Network Infrastructure Security Specialist
The Network Infrastructure Security Specialist is responsible for tracking, managing, liaison, and coordinating with internal and external stakeholders to develop, implement, and monitor security control measures as they are related to USPS network infrastructures. The major stakeholders will include, but not limited to, network operations, SOC, Enterprise security architecture, CISO, USPIS, DHS/CISA and their subordinate organizations. The roles and responsibilities will line up with functional teams within Network Operations, in support of their prevailing efforts at the time. The ideal candidate for this job will be an experienced information security practitioner with a solid understanding of AI/LLM, and who is goal-oriented and strives to exceed expectations.
RESPONSIBILITIES:
- Develop, document, and deploy security solutions, both through novel and innovate use of native capabilities of existing tools or through development, to include leveraging AI/ML capabilities.
- Provide Security guidelines based existing security policies and standards to the Network Ops and CISO.
- Monitor and validate network infrastructure practices to ensure adherence to security policy and governance
- Develop and document, for implementation, use cases for CSOC
- Coordinate within the group to interpret and issue guidance in accordance with known policies and governance
- Engage stakeholders to identify or develop guidance and policy regarding their focus areas.
QUALIFICATIONS:
- Strong knowledge of network design and security principles, including network segmentation, MPLS, Internet access, SASE/SD-WAN, DIA, SSE, FWaaS, SWG, ZTNA, and how to engage and intertwine AI and LLM into the design and security principles
- Strong knowledge of netflow/data analytics/network access control for compliance validation and Incident response / threat monitoring (e.g., Cisco ISE, StealthWatch, Netscout).
- Ability to work independently or within a group to identify and develop solutions to complex network and security issues.
- In depth experience with Network Services and their security features, to include DNS, DHCP, IP management, DNS security (CISA PDNS, Bluecat Address Manager, Bluecat DNS Edge, Bluecat Gateway, IPAM, and Splunk)
- Strong knowledge of network-based security measures, e.g., FW, IDS/IPS, explicit/transparent Proxy, Loadbalancers, and LAN segmentation
- Knowledge of host-based data and asset protection, including, AV, Host based FW, X/NDR, data encryptions.
- Knowledge of NIST CSF, NIST SP 800 (e.g., NIST SP 800-53)
- One or more of the following: CISSP, Certified Ethical Hacker (C|EH), CISM, CCNP
- 11+ years’ experience in IT, data, or operational analysis, and/or security.
- Bachelor’s degree in computers or other IT, Security related major; or equivalent experience as listed above.
DESIRED:
- Knowledge of Security Standards (e.g. AS805)
- Project planning experience
- Excellent writing skills
- Microsoft office suite of applications, Visio.
TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.
“TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.”