Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Quick apply
Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Network Engineer - 3629953 with Security Clearance
Washington, DC · On-site
$117K - $161K/yr
Enforce Zero Trust network architecture principles in accordance with NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices. * Design ...
Network Engineer - 3629953 with Security Clearance
Washington, DC · On-site
$117K - $161K/yr
Enforce Zero Trust network architecture principles in accordance with NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices. * Design ...
Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Quick apply
Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements. * Lead network incident response ...
Lead Network Engineer
Washington, DC · On-site
$140K - $195K/yr
Network segmentation * Micro-segmentation * Identity-aware access controls * Least privilege architecture * Lead Cisco ISE / 802.1X / Network Access Control (NAC) implementations. * Review and ...
Quick apply
Lead Network Engineer
Washington, DC · On-site
$140K - $195K/yr
Network segmentation * Micro-segmentation * Identity-aware access controls * Least privilege architecture * Lead Cisco ISE / 802.1X / Network Access Control (NAC) implementations. * Review and ...
Implement network segmentation strategies using VLANs and Access Control Lists within a Zero Trust model. * Enhance network and endpoint security by minimizing attack surfaces and enforcing secure ...
Quick apply
Implement network segmentation strategies using VLANs and Access Control Lists within a Zero Trust model. * Enhance network and endpoint security by minimizing attack surfaces and enforcing secure ...
Support routing and switching technologies including BGP, OSPF, EIGRP, STP, VLANs, VRFs, ACLs, VPNs, and network segmentation. * Develop and maintain network documentation including topology diagrams ...
Support routing and switching technologies including BGP, OSPF, EIGRP, STP, VLANs, VRFs, ACLs, VPNs, and network segmentation. * Develop and maintain network documentation including topology diagrams ...
Lead Network Engineer
Washington, DC · On-site
$140K - $195K/yr
Network segmentation * Micro-segmentation * Identity-aware access controls * Least privilege architecture * Lead Cisco ISE / 802.1X / Network Access Control (NAC) implementations. * Review and ...
Lead Network Engineer
Washington, DC · On-site
$140K - $195K/yr
Network segmentation * Micro-segmentation * Identity-aware access controls * Least privilege architecture * Lead Cisco ISE / 802.1X / Network Access Control (NAC) implementations. * Review and ...
Sr Network Engineer - onsite and travel required in DMV area
Washington, DC · On-site
$110K - $151K/yr
High-level and low-level network designs (HLDs/LLDs) Network segmentation models supporting IT/OT convergence Routing architectures (BGP, OSPF, SD-WAN) and failover design Firewall security zone ...
Sr Network Engineer - onsite and travel required in DMV area
Washington, DC · On-site
$110K - $151K/yr
High-level and low-level network designs (HLDs/LLDs) Network segmentation models supporting IT/OT convergence Routing architectures (BGP, OSPF, SD-WAN) and failover design Firewall security zone ...
... segmentation Support of migration of services to Cloud infrastructure Department: Preferred Vendors This is a contract position
... segmentation Support of migration of services to Cloud infrastructure Department: Preferred Vendors This is a contract position
Network Engineer (Cisco/Zero Trust) with Security Clearance
Washington, DC · On-site
$117K - $161K/yr
Establish and maintain secure network segmentation and micro-segmentation strategies to limit lateral movement across all network layers and protect high-value assets and sensitive environments. • ...
Network Engineer (Cisco/Zero Trust) with Security Clearance
Washington, DC · On-site
$117K - $161K/yr
Establish and maintain secure network segmentation and micro-segmentation strategies to limit lateral movement across all network layers and protect high-value assets and sensitive environments. • ...
Senior Network Engineer with Security Clearance
Fort George G Meade, MD · On-site
$115K - $158K/yr
This role will lead upcoming and future engineering projects such as Network Segmentation, Comply-to-Connect (C2C), and other network transformation initiatives that support the evolution of the DES ...
New
Senior Network Engineer with Security Clearance
Fort George G Meade, MD · On-site
$115K - $158K/yr
This role will lead upcoming and future engineering projects such as Network Segmentation, Comply-to-Connect (C2C), and other network transformation initiatives that support the evolution of the DES ...
New
Senior Network Engineer
Washington, DC · On-site
$117K - $160K/yr
Responsibilities : • Design, configure, monitor, troubleshoot, and sustain secure enterprise network infrastructure. • Support routing, switching, firewall, network segmentation, connectivity ...
Senior Network Engineer
Washington, DC · On-site
$117K - $160K/yr
Responsibilities : • Design, configure, monitor, troubleshoot, and sustain secure enterprise network infrastructure. • Support routing, switching, firewall, network segmentation, connectivity ...
