Skip to content

Open nowPosted today

Principal Network Security Engineer

Leidos1,016 open roles

Where
Odenton, MD
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Network Security EngineerLeidos · Odenton, MD
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Leidos's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Leidos postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted today

Leidos median: 3 days open

The posting

Leidos is seeking an experienced Principal Network Security Engineer to design, engineer, and implement enterprise network security capabilities across a large, distributed network environment. The role is responsible for advancing network security architecture through the execution of strategic design and implementation efforts that improve the security posture, segmentation, access control, and resiliency of the enterprise network.

This position is responsible for overall network security engineering support across a broad range of efforts, including planning, designing, and evaluating the security components of the network. Duties include providing specifications for network security architecture, evaluating and recommending new technologies to enhance current capabilities, performing needs assessments, and directing the installation, configuration, testing, and tuning of network security infrastructure.

The successful candidate serves as a technical leader and subject matter expert — assessing the current security architecture, defining the controls and segmentation model the enterprise needs, building practical implementation plans with realistic risk and rollback provisions, and directing a team of engineers to deliver them under aggressive timelines.

Scope and Impact

Impact: Influences development of solutions that impact strategic project and program goals and business results. Recommends and develops new technical solutions, products, and security standards. Leads and manages the work of other technical staff that has significant impact on project results and outputs.

Complexity: Resolves highly complex problems through significant application of technical knowledge, conceptualization, reasoning, and interpretation. Develops solutions that are highly innovative and achieved through research and integration of best practices.

Communication: Communicates with government, program, cybersecurity, and technical leadership on matters of significant technical importance. Presents security architecture recommendations, implementation plans, risks, dependencies, and status to technical leadership, cybersecurity authorities, stakeholders, and approval boards, and works to build consensus around new concepts, practices, and approaches.

Knowledge: In-depth understanding of network security principles, theories, and concepts and their application across a range of programs. Serves as a subject matter expert within the network security domain.

Primary Responsibilities:

Network Security Engineering and Architecture

  • Design, engineer, and implement enterprise network security architecture spanning next-generation firewalls, intrusion detection and prevention, web and TLS proxies, VPN and encryption services, network access control, DNS security, and east-west security controls.
  • Evaluate the current network security architecture, identify gaps and improvement opportunities, estimate level of effort, assess implementation risk, and develop practical engineering plans to strengthen enterprise security capabilities.
  • Lead network segmentation and secure connectivity efforts, including data-flow mapping, security-zone and enclave design, firewall rule set and ACL review and rationalization, routing and security policy coordination, cutover sequencing, validation, and stakeholder approval.
  • Design and implement network access control and device-posture enforcement (Comply-to-Connect style), including identity and device authentication, posture assessment, policy enforcement points, remediation workflows, and phased enforcement rollout.
  • Advance zero-trust-aligned networking, micro-segmentation, least-privilege access policy, and encrypted-transport strategies across the enterprise.
  • Provide specifications for network security architecture, evaluate and recommend emerging security technologies, and perform needs assessments to inform design and investment decisions.
  • Engineer secure connectivity between on-premises, cloud, and remote environments, including IPsec and TLS VPN, secure cloud interconnects, and perimeter and boundary protection designs.
  • Tune and optimize security controls to reduce false positives, close coverage gaps, and improve detection and enforcement without degrading network performance or availability.

Project Execution

  • Drive security engineering projects from concept through implementation, including architecture evaluation, requirements analysis, dependency identification, design coordination, planning, execution, validation, and transition to operations.
  • Develop and manage implementation plans, schedules, cutover strategies, contingency plans, rollback procedures, validation steps, stakeholder communications, and change documentation for mission-critical security changes.
  • Coordinate change windows, maintenance activities, test validation, and rollback procedures for high-impact security policy and infrastructure changes.
  • Partner with network architecture, cybersecurity, operations, project management, and technical SME teams to resolve blockers, manage dependencies, and reduce delivery risk.
  • Support accreditation and compliance activities, including security control implementation, STIG application, vulnerability remediation, POA&M support, and the technical artifacts required for authorization.

