Demo

Network Security Engineer

Randstad Digital
Rancho Cordova, CA Contractor
POSTED ON 5/23/2026
AVAILABLE BEFORE 6/22/2026
job summary:

Our client is seeking a contract resource to



support modernization of site-to-site IPsec VPN tunnels and firewall access



control policy hardening within the client's environment. This role



will focus on upgrading existing VPN tunnels from IKEv1 to IKEv2 and ensuring cryptographic configurations meet organizational standards. The contractor will also review and refine firewall rules on Cisco Firepower



systems to reduce overly permissive access and align configurations with approved requirements. This work supports improved security and controlled network connectivity across the client and its external



partners.



Responsibilities



- Review approximately 80 existing site-to-site IPsec VPN tunnels



- Upgrade approximately 50 VPN tunnels from IKEv1 to IKEv2



- Ensure VPN configurations align with organizational cryptographic standards



- Update pre-shared keys (PSKs) to meet a minimum 20-character requirement



- Validate VPN tunnel functionality after each change



- Review approximately 10 firewall access control rules on Cisco Firepower



- Modify firewall rules to remove overly permissive or broad subnet access



- Restrict firewall rules to required source/destination networks, ports, and protocols



- Apply principle of least privilege in firewall rule updates



- Perform validation testing after firewall changes to confirm no service disruption



- Coordinate implementation activities with UC Davis campus teams and external partners



- Support execution of approved maintenance window changes



- Provide technical assistance during implementation activities



- Document VPN and firewall changes and validation results



- Coordinate cryptographic parameter and shared secret updates with external partners



- Support scheduling and execution of maintenance window activities



Required Technical Experience



- Experience managing site-to-site IPsec VPNs



- Hands-on experience upgrading VPNs from IKEv1 to IKEv2



- Experience configuring and validating VPN tunnel connectivity



- Knowledge of cryptographic standards and secure key management practices



- Experience managing firewall access control rules



- Experience with Cisco Firepower firewall platforms



- Ability to implement least privilege network access controls



- Experience performing post-change validation and troubleshooting network issues



- Experience coordinating technical changes with internal teams and external partners



- Experience working within structured maintenance window processes



Preferred Qualifications



- Experience in healthcare or higher education IT environments



- Familiarity with large-scale enterprise network environments



- Experience supporting change management processes in production environments



Desired Certifications



- Cisco CCNA Security or CCNP Security (or equivalent experience)



- CompTIA Security or equivalent security certification



- ITIL Foundation (preferred)







location: Rancho Cordova, California

job type: Contract

salary: $70 - 80 per hour

work hours: 8am to 5pm

education: No Degree Required



responsibilities:

Our client is seeking a contract resource to



support modernization of site-to-site IPsec VPN tunnels and firewall access



control policy hardening within the client's environment. This role



will focus on upgrading existing VPN tunnels from IKEv1 to IKEv2 and ensuring cryptographic configurations meet organizational standards. The contractor will also review and refine firewall rules on Cisco Firepower



systems to reduce overly permissive access and align configurations with approved requirements. This work supports improved security and controlled network connectivity across the client and its external



partners.



Responsibilities



- Review approximately 80 existing site-to-site IPsec VPN tunnels



- Upgrade approximately 50 VPN tunnels from IKEv1 to IKEv2



- Ensure VPN configurations align with organizational cryptographic standards



- Update pre-shared keys (PSKs) to meet a minimum 20-character requirement



- Validate VPN tunnel functionality after each change



- Review approximately 10 firewall access control rules on Cisco Firepower



- Modify firewall rules to remove overly permissive or broad subnet access



- Restrict firewall rules to required source/destination networks, ports, and protocols



- Apply principle of least privilege in firewall rule updates



- Perform validation testing after firewall changes to confirm no service disruption



- Coordinate implementation activities with UC Davis campus teams and external partners



- Support execution of approved maintenance window changes



- Provide technical assistance during implementation activities



- Document VPN and firewall changes and validation results



- Coordinate cryptographic parameter and shared secret updates with external partners



- Support scheduling and execution of maintenance window activities



Required Technical Experience



- Experience managing site-to-site IPsec VPNs



- Hands-on experience upgrading VPNs from IKEv1 to IKEv2



- Experience configuring and validating VPN tunnel connectivity



- Knowledge of cryptographic standards and secure key management practices



- Experience managing firewall access control rules



- Experience with Cisco Firepower firewall platforms



- Ability to implement least privilege network access controls



- Experience performing post-change validation and troubleshooting network issues