... network segmentation • Support of migration of services to Cloud infrastructure Department ... Preferred Vendors This is a contract position
... network segmentation • Support of migration of services to Cloud infrastructure Department ... Preferred Vendors This is a contract position
Senior Azure Cloud & Network Architect
Washington, DC · Hybrid
$74.50 - $94.75/hr
Architect hub-and-spoke network topologies and segmentation models that support scalable enterprise cloud environments. * Design and implement Azure Landing Zones to support enterprise governance ...
Quick apply
Senior Azure Cloud & Network Architect
Washington, DC · Hybrid
$74.50 - $94.75/hr
Architect hub-and-spoke network topologies and segmentation models that support scalable enterprise cloud environments. * Design and implement Azure Landing Zones to support enterprise governance ...
Network Engineer
Washington, DC · Hybrid
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Network Engineer
Washington, DC · Hybrid
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Network Engineer
Washington, DC · On-site
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Quick apply
Network Engineer
Washington, DC · On-site
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Network Engineer
Washington, DC · On-site
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Network Engineer
Washington, DC · On-site
Support network segmentation and Zero Trust initiatives * Collaborate with cybersecurity, cloud, and infrastructure teams to ensure secure system integration * Participate in system upgrades ...
Sr. Principal Network Engineer
Washington, DC · Hybrid
$120K - $315K/yr
Ensure compliance with government security protocols (e.g., NIST, FISMA, DISA STIGs), implementing secure networking solutions such as VPNs, firewalls, and network segmentation. * Perform ...
Sr. Principal Network Engineer
Washington, DC · Hybrid
$120K - $315K/yr
Ensure compliance with government security protocols (e.g., NIST, FISMA, DISA STIGs), implementing secure networking solutions such as VPNs, firewalls, and network segmentation. * Perform ...
Network Engineer - VDI Security / Network Infrastructure with Security Clearance
Chantilly, VA · On-site
$2.5K/wk
Implement network segmentation strategies using VLANs and Access Control Lists within a Zero Trust model. * Enhance network and endpoint security by minimizing attack surfaces and enforcing secure ...
Network Engineer - VDI Security / Network Infrastructure with Security Clearance
Chantilly, VA · On-site
$2.5K/wk
Implement network segmentation strategies using VLANs and Access Control Lists within a Zero Trust model. * Enhance network and endpoint security by minimizing attack surfaces and enforcing secure ...
Network Segmentation information
What is the difference between Network Segmentation vs Network Security Engineer?
| Aspect | Network Segmentation | Network Security Engineer |
|---|---|---|
| Primary Focus | Dividing a network into segments to control traffic | Designing, implementing, and managing security measures |
| Required Skills | Networking protocols, VLANs, firewalls | Firewall configuration, intrusion detection, security policies |
| Work Environment | Network infrastructure, data centers, enterprise networks | Security teams, IT departments, cybersecurity environments |
| Certifications | CCNA, CompTIA Network+ | CISSP, CEH, CompTIA Security+ |
Network segmentation involves dividing a network into smaller parts to improve performance and security, while a Network Security Engineer focuses on protecting the network through security measures. Both roles require networking knowledge, but their primary objectives differ: segmentation manages network structure, whereas security engineers safeguard it from threats.
What are the key skills and qualifications needed to thrive in a network segmentation role, and why are they important?
What is network segmentation?
What are some common challenges faced by professionals working in network segmentation roles, and how can they be addressed?
What are popular job titles related to Network Segmentation jobs in Washington?
For Network Segmentation jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Network Segmentation jobs in Washington look for?
The top searched job categories for Network Segmentation jobs in Washington are:
What cities in Washington are hiring for Network Segmentation jobs?
Cities in Washington with the most Network Segmentation job openings:

Full-time
Medical, Dental, Vision, Retirement, PTO
Re-posted 11 days ago
Baltimore Aircoil Company rating
6.7
Based on 15 frontline employees who took The Breakroom Quiz
378th of 488 rated machine equipment manufacturers
Job description
The Network Engineer is the technical co-owner of Baltimore Aircoil Company’s global network. This is a hands-on subject matter expert role responsible for the design, implementation, operation, and lifecycle management of all routing, switching, wireless, firewall, and WAN infrastructure across our corporate offices and manufacturing plants.
The ideal candidate is a true network generalist who can architect a global solution in the morning, troubleshoot a plant-floor connectivity issue in the afternoon, and harden a firewall configuration before the day ends. They are equally comfortable working independently on long-term projects and collaborating with global teams to keep the business running.
Reports to: Manager of IT Infrastructure, North America
Location: On-site at Jessup, MD
Key ResponsibilitiesResponsibilities include but are not limited to:
- Design, implement, and maintain global network architecture across LAN, WAN, WLAN, and data center environments, with primary stacks built on Cisco (routing, switching, wireless) and Cato Networks (SD-WAN/SASE).