Technical Leadership

  • Serve as the senior technical authority for network security design decisions, providing technical direction, mentoring, and day-to-day guidance to network and security engineers, administrators, and analysts.
  • Organize technical priorities, track details across concurrent efforts, manage competing demands, and maintain accountability against aggressive schedules.
  • Provide clear, well-reasoned technical information and recommendations to government stakeholders and approval authorities.
  • Continuously improve engineering processes, documentation standards, implementation playbooks, migration runbooks, technical standards, and execution models to accelerate delivery, reduce rework, improve operational handoff, and lower sustainment burden.

Documentation

Develop and maintain engineering and operational documentation, including:

  • Network security architecture and logical/physical design diagrams
  • Data-flow diagrams, security-zone models, and segmentation designs
  • Firewall policy standards, rule set baselines, and ACL documentation
  • Port, protocol, and services (PPS) requirements
  • Implementation and cutover plans with rollback and contingency procedures
  • Test and validation plans
  • Risk, dependency, and decision registers
  • Security control implementation statements and accreditation artifacts
  • Technical standards, playbooks, runbooks, and standard operating procedures
  • As-built and operations transition documentation

Required Qualifications:

  • Bachelor's degree or equivalent experience and 12+ years of prior relevant experience, or Master's degree with 10+ years of experience. Specific experience, education, and training may be considered in lieu of a degree.
  • Significant experience designing and implementing network security architecture in complex, large-scale enterprise environments.
  • Experience serving as a senior technical lead directing the work of network and security engineers, administrators, analysts, or implementation resources.
  • Experience leading security engineering projects from planning through implementation, including requirements analysis, dependency management, risk reduction, contingency planning, execution oversight, validation, and operational transition.
  • Hands-on engineering experience with next-generation firewalls, intrusion detection and prevention systems, proxies and TLS inspection, VPN and encryption services, and network access control platforms.
  • Experience with network segmentation or similar secure connectivity efforts, including data-flow analysis, firewall and ACL policy review, routing changes, security-zone design, stakeholder coordination, and implementation planning.
  • Strong working knowledge of core networking concepts, including TCP/IP, routing protocols, switching, VLANs, DNS/DHCP/IPAM, NAT, QoS, and software-defined and cloud-connected network environments.
  • Hands-on experience with two or more of the following technologies: Palo Alto, Cisco, Aruba, Dell, Infoblox, and Brocade.
  • Working knowledge of Federal Government application, server, and network security requirements such as NIST, FedRAMP, FISMA, RMF, DISA STIGs, and DoD cybersecurity requirements.
  • Demonstrated ability to organize work, track details, manage competing priorities, meet aggressive schedules, and drive complex technical efforts to completion with a high degree of accountability.
  • Experience documenting security and network designs, implementation plans, risks, dependencies, and technical recommendations using tools such as Visio, PowerPoint, Cameo, or similar.
  • Excellent written and verbal communication skills, including experience briefing technical leadership, cybersecurity authorities, stakeholders, and approval boards.
  • Current IAT Level II or higher certification, such as Security+ or CISSP.
  • Active DoD Secret clearance.

Preferred Qualifications:

  • CISSP, Palo Alto PCNSE, Cisco CCNP Security, or equivalent advanced security certification.
  • Experience implementing Comply-to-Connect, 802.1X, or comparable network access control and device-posture enforcement at enterprise scale.
  • Experience with zero-trust architecture, micro-segmentation, SASE, or secure cloud connectivity designs.
  • Experience integrating network security platforms with SIEM, SOAR, ITSM, and analytics tooling.
  • Experience with security automation and infrastructure-as-code using Python, Ansible, REST APIs, or similar, including automated firewall policy management.
  • Experience with certificate and PKI management, encrypted-traffic inspection, and key management in enterprise environments.
  • Experience supporting RMF, eMASS, continuous monitoring, and audit or inspection activities.
  • Experience with Jira, Confluence, or other project and knowledge-management tools used to coordinate technical work across distributed engineering teams.
  • Experience developing repeatable engineering execution frameworks, implementation playbooks, migration runbooks, technical standards, and risk-reduction processes.

Key Success Factors

This position requires more than a firewall administrator working a change queue. It requires a security engineer who can look at an enterprise network, determine where the real exposure is, design the segmentation and control model that closes it, and sequence the implementation so the enterprise stays up while it happens.

The successful engineer is equally comfortable in the technical detail — policy, routing, identity, certificates, inspection, and automation — and in front of cybersecurity authorities and approval boards defending a design, its residual risk, and its dependencies.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

October 8, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $116,350.00 - $210,325.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Leidos's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Leidos's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Leidos's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.