Simplify Logo
GovCIO

GovCIO

Federal IT modernization and cybersecurity services

Master Network Security Engineer

Full-TimePosted on 9/16/2026Deadline 9/16/27
$125k - $150k/yr
Expert
Master's
Remote in USA
Remote

About the job

Requirements
  • A Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field; a Bachelor’s degree requires three additional years, and equivalent relevant experience may be considered.
  • At least 10 years of progressive experience in network engineering, network security, firewall administration, or security infrastructure operations.
  • At least 6 years of hands-on Palo Alto Networks firewall experience in a production enterprise environment.
  • Advanced operational experience with Palo Alto Panorama, including multi-device policy management, templates, device groups, upgrades, configuration management, and troubleshooting.
  • Strong hands-on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments.
  • Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes.
  • Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet-level troubleshooting.
  • Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior.
  • Extensive experience with Cisco Catalyst and/or Nexus switching technologies.
  • Strong knowledge of enterprise switching and routing, including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch-security controls.
  • Proven experience designing or implementing network segmentation and microsegmentation solutions.
  • Working knowledge of Cortex XSIAM, Strata Logging Service, security-event correlation, alert investigation, XQL Search, and firewall log ingestion.
  • Ability to lead technical design discussions, independently manage complex workstreams, and communicate risks and recommendations to technical and nontechnical stakeholders.
  • Strong documentation, change-management, incident-management, and root-cause-analysis skills.
  • Ability to obtain and maintain a Public Trust clearance.
Responsibilities
  • Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks next-generation firewall environments running PAN-OS.
  • Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
  • Design and govern security policies using zero-trust, least-privilege, application-aware, and risk-based principles.
  • Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App-ID policies.
  • Lead enterprise network-segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application-based security policies.
  • Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data-center workloads, and cloud resources.
  • Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required.
  • Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split-brain prevention, and failover recovery.
  • Plan and execute HA failover testing, PAN-OS upgrades, disaster-recovery exercises, and maintenance procedures while minimizing service impact.
  • Troubleshoot HA infrastructure dependencies, including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant-path failures.
  • Lead the configuration, support, and troubleshooting of Cisco Catalyst and Nexus switching environments.
  • Design and support VLANs, trunking, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access-control technologies.
  • Diagnose complex connectivity and performance issues through firewall logs, session inspection, packet captures, command-line diagnostics, switch counters, flow data, and network-monitoring platforms.
  • Analyze TCP/IP behavior, including handshake failures, SYN/SYN-ACK/ACK flow, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, packet loss, and NAT translation problems.
  • Verify packet flow across firewall policy, App-ID, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.
  • Monitor firewall management-plane and dataplane health, including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.
  • Integrate Palo Alto next-generation firewalls and Panorama with Strata Logging Service and Cortex XSIAM.
  • Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event availability, retention, and telemetry quality.
  • Use Cortex XSIAM and XQL Search to investigate, correlate, and respond to firewall, endpoint, identity, cloud, and third-party security events.
  • Partner with SOC teams to tune detections, investigate alerts, develop response procedures, improve visibility, and support incident containment and remediation.
  • Lead root-cause analyses for major network or security incidents and deliver corrective and preventive action plans.
  • Develop and maintain network diagrams, firewall-policy documentation, HA designs, runbooks, change plans, architecture standards, and operational procedures.
  • Mentor junior engineers and provide technical leadership during projects, production incidents, and security reviews.
Desired Qualifications
  • Palo Alto Networks certifications such as PCNSA, PCNSE, or PCCSE, or equivalent enterprise-level experience.
  • Cisco certifications such as CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, or CCIE Security, or comparable expertise.
  • Experience with Palo Alto Prisma Access, Prisma Cloud, Cortex XDR, Cortex XSOAR, or cloud-delivered security services.
  • Experience with Cortex XSIAM alert triage, XQL queries, data-source integrations, detection tuning, dashboards, reporting, and response automation.
  • Experience with Cisco ISE, Cisco ACI, SD-Access, or enterprise network-access-control solutions.
  • Familiarity with Fortinet Security Fabric, FortiGate, FortiManager, and FortiAnalyzer.
  • Experience with AWS, Azure, Google Cloud Platform, hybrid-cloud network design, and cloud-security controls.
  • Familiarity with SIEM, SOAR, EDR/XDR, vulnerability-management, NDR, network-monitoring, and ticketing platforms.
  • Automation skills using Python, Ansible, Terraform, REST APIs, or related infrastructure-as-code and orchestration tools.
  • Experience supporting 24x7 environments, participating in an on-call rotation, leading critical incidents, and executing emergency changes.

About the company

GovCIO provides IT services and digital solutions to the U.S. federal government, including IT modernization, digital services, data analytics, cybersecurity, DevSecOps, and management consulting. It wins prime federal contracts and delivers a full range of services through its business units—Health and Civilian Agencies, National Security Solutions, and Veteran and Enterprise Technology Solutions—along with GovCIO Media & Research. The company differentiates itself by expanding through strategic investments and acquisitions, such as WCAS’s stake and the Salient CRGT purchase, and by targeting federal health, national security, and civilian agencies under major contract vehicles like VA T4NG2. Its goal is to help the government transform and modernize its IT landscape with mission-critical technology and analytics capabilities.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Washington DC, District of Columbia

Founded

2010

Get referred to GovCIO

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • GovCIO won a $389.7 million VA IT support order, extending revenue through 2027.
  • Its February 25, 2026 VLM recompete preserves trusted VA visibility and low-friction renewal work.
  • SoldierPoint transition added nearly 300 employees and deepened access to 4 million veterans.

What critics are saying

  • GovCIO lost the GAO-recompeted $95 million GAO IT services contract in January 2026.
  • A D.C. Federal Claims case opened March 2026 keeps GovCIO exposed to protest volatility.
  • Heavy VA concentration makes any 2027 recompete or budget shift an existential revenue shock.

What makes GovCIO unique

  • GovCIO controls VA-connected care through SoldierPoint’s $2 billion CCIN contract, July 2025.
  • Its GovCIO Media & Research brand shapes federal IT narratives, not just delivery services.
  • WCAS-backed scale and 3,300 employees support rapid acquisition integration across federal health programs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Company News

Startup Daily
Aug 11th, 2026
WA government delivers $1.275 million in grants to 26 startups

A total of $1,274,686 was awarded to ideas span energy, tourism and events, space, health and medical life sciences, and primary industries.

Business Wire
Jul 24th, 2025
Iron Bow Technologies Announces Acquisition of SoldierPoint Digital Health, LLC by GovCIO

Iron Bow Technologies (Iron Bow), a leading provider of innovative IT solutions to government, commercial, education, and healthcare markets, today announced...

GovCon Wire
Jan 21st, 2022
GovCIO acquired Salient CRGT, Inc. for $700M on Aug 1st 21'.

The rebranding effort came after GovCIO acquired IT services contractor Salient CRGT in August 2021, creating a combined entity with more than 2,600 employees and $700 million in annual revenues, GovCIO said Thursday.

PR Newswire
Dec 22nd, 2021
GovernmentCIO signs new client U.S. Department of Veterans Affairs

GovernmentCIO (GovCIO) has been awarded an $37M contract by Department of Veterans Affairs (VA) to continue supporting the Veterans Legacy Memorial (VLM).

PR Newswire
Aug 19th, 2021
GovernmentCIO merges with Salient Federal Solutions, Inc.

GovernmentCIO announced it has merged with Salient CRGT, combining two premier government IT solutions companies.