As a Senior Network Security Engineer (Firewall), you will work within a team responsible for secure, stable and compliant network-security services. The role remains strongly technical, with increased ownership for complex implementations, troubleshooting and operational quality.
You will implement and operate firewall, VPN, SSL interception and network micro-segmentation services together with the team. Responsibilities include security policy implementation, lifecycle management, upgrades, infrastructure changes and resolution of complex incidents.
You will provide technical guidance to engineers, contribute to technical reviews and help improve documentation, standards and operational procedures. The role does not include direct people-management responsibility.
Key Activities:
Administration and operation of firewall, Site-to-Site VPN, Remote Access/SSL VPN and SSL Interception environments
Evaluation, technical validation and configuration of firewall policy requests in accordance with security standards and least-privilege principles
Handling of complex Requests, Incidents, Changes and Problems, including root-cause analysis and coordination of corrective actions
Planning and implementation of firewall upgrades, lifecycle activities and infrastructure changes with appropriate testing, rollback and documentation
Advising customers and application teams on secure connectivity, traffic flows and firewall rule design
Setup and troubleshooting of traffic flows and segmentation policies using Guardicore or equivalent micro-segmentation technology.
Setup, troubleshooting and maintenance of Site-to-Site VPN connections, including IPSec-related issues
Performing packet-flow analysis and end-to-end troubleshooting across firewall, routing, proxy, DNS and application dependencies
Supporting high-availability platforms and participating in service restoration for priority incidents when required
Reviewing technical implementations and providing practical guidance to less-experienced engineers without formal line-management responsibility
Communicating with internal departments, global network/security counterparts, external companies and vendors
Coordinating software maintenance, upgrades and agent rollouts with vendors, server administrators and relevant stakeholders
Contributing to continuous improvement, automation opportunities, operational controls and reduction of recurring incidents
Ensuring company guidelines, internal requirements, security standards and change-management controls are followed
Maintaining accurate technical documentation, operational procedures, knowledge articles and configuration records
Main Skills Requirement:
Understanding Network Security principles and best practices
Experience with tools for network-micro segmentation, policy-Settings to regulate traffic flows based on labels (preferred with Guardicore)
Experience with firewall technology
Network theory and services (TCP/IP, UDP/IP, 7 layers of OSI, DNS, DHCP)
Experience running and supporting high availability infrastructure
Experience in x86 Server Operating Systems, Windows and Linux (RHEL)
Experience in Virtualization VMware
Experience with Office 365, especially performing and analyzing pivots in Excel
Experience working with IPSec/SSL
Alternative Skills Requirement:
Experience with large network integration with Public Cloud (Azure and/or GCP)
Packet capture analysis as required during incident resolution using various tools such as Wireshark, and network protocol analyzers
Ability to demonstrate analytical end to end troubleshooting and problem-solving skills
Experience in organizational tasks, such as Agent-Rollout in a large company with foreign branches.
Basic knowledge in SIEM aspects and the corresponding tools such as ArcSight.
Experience with SSL Interception technologies
Personal Skills:
6 to 8 years of hands-on experience in enterprise firewall or network-security operations
Strong analytical troubleshooting and stakeholder communication skills
Ability to work independently, take technical ownership and provide guidance within the team
Experience in a regulated, global or large-scale enterprise environment is an advantage
Formal Education:
Bachelor’s degree in Information Technology, Computer Science, Network Engineering or a related discipline; equivalent relevant professional experience may be considered
Relevant firewall or network-security certification is an advantage (for example, Fortinet, Cisco or equivalent)