Peraton is seeking an experienced Network Engineer to join our team of qualified and diverse individuals. The Network Engineer - Firewall & Load Balancing will support the DHS CBP Network Operations Center (NOC) by designing, implementing, securing, and maintaining enterprise network security infrastructure. This role will provide hands-on support for mission critical network environments with a focus on F5 BIG-IP load balancing solutions, Palo Alto Next Generation Firewalls (NGFW), and Cisco Firepower Threat Defense (FTD) managed through Firepower Management Center (FMC).
The ideal candidate will have experience managing complex enterprise security platforms, troubleshooting network security issues, implementing secure configurations, and supporting hybrid infrastructure environments. The Network Security Engineer will collaborate with network operations, cybersecurity teams, and government stakeholders to maintain secure, reliable, and compliant network services.
Location: Onsite based in either Ashburn, VA, Springfield, VA or Orlando, FL. Candidates must reside near one of these locations to be considered.
- Design, configure, maintain, and troubleshoot enterprise network security infrastructure, including firewalls, load balancers, VPN solutions, and network security platforms.
- Administer and support F5 BIG-IP environments, including Local Traffic Manager (LTM), Global Traffic Manager (GTM/DNS), virtual servers, pools, iRules, SSL profiles, health monitors, and traffic policies.
- Perform SSL/TLS certificate management, traffic optimization, application delivery troubleshooting, and load balancing configuration.
- Support F5 Advanced Web Application Firewall (WAF) policies and security configurations.
- Configure and manage Palo Alto Networks Next Generation Firewalls, including security policies, NAT, QoS, decryption, and VPN configurations.
- Administer Palo Alto Panorama for centralized firewall management across enterprise environments.
- Configure and maintain Palo Alto security capabilities, including App-ID, User-ID, Content-ID, Threat Prevention, URL Filtering, and WildFire.
- Manage Cisco Firepower Threat Defense (FTD) devices using Firepower Management Center (FMC).
- Develop and maintain Access Control Policies (ACP), IPS policies, malware inspection policies, and Snort rule tuning within Cisco FMC.
- Perform firewall event analysis, security monitoring, incident investigation, and troubleshooting activities.
- Support network engineering activities including VLANs, segmentation, routing protocols, VPN connectivity, and network performance optimization.
- Develop and maintain network documentation including diagrams, standard operating procedures, and technical runbooks.
- Support change management activities by ensuring network security changes are tested, documented, approved, and implemented in accordance with established processes.
- Monitor network performance, troubleshoot incidents, perform root cause analysis, and support service level agreement (SLA) requirements.
- Collaborate with cybersecurity teams to support Zero Trust architecture, defense in depth strategies, and security compliance requirements.