1

Ids Ips Network Engineer Jobs (NOW HIRING)

The Network Engineer II serves as a senior technical leader responsible for the design, security ... Strong knowledge of network security principles, including firewalls, IDS/IPS, VPNs, and ...

The Network Engineer II serves as a senior technical leader responsible for the design, security ... Strong knowledge of network security principles, including firewalls, IDS/IPS, VPNs, and ...

Network Engineer

Caldwell, ID · On-site

$72K - $86K/yr

The Network Engineer identifies and recommends best options to optimize both the physical and ... and prevention (IDS/IPS), SSL interception, application control, and malware protection

The Network Engineer identifies and recommends best options to optimize both the physical and ... and prevention (IDS/IPS), SSL interception, application control, and malware protection

Cloud Network Engineer

Washington, DC · On-site

$120K - $170K/yr

Proficiency in network security practices and tools (IDS/IPS, firewalls, VPNs). * Experience ... Azure Network Engineer Associate * Google Cloud Certified: Professional Cloud Network Engineer

Senior Network Engineer

Honolulu, HI · On-site

$102K - $140K/yr

IDS/IPS capabilities; diagnostic tools; MIB/MRTG concepts; OTDR, cable testers, sniffers, and EIA/TIA cabling standards. * Experience implementing and maintaining STIG-compliant configurations ...

Senior Network Engineer

San Antonio, TX · On-site

$94K - $129K/yr

IDS/IPS capabilities; diagnostic tools; MIB/MRTG concepts; OTDR, cable testers, sniffers, and EIA/TIA cabling standards. * Experience implementing and maintaining STIG-compliant configurations ...

Senior Network Engineer

San Antonio, TX · On-site

$93K - $128K/yr

IDS/IPS capabilities; diagnostic tools; MIB/MRTG concepts; OTDR, cable testers, sniffers, and EIA/TIA cabling standards. * Experience implementing and maintaining STIG-compliant configurations ...

Network Architect

Fort Belvoir, VA · On-site

$120K - $140K/hr

The Network Engineer will work closely with the government technical leadership team to help drive ... In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ...

Network Architect

Fort Belvoir, VA · On-site

$73.25 - $98/hr

The Network Engineer will work closely with the government technical leadership team to help drive ... In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ...

Senior Network Engineer

San Jose, CA · On-site

$122K - $167K/yr

We are seeking a Senior Network Engineer to support, design, and maintain our enterprise network ... Security experience: firewall log analysis, incident response support, IDS/IPS, network ...

Senior Network Engineer

Honolulu, HI · On-site

$102K - $140K/yr

IDS/IPS capabilities; diagnostic tools; MIB/MRTG concepts; OTDR, cable testers, sniffers, and EIA/TIA cabling standards. * Experience implementing and maintaining STIG-compliant configurations ...

Network Architect

Fort Belvoir, VA · On-site

$73.25 - $98/hr

The Network Engineer will work closely with the government technical leadership team to help drive ... In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat ...

New

The Network Engineer's responsibilities include planning, designing and implementing best practice ... Network-based Intrusion Detection/Prevention Systems (IDS/IPS) * Host-based Intrusion Detection ...

Network Engineer

Milwaukee, WI · On-site

$45 - $50/hr

... VPNs, IDS/IPS systems Plan and execute network upgrades and migrations with minimal downtime ... network engineers Collaborate with cross-functional teams including systems, security, and ...

Showing results 41-60

Ids Ips Network Engineer information

See salary details

$31K

$109K

$158K

How much do ids ips network engineer jobs pay per year?

As of Sep 14, 2026, the average yearly pay for ids ips network engineer in the United States is $109,040.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $133,500.00 per year, depending on experience, location, and employer.

What is an IDS IPS network engineer?

IDS/IPS Network Engineers are IT professionals who specialize in the design, deployment, management, and maintenance of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) within an organization's network infrastructure. Their primary goal is to monitor network traffic for suspicious activity, respond to potential security threats, and help prevent unauthorized access or attacks. They configure and fine-tune IDS/IPS devices, analyze security alerts, and work closely with other security teams to ensure a robust defense against cyber threats. Additionally, IDS/IPS Network Engineers may assist in incident response and security policy development.

What are the key skills and qualifications needed to thrive as an IDS IPS network engineer?

To thrive as an IDS/IPS Network Engineer, you need a solid understanding of network protocols, cybersecurity principles, and hands-on experience with intrusion detection and prevention systems, often supported by a degree in computer science or related certifications like CISSP or CEH. Familiarity with tools such as Snort, Suricata, Cisco Firepower, and SIEM platforms is essential for monitoring and analyzing network traffic. Strong analytical thinking, attention to detail, and effective communication skills help you quickly identify threats and collaborate with IT teams. These skills are crucial for protecting organizational assets, minimizing security risks, and ensuring network integrity.

What are some common challenges faced by IDS IPS network engineers when managing large-scale enterprise networks?

IDS/IPS Network Engineers often encounter challenges such as tuning detection systems to minimize false positives while ensuring effective threat detection, especially in large and complex network environments. Managing the high volume of alerts and distinguishing genuine threats from benign anomalies requires continuous monitoring and expertise. Additionally, integrating IDS/IPS solutions with other security tools and maintaining system performance without introducing network latency are crucial aspects of the role. Collaboration with security analysts and IT teams is essential to ensure coordinated incident response and ongoing improvement of defense strategies.

What are popular job titles related to Ids Ips Network Engineer jobs?

For Ids Ips Network Engineer jobs, the most frequently searched job titles are:

CSfC Network Engineer Subject Matter Expert (SME)

Fort Belvoir, VA • On-site

Leidos
IT Services • 10K+ employees

$118K - $161K/yr

Full-time

Posted 11 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 154 frontline employees who took The Breakroom Quiz


Job description

Leidos is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.
Clearance: Must have an active TS/SCI clearance at time of consideration. U.S. Citizen is a must.
Primary Responsibilities:
The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.
  • Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Understanding of NIAP approved list and monitors for changes
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation.
  • Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection.
  • Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling.
  • Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure.
  • Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission.

Basic Qualifications:
  • Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree.
  • 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments
  • Active TS/SCI Clearance
  • Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
  • Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP
  • Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF).
  • Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles.
  • Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies.
  • Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization.
  • Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN).
  • Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs).
  • Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations.
  • Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:
September 3, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range -
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media