{"schemaVersion":"jobsearcher.job.v1","id":"bff24cbb19d4dccc3b5c9344","url":"https://jobsearcher.com/jobs/bff24cbb19d4dccc3b5c9344","canonicalUrl":"https://jobsearcher.com/jobs/bff24cbb19d4dccc3b5c9344","title":"Network Security Engineer","description":"Position Description:\n\nValiant Solutions is seeking a Network Security Engineer to join our rapidly growing and innovative cybersecurity team!\n\nValiant Solutions is seeking a Network Security Engineer to deploy and operate the Network Access Control and perimeter security capabilities protecting a federal agency's enterprise network. The engineer owns the Cisco Identity Services Engine deployment end to end, covering 802.1X authentication of Government Furnished Equipment, HSPD-12 credential integration, endpoint posture assessment across Windows and macOS, and TrustSec segmentation, alongside the Cisco Firepower Threat Defense firewall fleet and the remote access VPN.\n\nThe current environment runs a seven-node ISE deployment on version 3.4 with separate policy sets per organizational component, and roughly 384 network access devices await integration. This position turns that partial deployment into enforced Zero Trust access control under NIST SP 800-207, measured against a target of 80 percent of active access ports under 802.1X enforcement within the first year.\n\nNamed one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!\n\nThis position is based in Silver Spring, MD, and allows for partial remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.\n\nRequired Experience\n\nBachelor’s Degree in Cybersecurity, Computer Science, Information Systems, or a related technical field. Four (4) additional years of specialized experience may be substituted for a Bachelor's degree.\n6 years of dedicated experience in network security engineering and infrastructure protection.\nHands-on experience taking a Cisco ISE deployment from partial configuration to enforced enterprise-wide 802.1X.\nExperience operating a production firewall fleet in an environment with defined availability standards.\nCisco Identity Services Engine administration, including distributed PAN, MnT, PSN, and pxGrid node topologies.\n802.1X, RADIUS, MAB, and certificate-based authentication in mixed Windows and macOS environments.\nEndpoint posture assessment with AnyConnect and Cisco Secure Client.\nCisco TrustSec design using Security Group Tags and Security Group Access Control Lists.\nCisco Firepower Threat Defense and Firepower Management Center administration, including intrusion prevention tuning.\nRemote access and site-to-site VPN engineering with posture integration and machine certificate enforcement.\nPKI concepts as they apply to machine and user certificate validation.\nSwitching and routing fundamentals sufficient to troubleshoot access-layer authentication failures end to end.\n\nPreferred Certifications\n\nCisco Certified Network Professional (CCNP) Security, Certified Information Systems Security Professional (CISSP), or CompTIA Security+.\n\nResponsibilities\n\nNetwork Access Control and Identity\nReview and validate the existing Cisco ISE configuration, document the gaps, and deliver the remediation design within the first 90 days of performance.\nConfigure and enforce 802.1X authentication for Government Furnished Equipment across the enterprise access layer.\nIntegrate ISE with Active Directory and LDAP, and enforce HSPD-12 compliant authentication using CAC or Yubikey credentials.\nBuild authorization policy that restricts service access to authenticated users and locks accounts after three consecutive failed login attempts.\nOnboard network access devices into ISE in a phased sequence that protects availability while raising enforcement coverage.\nProfiling, Posture, and Remediation\nConfigure the ISE profiling engine to discover, identify, and monitor every endpoint on the network.\nDeploy and tune AnyConnect and Cisco Secure Client posture agents on both Windows and macOS endpoints.\nImplement posture checks that validate antivirus and antimalware status, host firewall state, and operating system patch level before access is granted.\nDevelop remediation policy with the government security team so that non-compliant endpoints are quarantined and returned to service predictably.\nReport posture metrics monthly, including the count of devices denied access for failing compliance checks.\nSegmentation and Firewall Operations\nDesign TrustSec Security Group Tag segmentation that enforces policy by user role rather than IP address.\nIntegrate ISE with Cisco Firepower Management Center to share user and Security Group Tag context for identity-based firewall rules.\nManage the Cisco Firepower Threat Defense appliance fleet, including rule base tuning, intrusion prevention signature management, and malware defense configuration.\nMigrate remaining FTD appliance configurations to the cloud management plane where applicable.\nSupport Tier 2 and Tier 3 firewall rule analysis during incident response and change windows.\nRemote Access and Continuous Operations\nDeploy and manage remote access and site-to-site VPN services, including concentrator configuration and capacity management.\nEnforce posture validation before a remote client is authorized onto the network.\nImplement machine certificate validation and equivalent technical controls that restrict client-based VPN access to Government Furnished Equipment only.