Senior Network Protection Engineer / Consultant

TESTUDO CORP
San Jose, CA, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$187,200.0 - $228,800.0
Working hours
Shift work
Job source

Tech stack

Microsoft Word Java (Programming Language) Amazon Web Services Microsoft Azure Cisco PIX Complex Networks Cyber Security Computer Networks System Configuration Data Centers Dynamic Multipoint Virtual Private Networks Domain Name System (DNS)
+36 more
Perl (Programming Language) Ethernet IT Management Networking Hardware Internet Protocol Security (IP SEC) IPv4 IPv6 Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Multi-protocol Systems Python (Programming Language) Network Service Packet Analyzer Network Time Protocols Windows PowerShell Trend Micro SAP Sales and Distribution Security Information and Event Management Transmission Control Protocol (TCP) Virtual Local Area Networks Virtualization Technology Wide Area Networks Cisco Anyconnect Layer 2 Tunneling Protocol Network Routers Scripting Transport Layer Security File Transfer Protocol (FTP) Load Balancing Firewalls (Computer Science) Juniper Palo Alto Networks Ddos Cisco Vmware

Job description

We are seeking an experienced Senior Network Protection Engineer to support the California Department of Technology (CDT) Enterprise Network - Network Threat Protection Unit. In this role, you will work closely with state IT management to secure, configure, and maintain vital security infrastructure across data centers and wide area networks., * Review, evaluate, and optimize security configurations on network hardware and software throughout data center and wide area networks.

  • Install, configure, troubleshoot, and monitor critical security equipment, including firewalls, routers, switches, and load balancers.
  • Manage and configure Intrusion Detection/Prevention Systems (IDS/IPS), specifically Trend Micro TippingPoint.
  • Evaluate and document security practices for firewalls, IPS, and DDoS prevention services.
  • Configure and troubleshoot encryption, IPsec VPNs, and content load balancing.
  • Provide detailed written documentation, troubleshooting procedures, and knowledge transfer/training to state staff.
  • Submit weekly written contract status reports in MS Word format tracking completed tasks, project risks, and hours.

Requirements

To be considered for this role, you must meet the following baseline requirements:

  • Minimum of 7 years of dedicated Network Protection experience.
  • Active Certification: Must hold a TippingPoint Intrusion Prevention System Expert Certification.
  • Protocol Expertise: Strong configuration and troubleshooting skills in Ethernet, VLAN, L2TP, CDP, MPLS, RIPv2, BGPv4, IPv4, IPv6, IPsec, SFTP, TCP, TLS, NTP, and DNS.
  • Hardware/Software Proficiency: Extensive experience with Cisco, Juniper, Palo Alto, F5, and Ciena equipment (routers, switches, firewalls, and load balancers).
  • Virtualization: Hands-on experience with VMware NSX in a data center context.
  • Appliance Security: Direct experience with Cisco ASA, Juniper SRX, Palo Alto firewalls, and F5.
  • Advanced Threat Protection: Solid understanding of F5 ASM/WAF, Trend TippingPoint, and Distributed Denial of Service (DDoS) technologies.
  • VPN & SD-WAN: Proficiency with IPsec, 3DES, AES, IKE, DMVPN, Cisco AnyConnect, Full/Split-Tunnel client VPNs, Site-to-Site VPNs, and SD-WAN.

Preferred Qualifications (Desirable)

  • 12+ years of network protection experience.
  • Experience with AWS and/or Azure cloud networking services.
  • Strong experience writing complex network designs, change logs, and troubleshooting documentation.
  • Experience in sniffer packet capture and protocol analysis.
  • Basic scripting experience (Python, Perl, PowerShell, Java, etc.).
  • Familiarity with NIST 800-53 v4 security controls.
  • Experience using Security Information and Event Management (SIEM) tools., * Network Protection: 7 years (Required)

License/Certification:

  • TippingPoint Intrusion Prevention System Expert Cert (Required)

Work Location: Hybrid remote in San Jose, CA 95139

Benefits & conditions

$90 - $110 an hour - Full-time, Contract, * Competitive W2 hourly compensation or C2C options.

  • Weekly payroll with direct deposit.
  • Dedicated administrative support from our team.
  • The opportunity to support vital public-sector state infrastructure alongside seasoned professionals.

About the company

Testudo Logistics is a veteran-led, mission-driven Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in healthcare, technical, and performance staffing for state and federal agencies. We partner with elite professionals to deliver critical solutions that protect and support public infrastructure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

1:18 min

Overcoming enterprise network and platform security challenges

Oliver Zimmert · LIVE

Videos

See all

Related articles

See all