Description
We are seeking a Network Security Assessment Engineer to support large-scale enterprise security initiatives. This role focuses on hands-on assessment, vulnerability identification, and threat hunting across a complex hybrid infrastructure environment. The ideal candidate is highly technical, detail-oriented, and capable of executing deep-dive assessments across multiple network security domains while supporting remediation efforts.
This position plays a critical role in helping to strengthen its security posture by identifying risks, validating controls, and partnering with engineering teams to improve resilience across infrastructure platforms.
Job Details:
The Consultant shall provide expert-level network security engineering services to review, assess, hunt for known flaws and threat indicators, and document findings identified through red team testing and accelerated resolution of Security Operational Readiness Tests across the enterprise network infrastructure. Work encompasses the full technology stack managed by the network team, with emphasis on systematic security assessment of current configurations, threat hunting against known vulnerabilities and adversary TTPs, identification of security gaps, and actionable findings aligned to operational standards and risk tolerance.
The consultant must demonstrate hands-on proficiency and hold current certifications or equivalent documented experience in each of the following:
Firewall & Segmentation
Cisco ACI fabric policy model assessment, EPG/contract review, micro segmentation gap analysis
Cisco Firepower Threat Defense (FTD) - configuration assessment, policy and rule review, platform hardening analysis
Check Point firewalls - physical and virtual (R8x), SmartConsole policy assessment, IPS module and signature review
Routing & Switching
Cisco routers and switches - IOS/IOS-XE security configuration assessment, control plane protection review, routing protocol security analysis (BGP, OSPF authentication, prefix filtering)
Virtualized Cisco routers deployed in AWS (8000V) - cloud-native security control assessment, security group alignment review, route table integrity validation
Access Control & Identity
Cisco ISE - policy set assessment, profiling review, MAB/802.1X configuration analysis, guest and BYOD segmentation evaluation
Web & DNS
Broadcom/Symantec Blue Coat web proxy - policy assessment, SSL inspection gap analysis, category and exception hygiene review
BlueCat DNS/IPAM - zone security assessment, DNSSEC validation review, rogue record identification, IPAM access control evaluation
Load Balancing & Application Delivery
F5 BIG-IQ, LTM, and AFM - iRule security assessment, AFM policy review, SSL profile analysis, BIG-IQ RBAC evaluation
Visibility & Detection
Gigamon - traffic intelligence fabric assessment, filtering map review, out-of-band tap integrity verification
ExtraHop - detection rule review, threat coverage assessment, SIEM/SOAR integration validation
Time & Infrastructure
NTP appliances - stratum configuration assessment, authentication review (MD5/SHA1), ACL restriction analysis, source validation
Threat hunting - Known Vulnerability Hunt
Cross-reference all in-scope platforms against current NVD/CVE databases, CISA Known Exploited Vulnerabilities (KEV) catalog, and vendor security advisories
Identify unpatched or unmitigated CVEs present in the environment and assess exploitability given current network context
Document all findings with CVE identifiers, CVSS scores, affected assets, and recommended remediation priority
Qualifications
Minimum 7 years of enterprise network security engineering experience with demonstrated assessment and/or threat hunting expertise
Must hold at least two of: CCIE (Security or Enterprise), CCNP Security, Check Point CCSE, F5 301B, AWS Advanced Networking Specialty
At least one designated team member must hold a recognized threat hunting or threat intelligence credential (GCIA, GCIH, GCFE, GCTI, or equivalent)
Experience conducting or supporting formal security assessments, red team remediation engagements and/or remediation required.
Skills
security, firewall, network security, information security, cyber security, cloud, network engineering
Top Skills Details
security,firewall,network security,information security,cyber security,cloud,network engineering
Additional Skills & Qualifications
Overall Must-Have Skills:
Firewall, network segmentation, and infrastructure security (Cisco ACI, FTD, Check Point)
Routing/switching security (BGP, OSPF, AWS networking)
Threat hunting, CVE analysis, and vulnerability assessment
Security tool experience (F5, Blue Coat, Gigamon, ExtraHop, DNS/IPAM)
Identity/access controls (Cisco ISE) and network-level security governance
Strong documentation and remediation reporting skills
*Experience in regulated or financial services environments is strongly preferred.*
Job Type & Location
This is a Contract position based out of Remote, OR.
Pay and Benefits
The pay range for this position is $90.00 - $105.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Remote,OR.
Application Deadline
This position is anticipated to close on Jul 24, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 101054TS
- Position Id: JP-006163330
- Posted 1 hour ago