\nPrepare Methods of Procedure for every security configuration change and carry them through the Change Control Board.\nParticipate in the 24x7x365 on-call rotation, responding to Priority 1 incidents within 15 minutes.\nCommunication and Stakeholder Engagement\nWritten and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.\nAbility to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.\nClear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.\nAbility to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.\nFederal Knowledge\nWorking knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.\nFamiliarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.\nUnderstanding of HSPD-12 identity credentialing and its enforcement in network access decisions.\nAwareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.\nExperience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.\nWillingness to complete required customer training, including annual cybersecurity awareness, records management, privacy, safety, and harassment prevention training.\n\nAbout Valiant Solutions\n\nValiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology’s Fast 50, and Washington Business Journal’s Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you’ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect – and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.\n\nBenefits Snapshot (includes, but not limited to)\nValiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees\nValiant contributes 25% towards Health Coverage for Family and Dependents\n100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees\n100% Paid Certifications\n401K Matching up to 4%\nPaid Time Off\nPaid Federal Holidays\nWellness & Fitness Program\nValiant University – Online Education and Training Portal\nFSA programs for: Medical Costs, Dependent Care, Transit, and Parking\nReferral Bonuses\n\nThe salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $130,000-$135,000 range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.\n\nRemote Work Policy\n\nRemote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.\n\nEqual Employment Opportunity\n\nValiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.\n\nPhysical Demands\n\nSitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.\n\nAuthorization to Share Resume and Personal Information\n\nBy submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.","company":"Valiant Solutions","rawCompany":"valiant solutions","city":"Silver Spring","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-09-25T11:13:31.754Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"561621","title":"Security Systems Services (except Locksmiths)","slug":"security-systems-services-except-locksmiths"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Network Security Engineer","description":"Position Description:\n\nValiant Solutions is seeking a Network Security Engineer to join our rapidly growing and innovative cybersecurity team!\n\nValiant Solutions is seeking a Network Security Engineer to deploy and operate the Network Access Control and perimeter security capabilities protecting a federal agency's enterprise network. The engineer owns the Cisco Identity Services Engine deployment end to end, covering 802.1X authentication of Government Furnished Equipment, HSPD-12 credential integration, endpoint posture assessment across Windows and macOS, and TrustSec segmentation, alongside the Cisco Firepower Threat Defense firewall fleet and the remote access VPN.\n\nThe current environment runs a seven-node ISE deployment on version 3.4 with separate policy sets per organizational component, and roughly 384 network access devices await integration. This position turns that partial deployment into enforced Zero Trust access control under NIST SP 800-207, measured against a target of 80 percent of active access ports under 802.1X enforcement within the first year.\n\nNamed one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!\n\nThis position is based in Silver Spring, MD, and allows for partial remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.\n\nRequired Experience\n\nBachelor’s Degree in Cybersecurity, Computer Science, Information Systems, or a related technical field. Four (4) additional years of specialized experience may be substituted for a Bachelor's degree.\n6 years of dedicated experience in network security engineering and infrastructure protection.\nHands-on experience taking a Cisco ISE deployment from partial configuration to enforced enterprise-wide 802.1X.\nExperience operating a production firewall fleet in an environment with defined availability standards.\nCisco Identity Services Engine administration, including distributed PAN, MnT, PSN, and pxGrid node topologies.\n802.1X, RADIUS, MAB, and certificate-based authentication in mixed Windows and macOS environments.\nEndpoint posture assessment with AnyConnect and Cisco Secure Client.\nCisco TrustSec design using Security Group Tags and Security Group Access Control Lists.\nCisco Firepower Threat Defense and Firepower Management Center administration, including intrusion prevention tuning.\nRemote access and site-to-site VPN engineering with posture integration and machine certificate enforcement.\nPKI concepts as they apply to machine and user certificate validation.\nSwitching and routing fundamentals sufficient to troubleshoot access-layer authentication failures end to end.