Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.
TDI is seeking a Firewall Engineer to support the Compartmented Enterprise Services Office (CESO) Task Order for the GIG Service Management – Operations II (GSM-O II) contract. We are looking for a professional with hands-on engineering and testing experience in virtualized and cloud environments. A skilled engineer knowledgeable and experienced in developing and implementing Firewall/Networking Security Solutions.
With the CESO program, the Defense Information System Agency (DISA) is looking to transform the existing Secure Web Services (SWS) environment, used to provide secure information sharing to the community, into a more mature service offering to meet the DoD and IC community. The goal will be to manage the commercial cloud migration and fully automate the continuous development & continuous integration environment, fourth estate consolidation, professionalize services – ITIL/DevSecOps based processes, improve the customer experience 1st call resolution, and achieve development of a service catalog for Defense Working Capital Fund (DWCF) Model.
This position is onsite 5 days/week in Arlington, VA and requires an active TS/SCI clearance.
RESPONSIBILITIES:
- Identify and remediate misconfigurations, conflicting rules, security gaps, firewall and load balancer security issues, optimize rule-sets, and enhance the overall security posture and performance of Firewalls and Load Balancers
- Provide Tier 3 support to members of the operations network administrations.
- Maintain all HW and SW components at vendor supported levels.
- Support mission-critical Continuity of Operations (COOP).
- Conduct a minimum of two (2) assessment of firewall each month on CESO and customer devices and generate assessment reports and provide recommendations for improvements.
- Support the creation of network device performance and traffic utilization monthly reports.
- Develop and/or participate in After Action Reports (AARs)
- Provide expert advice and direction regarding the management and operation of all Palo Alto devices in the DISA CESO enterprise architecture.
- Interact with the customer point of contact to set objectives/goals based on Palo Alto Networks technologies and available technology roadmap for architecture and design discussions.
- Evaluate current technologies and processes associated with DISA CESO to identify gaps.
- Provide requirements and strategies for future cybersecurity operations.
- Active participant in meetings with DISA CESO and mission partner working groups.
- Adhere to applicable DOD STIGs, DISA applicable orders, and JSIG policy, guidelines, and regulations.
QUALIFICATIONS:
- Bachelor's degree and 8+ years of directly relevant experience. Additionall experience may be considered in lieu of degree.
- 5+ years of hands-on Cisco / Palo Alto Firewall experience in both engineering and Operations and maintenance roles.
- Strong knowledge of Palo Alto concepts and best practices:
- Panorama Installation, HA Config, Template and Template Stacks
- Panorama Policy creation and push to group of Firewalls and Verify Push
- Palo Alto Route configuration, IPSec Site to Site VPN Config and Troubleshooting
- Palo Alto VM in AWS, IPS Configuration, Virtual Router / Systems and Firewall HA
- Experience working in a high op-temp, Top Secret environment.
- 8570 IAT Level II Baseline Certification (e.g. CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP)
The anticipated salary range for this position is $115,000 - $125,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.
Skills Required
- Bachelor's degree (or equivalent experience) and 8+ years directly relevant experience
- 5+ years hands-on Cisco and Palo Alto firewall experience in engineering and operations/maintenance roles
- Strong knowledge of Palo Alto concepts and best practices (Panorama installation, HA config, templates/template stacks, policy creation and pushes)
- Palo Alto route configuration, IPSec site-to-site VPN configuration and troubleshooting, IPS, virtual router/systems and firewall HA
- Experience with Palo Alto VM deployments in AWS and virtualized/cloud environments
- Experience working in a high op-tempo, Top Secret environment
- Active TS/SCI clearance
- 8570 IAT Level II Baseline Certification (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP)
- Onsite 5 days/week in Arlington, VA
What We Do
For over 20 years, TDI’s one and only passion has been delivering cybersecurity solutions to effectively manage the business of cyber. At the global vanguard of innovation, we created Cybersecurity Performance Management (CPM) and the industry-leading CPM platform, CnSight®. Combining CnSight® with our remarkable historical experience and our exceptional capabilities of cyber operations and compliance, we offer Managed Cybersecurity Performance, a first of its kind managed CPM offering. TDI’s CPM solutions mitigate risk, reduce ransomware, provide continuous compliance, improve cyber-ROI, and provide comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, particularly for Boards of Directors. CnSight® is the industry-leading Cybersecurity Performance Management (CPM) platform which mitigates risk, reduces ransomware, provides continuous compliance, improves cyber-ROI, and provides comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, so executives and Boards may effectively manage the business of cybersecurity– the result: reduced stress, better performance, less cost, and a true understanding of cyber investment. With CnSight® at its core, TDI’s Managed Cybersecurity Performance offering ensures strategic cyber goals are met to protect an organization’s investments, assets and reputation by reducing the risk of ransomware, lowering cyber insurance premiums, improving ROI, reducing legal and fiduciary liability, delivering actionable reporting to the Board and C-Suite, providing on-call advice, ensuring continuous compliance and providing subject matter expertise on the organization’s behalf in meeting with the C-Suite and the Board, dealing with auditors, and supporting budget decisions – the result: reduced stress, better performance, less cost, and a true understanding of cyber investment.









