Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies. Since 1968, we’ve been solving the toughest challenges with groundbreaking tech. Explore thrilling projects in Digital Transformation, Cybersecurity, IT, Data Analytics and Software Development. Elevate your career and make a difference. Your adventure begins now—unleash your potential with MANTECH!
MANTECH seeks a motivated, career and customer-oriented Senior Network Security Engineer to join our team in either Fairmont, WV, Boulder CO, or REMOTE (US-Based).
The Senior Network Security Engineer will serve as a technical anchor, driving network modernization efforts, eliminating operational silos, and leading the transition from legacy, colocation-dependent architectures to a secure, cloud-integrated Trusted Internet Connection (TIC) 3.0 framework. The candidate must possess a strong, proactive problem-solving mindset and be comfortable working in a high-tempo, availability-first environment.
Responsibilities include but are not limited to:
- Perimeter Architecture & TIC 3.0 Transition: Design, configure, and maintain our geographically distributed network boundaries. Architect and engineer secure site-to-site IPsec VPN tunnels and related components to modernize our boundary from TIC 2.0 colocation centers to cloud-integrated TIC 3.0 secure overlays.
- Multi-Vendor Firewall & Switching Engineering: Perform expert-level administration, configuration, and troubleshooting of our enterprise firewall and switching planes. This includes configuring and managing products that may include, Palo Alto Networks Next-Generation Firewalls, Fortinet FortiGate appliances, as well as Juniper and Brocade switches.
- GitOps & Automation Integration: Maintain and enforce network configuration baselines using Infrastructure as Code (IaC) techniques. Collaborate with our tools development team to write and execute Ansible playbooks and GitLab CI/CD pipelines to automate VLAN assignments, port configuration, and dynamic DNS sinkhole blocks.
- Network Observability & Traffic Analysis: Utilize packet brokers to capture and route packet streams. Operate tools and technologies to monitor internal network flows and detect anomalous lateral movement. Integrate out-of-band network probing utilities to continuously track perimeter performance.
- Technical Documentation & Configuration Management: Develop and maintain up-to-date, accurate documentation of network cabling, IP Addresses, MAC addresses, and VLAN assignments for critical systems. Utilize tools to generate dynamic network topology maps, execute runbooks, and automate configuration drift audits.
- Vulnerability Remediation & Compliance: Collaborate closely with the ISSO and Vulnerability Assessment Teams. Run network vulnerability scans, analyze results, apply Security Technical Implementation Guides (STIGs/CIS), and execute directed patching or configuration changes.
- COOP & High-Availability Operations: Configure and maintain High-Availability (HA) firewalls, actively diagnosing active-active split-brain states or persistent ARP resolution bugs. Participate in a 24/7 on-call rotation with a strict one-hour response window for service-impacting network events.
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Computer Systems Engineering, Cybersecurity, or a related field with 5+ years of direct Systems or Network Engineering experience or Associate’s degree in a related field with 8+ years of relevant experience or 11+ years of relevant experience with no degree.
- Firewall & Networking Ecosystem: Minimum of 3 years of hands-on administration of Palo Alto Networks firewalls (PAN-OS) and Juniper core switching infrastructure (Junos OS) in an enterprise environment.
- Dynamic Routing & Tunneling: In-depth technical mastery of BGP routing (including BGP Anycast configurations and route-withdrawal failover scripts), OSPF, and IPsec VPN tunneling.
- Security Frameworks: Proven working knowledge of federal security compliance standards, including FISMA, the NIST Risk Management Framework (RMF) SP 800-53 Rev. 5, and CISA Zero Trust guidelines.
Preferred Qualifications:
- Possession of one or more of the following professional, role-based security certifications is highly desired to align with Department of Commerce (DOC) CAT Standards:
- ISC2 CISSP (Certified Information Systems Security Professional) or ISSAP (Information Systems Security Architecture Professional)
- Cisco CCIE Security, CCDE, or CCAr
- ISC2 CCSP (Certified Cloud Security Professional)
- Networking Baselines: Active CCNA or Advanced Palo or Juniper-equivalent certifications.
- Infrastructure Automation: Experience scripting in Python or Bash and building custom playbooks in Ansible to manage network configurations.
- Cloud Architecture: Experience setting up secure transit gateways and VPC routes within Amazon Web Services (AWS) or Microsoft Azure environments.
Clearance Requirements:
- Must be a US citizen with a current/active Secret clearance.
Physical Requirements:
- Must be able to remain in a stationary position more than 50% of the time.
- Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.