- Serve as the technical lead for all network projects, including site builds, refreshes, migrations, and acquisitions — from initial design through implementation, testing, and documentation.
- Own day-to-day network operations: monitoring, capacity planning, performance tuning, configuration management, patching, and lifecycle management of all network hardware and software.
- Configure and manage firewalls, VPNs, ACLs, and network segmentation (including VLANs and OT/IT separation) to support both connectivity and security requirements.
- Lead network incident response — triage outages, perform root cause analysis, implement permanent fixes, and maintain runbooks and incident playbooks.
- Partner with manufacturing and controls engineering teams to design, deploy, and support Operational Technology (OT) network infrastructure on the plant floor, applying segmentation and reliability best practices appropriate to industrial environments.
- Collaborate with the BAC Global Business Services (GBS) team and global network peers on shared standards, remediation of identified gaps, and adherence to enterprise architecture.
- Support hybrid cloud connectivity, including site-to-cloud and inter-cloud networking for our cloud environments as required.
- Maintain accurate, up-to-date network documentation: diagrams, IP schemas, circuit inventories, configuration backups, and change records.
- Participate in disaster recovery planning, testing, and execution for all network-dependent systems.
- Contribute to internal and Amsted-driven audit and compliance activities by providing evidence, remediating findings, and maintaining controls within the network domain.
- Mentor junior IT staff and provide technical guidance on networking topics across the broader infrastructure team.
- Bachelor’s degree in Computer Science, Network Engineering, Information Technology, or a related field. Equivalent professional experience and certifications will be considered in lieu of a degree.
- Minimum of 5–7 years of progressive experience as a Network Engineer, Network Architect, or comparable hands-on network role.
- Deep, hands-on expertise with Cisco routing and switching (IOS / IOS-XE), including Catalyst switches and ISR/ASR routers.
- Strong working knowledge of enterprise wireless (Cisco Catalyst, Meraki, or Aironet) including controller configuration, RF planning, and troubleshooting.
- Production experience with SD-WAN, ideally Cato Networks. Equivalent experience with Velocloud, Viptela, Versa, or Silver Peak will be considered.
- Expert-level understanding of TCP/IP, routing protocols, switching (VLANs, STP, trunking, EtherChannel), and modern network design principles.
- Hands-on firewall configuration and management experience — rule design, NAT, VPN (site-to-site and remote access), and policy auditing.
- Experience designing and supporting network segmentation, including VLANs, ACLs, and IT/OT separation in a manufacturing environment.
- Working knowledge of network monitoring and management platforms (e.g., SolarWinds, PRTG, Cisco DNA Center, Cato Management Application, or similar).
- Demonstrated experience with network incident response and structured root cause analysis.
- Familiarity with disaster recovery planning and testing for network infrastructure.
- Strong written and verbal communication skills, with the ability to translate complex technical concepts for non-technical stakeholders, plant leadership, and executive audiences.
- Ability to work independently, prioritize across multiple concurrent projects, and collaborate effectively across global teams and time zones.
- Willingness to support occasional after-hours change windows and on-call rotation for critical network incidents.
- Active Cisco certifications: CCNP Enterprise required level of knowledge; CCIE Enterprise Infrastructure strongly preferred.
- Cato Networks certification (CNSE / Cato Certified SASE Expert) or equivalent vendor-specific SD-WAN/SASE certification.
- Experience supporting OT networks in a manufacturing environment, including familiarity with the Purdue model, industrial protocols, and coordination with controls/automation engineers.
- Cloud networking experience in Azure and/or AWS (VNets/VPCs, ExpressRoute/Direct Connect, transit gateways, hybrid routing).
- Experience with network automation and infrastructure-as-code tools (Ansible, Python scripting, Terraform, Cisco DNA Center, or similar).
- Familiarity with security frameworks and standards relevant to network controls (NIST CSF, ISO 27001, CIS Benchmarks).
- Prior experience supporting a global, multi-site enterprise (manufacturing or industrial vertical preferred).
- On-site role based at the BAC Jessup, MD location.
- Occasional travel to other BAC sites and manufacturing plants as required for projects, deployments, and incident support.
- Periodic after-hours and weekend work for change windows, maintenance, and incident response.
BAC Hiring Compensation Range $75,300-$129,100
BAC offers a comprehensive benefits package to include medical, dental, vision, paid time off, 401k, employee stock ownership plan, and more. Please see additional details on the BAC website at www.Baltimoreaircoil.com.
BAC Employees are eligible to participate in an annual bonus incentive program.
What Baltimore Aircoil Company employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Baltimore Aircoil
Sourced by ZipRecruiter
Industry
Industrial machinery manufacturing
Company size
501 - 1,000 Employees
Headquarters location
Jessup, MD, US
Year founded
1938