Network Security Posture Enhancement -- 2
Budget: $25 – $50 USD
I supervise our in-house network security team and want an external specialist to strengthen three critical areas—firewall management, intrusion detection / prevention, and ongoing network monitoring / analysis. The single objective is a demonstrable improvement in our overall security posture: cleaner rules, sharper detection, and clearer visibility that the team can maintain long after you finish.
Here’s how I picture the engagement:
• Begin with read-only access so you can baseline current firewall rules, IDS/IPS signatures, and telemetry.
• Present an action plan that outlines changes, testing steps, and potential impact.
• Optimise firewall policies, fine-tune IDS/IPS rules, and build or refine monitoring dashboards (Splunk, ELK, Security Onion, or comparable) with alerts mapped to MITRE ATT&CK.
• Document every change, include roll-back instructions, and schedule brief progress reviews—no rush, quality over speed.
Expected deliverables
1. Hardened firewall and IDS/IPS configurations with before/after comparison.
2. Re-usable monitoring dashboards and alert playbooks.
3. Final report summarising findings, implemented fixes, and future recommendations.
Experience with platforms such as Palo Alto, Fortinet, Cisco ASA/Firepower, Snort, Suricata, and major SIEM tools is highly valued. When you reply, let me know your preferred toolset and how you’d tackle the initial assessment.
Here’s how I picture the engagement:
• Begin with read-only access so you can baseline current firewall rules, IDS/IPS signatures, and telemetry.
• Present an action plan that outlines changes, testing steps, and potential impact.
• Optimise firewall policies, fine-tune IDS/IPS rules, and build or refine monitoring dashboards (Splunk, ELK, Security Onion, or comparable) with alerts mapped to MITRE ATT&CK.
• Document every change, include roll-back instructions, and schedule brief progress reviews—no rush, quality over speed.
Expected deliverables
1. Hardened firewall and IDS/IPS configurations with before/after comparison.
2. Re-usable monitoring dashboards and alert playbooks.
3. Final report summarising findings, implemented fixes, and future recommendations.
Experience with platforms such as Palo Alto, Fortinet, Cisco ASA/Firepower, Snort, Suricata, and major SIEM tools is highly valued. When you reply, let me know your preferred toolset and how you’d tackle the initial assessment.