Network and Infrastructure Engineer at Sushma | CazVid
Apply for this position
Review the job details below and click Apply Now to get started.
Network and Infrastructure Engineer
Sushma
Los Angeles, California, United States
$95,000 / yr
Responsibilities & Duties: Network Engineering and SecurityDesign, implement, configure, and maintain Pixxel’s corporate and protected network environments.Administer and secure Meraki and Fortinet firewalls, switches, wireless access points, VPNs, and related network services.Maintain appropriate separation among corporate systems, protected systems, CUI-related environments, guest networks, and untrusted devices.Configure and regularly review firewall rules, access control lists, VPN access, routing, DNS, DHCP, wireless security, and administrative interfaces.Apply secure network configuration standards and disable unnecessary services, ports, protocols, and functionality.Monitor network availability, capacity, performance, and security events.Investigate network outages, configuration issues, unauthorized connections, and suspicious activity.Perform root-cause analysis and document corrective and preventive actions.Maintain secure remote-access solutions with multifactor authentication.Evaluate and support implementation of zero-trust, secure web gateway, and network-access-control technologies.Infrastructure and Systems AdministrationAdminister Windows, macOS, and Linux systems supporting Pixxel’s business and technical operations.Manage identity, endpoint, and device configurations using JumpCloud and other approved systems.Support Google Workspace Enterprise administration, security configurations, authentication, and access controls.Implement secure configurations, operating-system hardening, patching, encryption, and device-compliance requirements.Support AWS and hybrid infrastructure, including connectivity, identity integration, logging, storage, and secure configurations.Maintain infrastructure monitoring, backups, recovery procedures, and business continuity capabilities.Automate infrastructure configuration and deployment using PowerShell, Bash, Python, Terraform, Ansible, or similar tools.Manage infrastructure capacity, lifecycle, warranty, licensing, and replacement planning.CMMC and NIST Technical ImplementationImplement assigned technical requirements supporting NIST SP 800-171 and CMMC Level 2.Protect systems that process, store, or transmit FCI, CUI, and other sensitive information.Implement least privilege, network segmentation, secure configurations, multifactor authentication, logging, encryption, and controlled remote access.Maintain asset inventories, network diagrams, data-flow diagrams, configuration baselines, firewall records, and system architecture documentation.Produce objective evidence showing that assigned technical controls are implemented and operating as documented.Participate in control testing, gap assessments, internal reviews, tabletop exercises, and external assessments.Remediate identified infrastructure vulnerabilities and compliance gaps by established deadlines.Support maintenance of the System Security Plan, Body of Evidence, and Plans of Action and Milestones.Immediately report control failures, unauthorized changes, missed milestones, or technical conditions that could place CUI at risk.Vulnerability and Configuration ManagementCoordinate authenticated vulnerability scanning of network devices, servers, endpoints, and cloud infrastructure.Review findings, determine technical impact, prioritize remediation, and validate closure.Establish and maintain secure configuration baselines.Perform periodic configuration and firewall-rule reviews.Test and deploy patches and firmware updates within approved remediation timelines.Track exceptions and unsupported systems through the approved risk-management process.Ensure infrastructure changes follow documented change-control and approval procedures.Documentation and CommunicationMaintain current network diagrams, configuration records, recovery procedures, SOPs, system inventories, and administrative guides.Document infrastructure work, owners, dependencies, milestones, and completion evidence in Jira or another approved platform.Provide timely status updates and communicate anticipated delays before deadlines are missed.Escalate outages, security concerns, compliance gaps, and project blockers promptly.Complete assigned work from initial planning through implementation, testing, documentation, and handoff.Collaborate with cybersecurity, IT, engineering, facilities, People Operations, leadership, and external service providers. Desirable Skills & Certifications:Reliable and secure network and infrastructure operations.Current and accurate network, system, and configuration documentation.Timely vulnerability, patch, and configuration remediation.Effective network segmentation and protection of the CUI environment.Complete technical evidence for assigned compliance requirements.Accurate status reporting and early communication of risks or delays.Infrastructure projects completed, tested, documented, and handed off by agreed deadlines.