
Kimley-Horn
A multidisciplinary engineering and planning firm offering innovative solutions in various sectors.
Network Security Engineer
Implement and manage enterprise network security, firewalls, VPNs, and cloud defenses.
Job Highlights
About the Role
The role involves participating in advanced security policy decisions, partnering with vendors and internal teams to design and optimize network security solutions, and implementing and maintaining firewalls, VPNs, and intrusion detection/prevention systems. You will troubleshoot complex cloud infrastructure issues, create and manage firewall rules across environments, and collaborate with Network Operations and Cloud teams to provide technical guidance. Monitoring network performance, analyzing access control lists, managing Web Application Firewalls, participating in system upgrades, providing staff training, and supporting after‑hours maintenance are also key duties. • Participate in advanced security policy decisions, including firewall and SASE logic reviews. • Design and optimize network security solutions with vendors and internal partners. • Implement and maintain firewalls, VPNs, and intrusion detection/prevention systems. • Troubleshoot complex cloud networking and security issues. • Create, review, and maintain firewall rules across multiple environments. • Provide technical guidance to Network Operations and Cloud teams. • Monitor and resolve network performance issues (utilization, throughput, latency, slowness). • Analyze, plan, and implement ACLs, firewall policies, and logical security controls in a multi‑vendor stack. • Review, update, and manage Web Application Firewalls. • Participate in system upgrades and enhancements. • Train staff on network security best practices. • Support after‑hours maintenance for outages and critical upgrades. • Hands‑on administration of Palo Alto firewalls and Panorama.
Key Responsibilities
- ▸firewall mgmt
- ▸vpn mgmt
- ▸ids/ips
- ▸security design
- ▸cloud troubleshoot
- ▸waf mgmt
What You Bring
Candidates must hold a bachelor’s degree in information security, cybersecurity, or a related field and have at least four years of enterprise‑level network security experience. Professional certifications such as Security+, Network+, CCNP Security, AZ‑700/AZ‑500, CISSP, or equivalent are required, along with hands‑on experience administering Palo Alto firewalls, Panorama, Cisco ISE, and Web Application Firewalls. Strong problem‑solving, communication skills, and familiarity with change‑management processes are essential. Preferred skills include deep knowledge of threat protection, URL filtering, TLS decryption, PCAP analysis, and cloud security best practices for AWS and Azure. Experience with core network services, API security standards, SD‑WAN platforms, and frameworks such as MITRE ATT&CK or NIST CSF is advantageous. Applicants must be legally authorized to work in the U.S. without employer sponsorship. • Bachelor’s degree in information security, cybersecurity, or related field. • 4+ years of enterprise‑level network security experience. • Relevant certifications (Security+, Network+, CCNP Security, AZ‑700/AZ‑500, CISSP, etc.). • Experience designing application‑based traffic and firewall architectures. • Experience managing and troubleshooting Web Application Firewalls. • Hands‑on experience with Cisco ISE. • Strong problem‑solving and critical thinking under pressure. • Experience with change‑management policies and procedures. • Excellent written and verbal communication skills. • Knowledge of threat protection, URL filtering, TLS decryption, and PCAP analysis. • Familiarity with cloud network security for AWS and Azure. • Understanding of core network services (DNS, DHCP, IP routing). • Knowledge of API security standards (OAuth, SSL, CORS, JWT). • Proven experience with SD‑WAN platforms. • Knowledge of MITRE ATT&CK and NIST Cybersecurity Framework. • Legal authorization to work in the U.S. without sponsorship.
Requirements
- ▸bachelor's
- ▸cissp
- ▸cisco ise
- ▸palo alto
- ▸aws
- ▸problem solving
Work Environment
Office Full-Time