\n\nPreferred Certifications\n\nCisco Certified Network Professional (CCNP) Security, Certified Information Systems Security Professional (CISSP), or CompTIA Security+.\n\nResponsibilities\n\nNetwork Access Control and Identity\nReview and validate the existing Cisco ISE configuration, document the gaps, and deliver the remediation design within the first 90 days of performance.\nConfigure and enforce 802.1X authentication for Government Furnished Equipment across the enterprise access layer.\nIntegrate ISE with Active Directory and LDAP, and enforce HSPD-12 compliant authentication using CAC or Yubikey credentials.\nBuild authorization policy that restricts service access to authenticated users and locks accounts after three consecutive failed login attempts.\nOnboard network access devices into ISE in a phased sequence that protects availability while raising enforcement coverage.\nProfiling, Posture, and Remediation\nConfigure the ISE profiling engine to discover, identify, and monitor every endpoint on the network.\nDeploy and tune AnyConnect and Cisco Secure Client posture agents on both Windows and macOS endpoints.\nImplement posture checks that validate antivirus and antimalware status, host firewall state, and operating system patch level before access is granted.\nDevelop remediation policy with the government security team so that non-compliant endpoints are quarantined and returned to service predictably.\nReport posture metrics monthly, including the count of devices denied access for failing compliance checks.\nSegmentation and Firewall Operations\nDesign TrustSec Security Group Tag segmentation that enforces policy by user role rather than IP address.\nIntegrate ISE with Cisco Firepower Management Center to share user and Security Group Tag context for identity-based firewall rules.\nManage the Cisco Firepower Threat Defense appliance fleet, including rule base tuning, intrusion prevention signature management, and malware defense configuration.\nMigrate remaining FTD appliance configurations to the cloud management plane where applicable.\nSupport Tier 2 and Tier 3 firewall rule analysis during incident response and change windows.\nRemote Access and Continuous Operations\nDeploy and manage remote access and site-to-site VPN services, including concentrator configuration and capacity management.\nEnforce posture validation before a remote client is authorized onto the network.\nImplement machine certificate validation and equivalent technical controls that restrict client-based VPN access to Government Furnished Equipment only.\nPrepare Methods of Procedure for every security configuration change and carry them through the Change Control Board.\nParticipate in the 24x7x365 on-call rotation, responding to Priority 1 incidents within 15 minutes.\nCommunication and Stakeholder Engagement\nWritten and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.\nAbility to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.\nClear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.\nAbility to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.\nFederal Knowledge\nWorking knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.\nFamiliarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.\nUnderstanding of HSPD-12 identity credentialing and its enforcement in network access decisions.\nAwareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.\nExperience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.\nWillingness to complete required customer training, including annual cybersecurity awareness, records management, privacy, safety, and harassment prevention training.\n\nAbout Valiant Solutions\n\nValiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology’s Fast 50, and Washington Business Journal’s Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you’ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect – and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.\n\nBenefits Snapshot (includes, but not limited to)\nValiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees\nValiant contributes 25% towards Health Coverage for Family and Dependents\n100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees\n100% Paid Certifications\n401K Matching up to 4%\nPaid Time Off\nPaid Federal Holidays\nWellness & Fitness Program\nValiant University – Online Education and Training Portal\nFSA programs for: Medical Costs, Dependent Care, Transit, and Parking\nReferral Bonuses\n\nThe salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $130,000-$135,000 range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.\n\nRemote Work Policy\n\nRemote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.\n\nEqual Employment Opportunity\n\nValiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.\n\nPhysical Demands\n\nSitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.\n\nAuthorization to Share Resume and Personal Information\n\nBy submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.","datePosted":"2026-09-25T11:13:31.754Z","dateModified":"2026-09-25T11:13:31.754Z","hiringOrganization":{"@type":"Organization","name":"Valiant Solutions","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Silver Spring","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"bff24cbb19d4dccc3b5c9344"},"url":"https://jobsearcher.com/jobs/bff24cbb19d4dccc3b5c9344"}}