×
Register Here to Apply for Jobs or Post Jobs. X

Network Engineer

Remote / Online - Candidates ideally in
Richmond, Henrico County, Virginia, 23214, USA
Listing for: Apex Systems
Remote/Work from Home position
Listed on 2026-08-29
Job specializations:
  • IT/Tech
    Cybersecurity, Network Engineer, Network Security, Systems Engineer
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

Job Description

Client is seeking an experienced Network Engineer to design, secure, and operate the agency’s hybrid network across on-premise infrastructure and AWS as part of a major migration from on-premise systems to AWS. This role owns end-to-end connectivity for mission-critical state police systems spanning 500+ remote sites and applications including VCIN, CCH, and Live Scan while engineering the highly available site-to-site VPN and hybrid connectivity fabric that links VSP facilities, VITA and partner networks, and AWS.

You will work closely with Infrastructure, Platform Engineering, and with state partners, to ensure all network components meet CJIS, COV, and FBI security requirements. Hybrid Network Operations & Secure Connectivity

  • Maintain a stable, resilient, and secured network across 500+ remote offices, ensuring reliable connectivity for mission-critical state police applications (VCIN, CCH, Live Scan, and similar).
  • Govern ACLs, routing policies, and device configurations through quarterly reviews evidencing alignment with security and compliance requirements.
  • Provide support on a 24x7 on-call rotation, returning critical production calls within 30 minutes and driving network incidents to resolution.
  • Review and update assigned Foot Prints and other tickets on receipt and work with Help Desk, Procurement and other teams on equipment moves, adds, and changes.
  • Perform onsite surveys for site modernization, new site implementations, and decommissioning. Install, terminate, and test structured cabling for new deployments and office expansions, and safely remove outdated hardware and cabling in compliance with asset disposal protocols. Site-to-Site VPN Engineering & High Availability
  • Design, build, and operate redundant IPsec site-to-site VPNs connecting clients facilities, VITA and partner networks, and Cloud, including the tunnels supporting clients operational, and law enforcement systems.
  • Ensure resilience across customer gateways and diverse carrier paths so no single device, circuit is a point of failure.
  • Set up dynamic failover using BGP over VPN by tuning basic route settings and filters so traffic automatically moves to the backup connection when needed.
  • Standardize IKEv2 settings including Phase 1/Phase 2 timers, PFS groups, rekey behavior, and retire outdated cipher suites to improve VPN security and consistency
  • Enable DPD, tunnel state monitoring, and per-tunnel alerting so partial failures surface before users report them.
  • Build and manage AWS Site-to-Site VPN attachments to Transit Gateway and Virtual Private Gateway, using accelerated VPN where latency or jitter sensitivity requires it.
  • Execute scheduled failover tests against RTO targets, manage pre-shared keys and certificates through approved secrets management, and maintain a complete VPN inventory of endpoints, tunnel pairs, encryption domains, and maintenance windows.
  • Support AWS Cloud migration efforts, hybrid connectivity setup, and post-migration stabilization.
  • Design, document, and validate VPC networking subnets, route tables, security groups, network ACLs, VPC endpoints and Private Link under an IP address management and CIDR strategy.
  • Build and operate Transit Gateway hub-and-spoke topologies with route table segmentation and controlled inter-VPC and inter-account routing.
  • Implement AWS Direct Connect and hybrid DNS using Route 53 Resolver endpoints and forwarding rules.
  • Deploy ingress and egress inspection using AWS Network Firewall, Gateway Load Balancer, or approved third-party virtual appliances.
  • Perform discovery and remediate on-prem network gaps and segmentation issues that could affect a secure cloud migration.
  • Monitor post-migration connectivity, routing, access controls, network performance, and collaborate with state partners, cloud teams, and vendors to ensure secure, compliant, and resilient hybrid designs.
  • Apply secure-by-design, least-privilege, and Zero Trust principles to routing, segmentation, encrypted transport, and access controls, including MFA for all admin access.
  • Align network configurations and audit evidence with CJIS Security Policy, COV, and FBI security requirements.
  • Strengthen device access controls by using centralized login and auditing systems, ensuring only authorized users can manage network equipment.
  • Support ongoing vulnerability scanning, remediation planning, and periodic access reviews across the network estate.
  • Use VPC Flow Logs, Traffic Mirroring, Cloud Trail, and Guard Duty findings for network threat detection, investigation, and forensics.
  • Identify network single points of failure across infrastructure and routing, and ensure DR segments and backup paths meet the same security standards.
  • Maintain accurate hardware and software inventory for SPHQ and DR, documenting new network equipment in Foot Prints within two weeks of arrival.
  • Deliver network components as code using Terraform, Cloud Formation, Ansible under Git-based version control with peer review, automating configuration deployment,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary