Network Security Engineer
Network Security Engineer
General Description
We are looking for a skilled Network Security Engineer to support internal and external customers with certificate-related issues across USPS applications and services. This role will engage in the development of key stakeholders on PKI lifecycle management, processes and procedures while providing “Wow Them” service to clients and/or internal customers or co-workers.
About the Federal Region
GuidePoint Security is the trusted partner that defense and civilian government agencies rely on to lead their cybersecurity efforts and protect their organizations. We help solve their most complex security challenges, mature security architectures, and proactively reduce risk. Our purpose-built solutions ensure compliance, safeguard critical assets, and align security with organizational objectives. Backed by deep expertise, strong partnerships, and advanced technologies, we deliver scalable, adaptive capabilities that evolve with the threat landscape so Federal agencies can lead with confidence and protect what’s next.
Roles and Responsibilities
Create reports and documentation using AI and other automation tools.
Review complex PKI and certificate-related issues, determine effective solutions, and recommend improvements to ensure efficient, reliable, and sustainable operations.
Support certificate automation using Venafi/CyberArk TPP identifying opportunities to incorporate AI into automation efforts.
Supervise the PKI team, develop project requirements for complex and critical applications, provides sound strategic advice, technical expertise, and guidance to program and project staff
Ability to work independently, work in a fast-paced environment, and attention to detail
Required Experience and Education
Strong knowledge of REST API integration, Simple Certificate Enrollment Protocol (SCEP), and Microsoft AD auto-enrollment.
Familiarity with technologies such as VCERT, Portable Git, Ansible, and Visual Studio Code.
Proficiency in PowerShell scripting.
Strong understanding of Public Key Infrastructure (PKI) including:
Certificate Authority Administration
Certificate Enrollment Web Service & Policy Web Service
Active Directory Certificate Services (ADCS) monitoring
Infrastructure experience in one or more of the following areas: IT or server administration, networking, Active Directory/LDAP, Unix/Linux, virtualization, or access control administration.
Strong communication skills with IT customers, developers, and system administrators.
Strong experience with certificate management tools, preferably Venafi/CyberArk, Microsoft Certificate Authority, and Hardware Security Modules (HSMs).
Heavy experience troubleshooting digital certificate issues, with an interest in advancing automation and AI-driven solutions.
Knowledge of Post Quantum Cryptography
Preferred Experience and Education
Experience with ServiceNow or other Change/Incident/Problem management ticketing technology
IT system administration experience (systems management, networks, firewalls) in an enterprise environment
Experience with user directory technologies for authentication (e.g., LDAP, Active Directory)
Experience with Microsoft Windows Server configuration, deployment, and troubleshooting.
Experience with Unix and Linux configuration and troubleshooting
Experience with technologies that use TLS/SSL encryption (e.g., F5, Netscaler, IIS, Apache, WebLogic, WebSphere, etc.)
Proficiency with server virtualization technologies (VMWare, HyperV)
Database administration (MSSQL) experience
A+, NET+, SEC+, nCSE, Venafi/CyberArk Admin, certified encryption engineer, CCENT, CCNA
Travel Requirements
Work will be REMOTE with candidates located in Morrisville, NC; Falls Church, VA; or Eagan, MN given preference.
Additional Provisions
Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
Once candidate’s resume is approved and interview passed; the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
All candidates must be a US Citizen or permanent status Green Card holder.
Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)
All overtime must be pre-approved in writing by the client manager or his/her designated representative.
Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.
Physical Requirements
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
If you have additional physical requirements/changes, please discuss with HR first
“Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information.”