIN, TX, and will support the customer's 24x7 Security Operations Center (SOC).
10 Years experience in IT
- Vendor certifications such as CCNP or Fortinet Network Security Expert Level 4 or better are desirable.
- Other industry certifications such as CISSP, GCIH, CEH, etc. are a plus.
- Ability to configure, deploy, and troubleshoot Cisco and Fortigate Firewall Platforms
- Ability to configure, deploy, and troubleshoot Imperva and Fortigate Web Application Firewall Platforms
- Under limited supervision support and engineering of the WAF and Firewall policies
- Engineer and Architect solutions using WAFs, firewalls or other security products. Develops and maintains WAF and firewall security design documentation.
- Work with internal delivery teams to integrate applications with WAF policies
- Provide accurate and timely reporting on all project deliverables
- Recommends secure and effective solutions for system/application development in compliance with Information
- Ability to analyze firewall configurations and rule sets.
- Working knowledge of VMWare NSX or Fortigate VMX
- Working knowledge of McAfee SIEM/Security Suite knowledge preferred
- Working knowledge of Windows Active Directory Domains
- Working Knowledge of various Linux OS
- strong Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption).
- Ability to interpret the information collected by network tools (e.g. Nslookup, Ping, and Traceroute).
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Knowledge of cybersecurity and privacy principles.
- Knowledge of cyber threats and vulnerabilities.
- Knowledge of encryption algorithms, cryptography, and cryptographic key management concepts.
- Knowledge of host/network access control mechanisms (e.g., access control list, capabilities lists).
- Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).
- Knowledge of incident response and handling methodologies.
- Knowledge of network traffic analysis methods.
- Knowledge of new and emerging information technology (IT) and cybersecurity technologies.
- Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
- Knowledge of key concepts in security management (e.g., Release Management, Patch Management).
- Knowledge of security system design tools, methods, and techniques.
- Knowledge of what constitutes a network attack and its relationship to both threats and vulnerabilities.
- Knowledge of defense-in-depth principles and network security architecture.
- Knowledge of different types of network communication (e.g., LAN, WAN, MAN, WLAN, WWAN).
- Knowledge of cyber defense and information security policies, procedures, and regulations.
- Knowledge of the common attack vectors on the application layer.
- Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
- Knowledge of cyber attackers (e.g., script kiddies, insider threat, nation/non-nation state sponsored).
- Knowledge of system administration, network, and operating system hardening techniques.
- Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools.
- Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).
- Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
- Knowledge of how to use network analysis tools to identify vulnerabilities.
- Skill in using protocol analyzers.
- US Citizen and must be able to pass background check(s)
location: Austin, Texas
job type: Contract
salary: $60 - 80 per hour
work hours: 8am to 5pm
- Provision firewalls for customer.
- Perform Changes to Firewalls as specified by customers.
- Develop and maintain rule sets for firewalls.
- Help determine tactics, techniques, and procedures (TTPs) for firewalls.
- Recommend computing environment vulnerability corrections.
- Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings).
- Perform patch management for customer's security tools.
- Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
- Ability to work with provided security policies to design and implement network and security rules and configurations across various security platforms.
- Experience level: Experienced
- Minimum 10 years of experience
- Education: Bachelors
- Cisco ASA (5 years of experience is required)
- Cisco Firepower (5 years of experience is required)
- FIREWALL ENGINEER
Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.