JOBSEARCHER

Network Security Engineer

Overview In this role you will design and enforce security architectures for mission-critical radio and data systems, aligning controls with NIST SP 800-171 and CMMC Level 2. You will work with cross-functional teams to embed security across the system lifecycle, from design to incident response. The position focuses on protecting CUI, IAM, and network services in a hybrid Irving, TX environment. You will help drive measurable security compliance and improvements across the organization. Compensation / Benefitscompetitive salaryhealth, dental, and vision benefits401K + employer matchtuition reimbursement12 paid holidays + additional PTOsupportive team-driven environment ResponsibilitiesDefine and maintain network security standards mapped to NIST SP 800-171 and CMMC Level 2 controlsCollaborate with architects to ensure security is embedded in designs, focusing on segmentation of CUI assetsDesign and maintain network controls for IA and SC families and contribute to SSP/POA&M and compliance packagesEnforce change-control and configuration management for baseline compliance; perform security impact assessments linked to CMMCDesign and deploy centralized LDAP for directory services and authentication; implement TACACS+ for AAAConfigure MFA for privileged/remote accounts; ensure unique identification for users/devices; integrate IAM with logging/SIEMDesign, configure, and deploy Remote Access VPNs and IPSec tunnels; manage NGFWs and IPS; tune IPSRun vulnerability assessments and pen tests; coordinate remediation for CMMC compliance; analyze SOC incidentsEnsure CUI is encrypted in transit and at rest; implement segmentation and least-privilege access; audit logs and configurationMaintain baselines, automate log collection, support field deployments, and assist in incident response drillsMentor engineers, promote secure-by-design principles, and contribute to the Security Program InitiativeTravel up to 30%Complete additional duties as required Key requirementsBachelor’s Degree in relevant disciplines (or equivalent)Cisco CCNP Security or equivalent requiredCISSP, CySA+, or CISM preferredExperience implementing controls aligned to NIST SP 800-171 and CMMC Level 2Hands-on experience with firewalls, VPNs, IPS, AAA, and loggingFamiliarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible)Experience with packet analysis/forensics (Wireshark, Zeek, Suricata)Knowledge of public-safety radio networks and secure field deployments preferredstrong written and verbal communicationanalytical and problem-solvingmentoring and collaborationLAN/WAN security designNIST SP 800-171 and CMMC Level 2 complianceIAM systems (LDAP, TACACS+)