V
Network Security Engineer
Job Description
Vibotek LLC is seeking a contract Network Security Engineer for an onsite role in Rancho Cordova, CA. This engagement focuses on strengthening network security by modernizing site-to-site IPsec VPN tunnels and tightening Cisco Firepower firewall access control policies. You will work alongside onsite campus teams and external partners to execute approved maintenance window changes with documented validation results.
What you’ll deliver
- Review approximately 80 existing site-to-site IPsec VPN tunnels.
- Upgrade approximately 50 tunnels from IKEv1 to IKEv2.
- Ensure VPN configurations align with organizational cryptographic standards, including secure handling of pre-shared keys (PSKs) with a minimum 20-character requirement.
- Validate VPN tunnel functionality after each change to confirm connectivity.
- Review approximately 10 firewall access control rules on Cisco Firepower systems to reduce overly permissive access and match approved requirements.
- Modify firewall rules to remove overly permissive or broad subnet access and restrict rules to required source/destination networks, ports, and protocols.
- Apply the principle of least privilege to network access controls.
- Perform validation testing after firewall changes to confirm no service disruption.
- Coordinate implementation activities with onsite campus teams and external partners, including cryptographic parameter and shared secret updates.
- Support scheduling, execution, and technical assistance during approved maintenance window changes.
- Document VPN and firewall changes along with validation results.
What you bring
- Experience managing site-to-site IPsec VPNs.
- Hands-on experience upgrading VPNs from IKEv1 to IKEv2.
- Experience configuring and validating VPN tunnel connectivity.
- Knowledge of cryptographic standards and secure key management practices.
- Experience managing firewall access control rules.
- Experience with Cisco Firepower firewall platforms.
- Ability to implement least privilege network access controls.
- Experience performing post-change validation and troubleshooting network issues.
- Experience coordinating technical changes with internal teams and external partners.
- Experience working within structured maintenance window processes.
Helpful background
- Experience in healthcare or higher education IT environments.
- Familiarity with large-scale enterprise network environments.
- Experience supporting change management processes in production environments.
Preferred certifications
- Cisco CCNA Security or CCNP Security (or equivalent experience).
- CompTIA Security+ (or equivalent security certification).
- ITIL Foundation (preferred).
Technologies involved
IPsec VPN, IKEv1, IKEv2, pre-shared keys (PSKs), Cisco Firepower, cryptographic standards, secure key management practices