Overview:
Our client is seeking a Network Security Assessment Engineer to provide expert-level network security engineering services to review, assess, hunt for known flaws and threat indicators, and document findings identified through red team testing and accelerated resolution of Security Operational Readiness Tests (SORTS) across the enterprise network infrastructure. Work encompasses the full technology stack managed by the network team, with emphasis on systematic security assessment of current configurations, threat hunting against known vulnerabilities and adversary TTPs, identification of security gaps, and actionable findings aligned to operational standards and risk tolerance.
Responsibilities:
Firewall & Segmentation
- Cisco ACI fabric policy model assessment, EPG/contract review, micro segmentation gap analysis
- Cisco Firepower Threat Defense (FTD) - configuration assessment, policy and rule review, platform hardening analysis
- Check Point firewalls — physical and virtual (R8x), SmartConsole policy assessment, IPS module and signature review
Routing & Switching
- Cisco routers and switches — IOS/IOS-XE security configuration assessment, control plane protection review, routing protocol security analysis (BGP, OSPF authentication, prefix filtering)
- Virtualized Cisco routers deployed in AWS (8000V) - cloud-native security control assessment, security group alignment review, route table integrity validation
Access Control & Identity
- Cisco ISE — policy set assessment, profiling review, MAB/802.1X configuration analysis, guest and BYOD segmentation evaluation
Web & DNS
- Broadcom/Symantec Blue Coat web proxy — policy assessment, SSL inspection gap analysis, category and exception hygiene review
- BlueCat DNS/IPAM — zone security assessment, DNSSEC validation review, rogue record identification, IPAM access control evaluation
Load Balancing & Application Delivery
- F5 BIG-IQ, LTM, and AFM — iRule security assessment, AFM policy review, SSL profile analysis, BIG-IQ RBAC evaluation
Visibility & Detection
- Gigamon - traffic intelligence fabric assessment, filtering map review, out-of-band tap integrity verification
- ExtraHop - detection rule review, threat coverage assessment, SIEM/SOAR integration validation
Time & Infrastructure
- NTP appliances - stratum configuration assessment, authentication review (MD5/SHA1), ACL restriction analysis, source validation
Threat hunting - Known Vulnerability Hunt
· Cross-reference all in-scope platforms against current NVD/CVE databases, CISA Known Exploited Vulnerabilities (KEV) catalog, and vendor security advisories
· Identify unpatched or unmitigated CVEs present in the environment and assess exploitability given current network context
· Document all findings with CVE identifiers, CVSS scores, affected assets, and recommended remediation priority
Qualifications:
Required Qualifications:
· Minimum 7 years of enterprise network security engineering experience with demonstrated assessment and/or threat hunting expertise
· Must hold at least two of: CCIE (Security or Enterprise), CCNP Security, Check Point CCSE, F5 301B, AWS Advanced Networking Specialty
· At least one designated team member must hold a recognized threat hunting or threat intelligence credential (GCIA, GCIH, GCFE, GCTI, or equivalent)
· Experience conducting or supporting formal security assessments, red team remediation engagements and/or remediation required