Network Security Engineer

📍 Virginia, United States 💼 Hybrid ⏰ Full Time 🏷️ Engineering

Work mode: Hybrid · Location: Virginia, United States · Schedule: Full Time.

Application Deadline
📅 Dec 21, 2026
Interested in this job?
Create your profile in 30 seconds and we'll apply for you automatically
📣 Share this job
Link copied ✓

Job Description

Job Title:    Network Security Engineer

Duration:  3 Month

Location:   Hybrid | Richmond, VA, (2 Days Remote + 3 Days Onsite as Required)


Position Summary

The Network Security Engineer will assess the network security controls supporting the  OT environment. Primary areas include firewall and ACL configuration, network segmentation, VPN and remote access, Azure-hosted DMZ components, wireless security, boundary protections, and connectivity between external, DMZ, TOC, field, and internal OT zones.

The engineer will coordinate with the Lead Penetration Tester to validate whether configured network controls prevent or detect unauthorized movement across security boundaries.

 

Key Responsibilities

·        Review approved network diagrams, segmentation models, device configurations, firewall rules, ACLs, and remote-access architecture.

·        Confirm the placement of in-scope assets within the Purdue-style segmentation model.

·        Evaluate external network protections associated with approved OT-facing public IP addresses.

·        Assess Azure-hosted DMZ components, public-facing gateways, security groups, network controls, and connectivity into the OT environment.

·        Test segmentation boundaries between externally reachable assets, the DMZ, TOC resources, field-connected systems, and internal OT resources.

·        Evaluate firewall rules and ACLs for unnecessary access, overly broad permissions, insecure protocols, or unintended trust paths.

·        Assess VPN controls, remote-access boundaries, authentication paths, geolocation controls, and access integrity.

·        Validate network reachability from approved internal starting points.

·        Review network trust relationships and identify paths that could support unauthorized lateral movement.

·        Assess wireless access points and controllers when included in the approved scope.

·        Support external discovery, service enumeration, packet analysis, and network-path validation.

·        Coordinate all active tests with the OT Security Specialist to prevent operational disruption.

·        Verify whether network and remote-access activity is visible to  logging and monitoring systems.

·        Document segmentation gaps, firewall or ACL weaknesses, remote-access risks, and compensating controls.

·        Develop network-specific remediation recommendations, including rule changes, segmentation improvements, monitoring enhancements, and access-control restrictions.

·        Provide evidence and technical content for the DMZ, segmentation, and remote-access assessment report.

·        Support retesting of remediated Critical and High network findings.


Required Skills

·        Enterprise network security

·        Firewall and ACL assessment

·        Network segmentation testing

·        VPN and remote-access security

·        Azure networking and boundary security

·        TCP/IP, routing, switching, and network protocols

·        Network discovery and service enumeration

·        Packet analysis and traffic inspection

·        Wireless network security

·        Trust-path and lateral-movement analysis

·        Network security architecture

·        Secure remote administration

·        Network logging and monitoring

·        Technical evidence collection and report writing

 

Required Experience

·        Minimum five years of network security engineering or network security assessment experience

·        Experience evaluating enterprise firewalls, ACLs, VPNs, and segmented networks

·        Experience validating network controls through configuration review and technical testing

·        Experience assessing DMZ and remote-access architectures

·        Experience identifying unintended access paths across network security zones

·        Experience working with penetration testers and SOC personnel during security assessments

·        Experience developing practical network remediation recommendations


Desired Experience

·        Experience with OT or ICS network segmentation

·        Knowledge of the Purdue Model and industrial network zones

·        Experience assessing Azure network controls and cloud-connected environments

·        Experience with LTE-connected field environments

·        Familiarity with industrial protocols and field-connected devices

·        Experience supporting transportation, public safety, critical infrastructure, or government networks

·        Familiarity with NIST SP 800-82, NIST SP 800-53, CIS Controls, and MITRE ATT&CK for ICS

 

Desired Certifications

·        Certified Information Systems Security Professional, CISSP

·        Certified Ethical Hacker, CEH

·        CompTIA Security+


About the Company

Company registered on Saplic.