Network Security Assessment Engineer

CareerCircle
Remote, OR, United States
28 days ago
Apply on www.careercircle.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$187,200.0 - $218,400.0
Working hours
Regular working hours

Tech stack

IEEE 802.1X Amazon Web Services Proxy Servers Apple IOS User Authentication Border Gateway Protocol Cisco Routers Cloud Computing Profiling Cyber Security Information Systems Computer Networks
+33 more
Databases Domain Name System Security Extensions Domain Name System (DNS) Internetworking IP Address Management Network Security Network Control Routing Network Segmentation Cisco Nexus Switches Open Shortest Path First (OSPF) Role-Based Access Control Broadcom Red Team (Cyber Security) Secure Hash Algorithm Security Information and Event Management Software Deployment Software Engineering Symantec Network Switches Network Routing Transport Layer Security Identity Services Engine Load Balancing Cyber Threat Analysis Firewalls (Computer Science) Cybercrime Check Point Firewalls Routing & Switching BIG-IP Advanced Firewall Manager (AFM) Firepower Cisco Vulnerability Analysis

Job description

We are seeking a Network Security Assessment Engineer to support large-scale enterprise security initiatives. This role focuses on hands-on assessment, vulnerability identification, and threat hunting across a complex hybrid infrastructure environment. The ideal candidate is highly technical, detail-oriented, and capable of executing deep-dive assessments across multiple network security domains while supporting remediation efforts.

This position plays a critical role in helping to strengthen its security posture by identifying risks, validating controls, and partnering with engineering teams to improve resilience across infrastructure platforms.

Job Details:

The Consultant shall provide expert-level network security engineering services to review, assess, hunt for known flaws and threat indicators, and document findings identified through red team testing and accelerated resolution of Security Operational Readiness Tests across the enterprise network infrastructure. Work encompasses the full technology stack managed by the network team, with emphasis on systematic security assessment of current configurations, threat hunting against known vulnerabilities and adversary TTPs, identification of security gaps, and actionable findings aligned to operational standards and risk tolerance.

The consultant must demonstrate hands-on proficiency and hold current certifications or equivalent documented experience in each of the following:

Firewall & Segmentation

Cisco ACI fabric policy model assessment, EPG/contract review, micro segmentation gap analysis

Cisco Firepower Threat Defense (FTD) - configuration assessment, policy and rule review, platform hardening analysis

Check Point firewalls - physical and virtual (R8x), SmartConsole policy assessment, IPS module and signature review

Routing & Switching

Cisco routers and switches - IOS/IOS-XE security configuration assessment, control plane protection review, routing protocol security analysis (BGP, OSPF authentication, prefix filtering)

Virtualized Cisco routers deployed in AWS (8000V) - cloud-native security control assessment, security group alignment review, route table integrity validation

Access Control & Identity

Cisco ISE - policy set assessment, profiling review, MAB/802.1X configuration analysis, guest and BYOD segmentation evaluation

Web & DNS

Broadcom/Symantec Blue Coat web proxy - policy assessment, SSL inspection gap analysis, category and exception hygiene review

BlueCat DNS/IPAM - zone security assessment, DNSSEC validation review, rogue record identification, IPAM access control evaluation

Load Balancing & Application Delivery

F5 BIG-IQ, LTM, and AFM - iRule security assessment, AFM policy review, SSL profile analysis, BIG-IQ RBAC evaluation

Visibility & Detection

Gigamon - traffic intelligence fabric assessment, filtering map review, out-of-band tap integrity verification

ExtraHop - detection rule review, threat coverage assessment, SIEM/SOAR integration validation

Time & Infrastructure

NTP appliances - stratum configuration assessment, authentication review (MD5/SHA1), ACL restriction analysis, source validation

Threat hunting - Known Vulnerability Hunt

· Cross-reference all in-scope platforms against current NVD/CVE databases, CISA Known Exploited Vulnerabilities (KEV) catalog, and vendor security advisories

· Identify unpatched or unmitigated CVEs present in the environment and assess exploitability given current network context