- Experience coordinating technical changes with internal teams and external partners



- Experience working within structured maintenance window processes



Preferred Qualifications



- Experience in healthcare or higher education IT environments



- Familiarity with large-scale enterprise network environments



- Experience supporting change management processes in production environments



Desired Certifications



- Cisco CCNA Security or CCNP Security (or equivalent experience)



- CompTIA Security or equivalent security certification



- ITIL Foundation (preferred)





qualifications:

Our client is seeking a contract resource to



support modernization of site-to-site IPsec VPN tunnels and firewall access



control policy hardening within the client's environment. This role



will focus on upgrading existing VPN tunnels from IKEv1 to IKEv2 and ensuring cryptographic configurations meet organizational standards. The contractor will also review and refine firewall rules on Cisco Firepower



systems to reduce overly permissive access and align configurations with approved requirements. This work supports improved security and controlled network connectivity across the client and its external



partners.



Responsibilities



- Review approximately 80 existing site-to-site IPsec VPN tunnels



- Upgrade approximately 50 VPN tunnels from IKEv1 to IKEv2



- Ensure VPN configurations align with organizational cryptographic standards



- Update pre-shared keys (PSKs) to meet a minimum 20-character requirement



- Validate VPN tunnel functionality after each change



- Review approximately 10 firewall access control rules on Cisco Firepower



- Modify firewall rules to remove overly permissive or broad subnet access



- Restrict firewall rules to required source/destination networks, ports, and protocols



- Apply principle of least privilege in firewall rule updates



- Perform validation testing after firewall changes to confirm no service disruption



- Coordinate implementation activities with UC Davis campus teams and external partners



- Support execution of approved maintenance window changes



- Provide technical assistance during implementation activities



- Document VPN and firewall changes and validation results



- Coordinate cryptographic parameter and shared secret updates with external partners



- Support scheduling and execution of maintenance window activities



Required Technical Experience



- Experience managing site-to-site IPsec VPNs



- Hands-on experience upgrading VPNs from IKEv1 to IKEv2



- Experience configuring and validating VPN tunnel connectivity



- Knowledge of cryptographic standards and secure key management practices



- Experience managing firewall access control rules



- Experience with Cisco Firepower firewall platforms



- Ability to implement least privilege network access controls



- Experience performing post-change validation and troubleshooting network issues



- Experience coordinating technical changes with internal teams and external partners



- Experience working within structured maintenance window processes



Preferred Qu


Salary : $70

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Network Security Engineer?

Sign up to receive alerts about other jobs on the Network Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,720 - $106,708
Income Estimation: 
$108,098 - $130,480
Income Estimation: 
$71,709 - $89,893
Income Estimation: 
$87,720 - $106,708
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Randstad Digital

  • Randstad Digital Smithfield, RI
  • job summary: Extensive knowledge of infrastructure as code (Terraform, CFT, CDK, etc.). Hands-on experience with continuous integration and continuous deli... more
  • 1 Day Ago

  • Randstad Digital West Des Moines, IA
  • job summary: What You Can Expect In This Role Enterprise data engineers will be responsible for designing and implementing scalable data and integration so... more
  • 1 Day Ago

  • Randstad Digital Hartford, CT
  • job summary: Enterprise Healthcare client has an immediate opening for a highly motivated Data analyst to join their dynamic and growing team. All qualifie... more
  • 1 Day Ago

  • Randstad Digital Minneapolis, MN
  • job summary: Enterprise Healthcare client has an immediate opening for a highly motivated Systems Mgmt Analyst to join their dynamic and growing team. All ... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Network Security Engineer jobs in the Rancho Cordova, CA area that may be a better fit.

  • Apex Systems Rancho Cordova, CA
  • Job#: 3034854 Job Description: Network Security Engineer Location: Rancho Cordova, California (Hybrid) Employment Type: Contract Role Overview We are seeki... more
  • 3 Days Ago

  • Apple, Inc. Sacramento, CA
  • Apple is where individual imaginations gather together, committing to the values that lead to great work. Every new product we build, service we create, or... more
  • 4 Days Ago

AI Assistant is available now!

Feel free to start your new journey!