Senior Network Security Engineer at Valar Atomics. . Location: Torrance, California, United States. About Valar Atomics. . At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry, hydrogen, and next-generation manufacturing. We are a team of builders, engineers, and operators who believe nuclear energy should be fast to deploy, factory-made, and built for the real world. Our first pilot plant in Orangeville, Utah will demonstrate how advanced nuclear systems and fuel fabrication can power the future. Joining Valar Atomics means becoming part of a company where autonomy, ownership, and impact exist at every level.. . The Team. . . As part of the . Business. organization, IT & Enterprise Software delivers the technology infrastructure, enterprise applications, and digital tools that power Valar's operations. The team ensures secure, reliable, and scalable technology solutions that support every function across the company.. . . The Role. . . Valar Atomics is seeking a hands-on . Senior. . Network Security Engineer. to design, implement, and . maintain. our enterprise network security infrastructure. This role focuses heavily on Palo Alto Networks . firewall. administration, secure remote access via . GlobalProtect. VPN, cloud connectivity across Azure and AWS, and network access control for wired, wireless, and IoT devices. The ideal candidate combines deep . firewall. /routing . expertise. with practical experience securing endpoints, cameras, and IoT devices through certificate-based (TLS/802.1X) authentication.. . . Key Responsibilities. . . Firewall & Network Security. . . . Configure and manage Palo Alto Networks firewall security policies, NAT rules, and threat prevention profiles. . . Design and implement Palo Alto Firewall routing (static, dynamic, and policy-based routing). . . Monitor, troubleshoot, and optimize firewall performance and rule sets. . . . VPN & Cloud Connectivity. . . . Build, configure, and maintain GlobalProtect VPN for secure remote access. . . Create and manage site-to-site VPN tunnels between on-premises infrastructure and Azure and AWS environments. . . Troubleshoot VPN connectivity, tunnel stability, and routing issues across hybrid cloud environments. . . . Identity, Certificates & Access Control. . . . Integrate and manage EZPKI and EZRadius (Azure-based SaaS RADIUS and SaaS TLS/PKI services) for certificate-based network authentication. . . Deploy and support TLS-based 802.1X authentication for IP cameras and other IoT devices. . . Configure 802.1X network access control policies across wired and wireless infrastructure. . . Integrate and manage AWS CA and AWS PKI infrastructure. . . Switching & LAN Infrastructure. . . . Configure and maintain routing on Ruckus switches. . . Support VLAN segmentation, inter-VLAN routing, and network access policies for IoT and camera device segments. . . . Cross-Functional / Nice-to-Have. . . . Support Prisma (Prisma Access / Prisma Cloud) initiatives as needed. . . Support Palo Alto CASB deployment and policy configuration as needed. . . . Basic Qualifications. . . . . Proven hands-on experience with . Palo Alto Networks firewalls. (policy creation, NAT, routing, troubleshooting). . . Experience configuring and supporting . GlobalProtect VPN. . . Experience building . site-to-site VPN tunnels. with . Azure. and . AWS. . . Working knowledge of . 802.1X authentication. (wired/wireless) and certificate-based network access. . . Experience with . Ruckus switch. configuration and routing. . . Strong understanding of enterprise routing concepts (static routing, VLANs, inter-VLAN routing). . . Solid troubleshooting skills across firewall, VPN, and switching layers. . . Performed root-cause analysis on wireless access point failures, adjusted AP placement and power/range settings to optimize coverage, and resolved intermittent Wi-Fi connectivity issues.. . . . Skilled in wireless access point diagnostics, RF coverage tuning, and troubleshooting client connectivity and signal degradation issues.. . . . Preferred Skills and Experience. . . . . . Experience with . Prisma Access. and/or . Prisma Cloud. . Experience with CMMC2. . Prior military service. in . US Airforce or Navy. , particularly in communications, networking, cybersecurity, IT, or other technical fields, is highly valued. Relevant military training and operational experience will be considered alongside civilian industry experience.. . Experience with . Palo Alto CASB. . Experience with . EZPKI / EZRadius. or similar Azure-based SaaS RADIUS/PKI/TLS certificate services. . Experience deploying . TLS/802.1X authentication for IoT devices and IP cameras. . Relevant certifications such as PCNSE (Palo Alto Certified Network Security Engineer), CCNP\CCNP Security, or similar. . Light automation such ansible, Terraform, Saltstack. . . What Success Looks Like. . . . Firewall policies and routing are well-organized, documented, and optimized for security and performance. . . GlobalProtect VPN provides reliable, secure remote access for all authorized users. . . Site-to-site tunnels to Azure and AWS are stable and properly monitored. . . Certificate-based authentication (EZPKI/EZRadius) is integrated smoothly with minimal access disruptions. . . IoT devices and cameras are securely onboarded via 802.1X/TLS with minimal friction. . . Ruckus switch routing is stable and correctly segmented across the network. . . . What We Offer. . . . Competitive base salary . . Equity ownership in a rapidly growing advanced energy company . . Comprehensive medical benefits . . Unlimited PTO. . Free daily lunch provided onsite . . Generous PPE stipend. . High-impact startup environment with significant ownership and autonomy . . Opportunities for rapid career growth and internal advancement . . Direct collaboration with experienced operators, engineers, and industry leaders . . The opportunity to help build and scale transformative energy technology from the ground up. . . Equal Employment Opportunity Statement. . Valar Atomics is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected status under applicable law.. . We are committed to providing a workplace free of discrimination and harassment and will provide reasonable accommodation as required by law.. . Applicants must be legally authorized to work in the United States as a U.S. citizen or lawful permanent resident (green card holder).. Salary. $160,000. - . $180,000. . USD
Senior Network Security Engineer at Valar Atomics