1

Ids Ips Network Engineer Jobs (NOW HIRING)

Network Engineer/Architect

Springfield, VA ยท On-site

$109K - $150K/yr

In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ... network engineering experience within DoD/DoW, federal, or defense contractor enterprise ...

New

Job Title- Network Engineer with Data Center Project Location - Baton Rouge LA 70803 - Hybrid ... IDS/IPS, Antivirus, Web-filtering, SSL * encrypt/decrypt, two-factor authentication, SSL VPN.

Network Engineer (SME)

Fort Belvoir, VA ยท On-site

$118K - $161K/yr

In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ... network engineering experience within DoD/DoW, federal, or defense contractor enterprise ...

$77K - $105K/yr

In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ... network engineering experience within DoD/DoW, federal, or defense contractor enterprise ...

Network Administrator

Newport, RI ยท On-site

$60K - $65K/yr

... Engineer, Deployed Support Specialist, CCNA, Cisco Networking, Active Directory, DNS Administration, Exchange Administration, Firewall Administration, IDS, IPS, Systems Administrator, Secret ...

Cisco Network Engineer Location:Raleigh, NC Duration: 12+ months contract position Client: NCDOT ... Knowledge and experience with current Cisco IDS/IPS or other vendor data center class IDS/IPS ...

Network Lead

Huntsville, AL ยท On-site

$100K - $137K/yr

Senior network engineering and telecommunications experience supporting enterprise LAN/WAN, voice ... IDS/IPS, Active Directory dependencies, switches, routers, hubs, bridges, cabling, fiber optics ...

Showing results 21-40

Ids Ips Network Engineer information

See salary details

$31K

$109K

$158K

How much do ids ips network engineer jobs pay per year?

As of Sep 14, 2026, the average yearly pay for ids ips network engineer in the United States is $109,040.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $133,500.00 per year, depending on experience, location, and employer.

What is an IDS IPS network engineer?

IDS/IPS Network Engineers are IT professionals who specialize in the design, deployment, management, and maintenance of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) within an organization's network infrastructure. Their primary goal is to monitor network traffic for suspicious activity, respond to potential security threats, and help prevent unauthorized access or attacks. They configure and fine-tune IDS/IPS devices, analyze security alerts, and work closely with other security teams to ensure a robust defense against cyber threats. Additionally, IDS/IPS Network Engineers may assist in incident response and security policy development.

What are the key skills and qualifications needed to thrive as an IDS IPS network engineer?

To thrive as an IDS/IPS Network Engineer, you need a solid understanding of network protocols, cybersecurity principles, and hands-on experience with intrusion detection and prevention systems, often supported by a degree in computer science or related certifications like CISSP or CEH. Familiarity with tools such as Snort, Suricata, Cisco Firepower, and SIEM platforms is essential for monitoring and analyzing network traffic. Strong analytical thinking, attention to detail, and effective communication skills help you quickly identify threats and collaborate with IT teams. These skills are crucial for protecting organizational assets, minimizing security risks, and ensuring network integrity.

What are some common challenges faced by IDS IPS network engineers when managing large-scale enterprise networks?

IDS/IPS Network Engineers often encounter challenges such as tuning detection systems to minimize false positives while ensuring effective threat detection, especially in large and complex network environments. Managing the high volume of alerts and distinguishing genuine threats from benign anomalies requires continuous monitoring and expertise. Additionally, integrating IDS/IPS solutions with other security tools and maintaining system performance without introducing network latency are crucial aspects of the role. Collaboration with security analysts and IT teams is essential to ensure coordinated incident response and ongoing improvement of defense strategies.

What are popular job titles related to Ids Ips Network Engineer jobs?

For Ids Ips Network Engineer jobs, the most frequently searched job titles are:

Network Engineer/Architect

Fort Belvoir, VA โ€ข On-site

$155K - $165K/yr

Full-time

Medical, Dental, Retirement, PTO

Posted 6 days ago


Job description

Benefits:
  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Profit sharing
  • Training & development
  • Tuition assistance
  • Vision insurance

Job Description
SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.
Primary Responsibilities:

The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.
  • Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN)  experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Understanding of NIAP approved list and monitors for changes
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation.
  • Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection.
  • Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling.
  • Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure.
  • Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission.
Required Qualifications:

  • Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree.
  • 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments
  • Active TS/SCI Clearance
  • Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
  • Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP
  • Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF).
  • Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles.
  • Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies.
  • Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization.
  • Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN).
  • Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs).
  • Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations.
  • Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).