· Document all findings with CVE identifiers, CVSS scores, affected assets, and recommended remediation priority

Requirements

Textiles Hardening Apple IOS F5 Irules Cisco ACI Operations Resilience IEEE 802.1X Gap Analysis Cisco Routers Proxy Servers Routing Table Cyber Security AWS Networking Detail Oriented Contract Review Authentications Access Controls Network Routing Network Switches Network Security Bluecoat Proxies Security Controls Routing Protocols Security Analysis Policy Evaluation, Software Engineering 2004 Balancing (Ledger/Billing) Enterprise Network Security IP Address Management (IPAM) GIAC Cyber Threat Intelligence Open Shortest Path First (OSPF) GIAC Certified Incident Handler GIAC Certified Intrusion Analyst Role-Based Access Control (RBAC) GIAC Certified Forensic Examiner Cisco Identity Services Engine (ISE) Domain Name System Security Extensions Common Vulnerability Scoring System (CVSS) Certified Information System Auditor (CISA) AWS Certified Advanced Networking Specialty CISCO Certified Network Professional - Security Security Information And Event Management (SIEM) Cisco Certified Internetwork Expert Security (CCIE Security), · Minimum 7 years of enterprise network security engineering experience with demonstrated assessment and/or threat hunting expertise

· Must hold at least two of: CCIE (Security or Enterprise), CCNP Security, Check Point CCSE, F5 301B, AWS Advanced Networking Specialty

· At least one designated team member must hold a recognized threat hunting or threat intelligence credential (GCIA, GCIH, GCFE, GCTI, or equivalent)

· Experience conducting or supporting formal security assessments, red team remediation engagements and/or remediation required.

Skills

security, firewall, network security, information security, cyber security, cloud, network engineering

Top Skills Details

security,firewall,network security,information security,cyber security,cloud,network engineering

Additional Skills & Qualifications

Overall Must-Have Skills:

Firewall, network segmentation, and infrastructure security (Cisco ACI, FTD, Check Point)

Routing/switching security (BGP, OSPF, AWS networking)

Threat hunting, CVE analysis, and vulnerability assessment

Security tool experience (F5, Blue Coat, Gigamon, ExtraHop, DNS/IPAM)

Identity/access controls (Cisco ISE) and network-level security governance

Strong documentation and remediation reporting skills

Experience in regulated or financial services environments is strongly preferred., Remote, OR*Remote

Firewall Textiles Hardening Apple IOS F5 Irules Cisco ACI Operations Resilience IEEE 802.1X Gap Analysis Cisco Routers Proxy Servers Routing Table Cyber Security AWS Networking Detail Oriented Contract Review Authentications Access Controls Network Routing Network Switches Network Security Bluecoat Proxies Security Controls Routing Protocols Security Analysis Policy Evaluation, Software Engineering 2004 Balancing (Ledger/Billing) Enterprise Network Security IP Address Management (IPAM) GIAC Cyber Threat Intelligence Open Shortest Path First (OSPF) GIAC Certified Incident Handler GIAC Certified Intrusion Analyst Role-Based Access Control (RBAC) GIAC Certified Forensic Examiner Cisco Identity Services Engine (ISE) Domain Name System Security Extensions Common Vulnerability Scoring System (CVSS) Certified Information System Auditor (CISA) AWS Certified Advanced Networking Specialty CISCO Certified Network Professional - Security Security Information And Event Management (SIEM) Cisco Certified Internetwork Expert Security (CCIE Security) +0

Benefits & conditions

This is a Contract position based out of Remote, OR. Pay and Benefits

The pay range for this position is $90.00 - $105.00/hr.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: * Medical, dental & vision * Critical Illness, Accident, and Hospital * 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available * Life Insurance (Voluntary Life & AD&D for the employee and dependents) * Short and long-term disability * Health Spending Account (HSA) * Transportation benefits * Employee Assistance Program * Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type

About the company

We’re partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company., We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careercircle.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

Videos

See all

Related articles

See all