Senior Network Security Engineer
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Network Security
The Senior Network Security Engineer to design, implement, operate, maintain, troubleshoot, and continuously improve enterprise network security infrastructure across on-premises, remote access, hybrid-cloud, and cloud-connected environments.
This role is responsible for senior-level engineering and day-to-day operational support of assigned security platforms, including firewalls, VPN and remote access services, MFA/token services, edge security, content filtering, network access control, security visibility platforms, logging, monitoring, vulnerability remediation, change management, and compliance documentation.
The ideal candidate is a hands‑on engineer who can support production systems, respond to incidents and service requests, perform upgrades and patching, manage configuration backups, maintain SOPs and diagrams, produce operational metrics, support audits, and coordinate effectively across network, cloud, identity, SOC/NOC, system owner, and application teams.
Scope and Technology Ownership- Primary scope:
- Cisco and Palo Alto firewall platforms, including Cisco ASA/Firepower/FTD/FMC and Palo Alto NGFW/Panorama/Global Protect. Remote access VPN, site-to-site VPN, cloud connectivity, partner connectivity, and secure access services.
- RSA SecurID Authentication Manager or equivalent MFA/two‑factor authentication platforms, including server operations, token lifecycle support, software updates, certificates, backups, logs, monitoring, and directory/VPN integration.
- Cloudflare or equivalent DNS, DDoS, WAF, CDN, Zero Trust/ZTNA, tunneling, access control, and edge security services.
- Network access control, content filtering, secure web/email gateway services, security visibility/packet broker platforms, monitoring, logging, SIEM integration, and AWS/Azure network security controls.
- Coordination scope:
- Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, security governance, system owner, application, and vendor teams during changes, incidents, troubleshooting, and compliance activities.
- Coordinate with load balancer and application delivery teams when application traffic, SSL/TLS, routing, DNS, WAF, firewall policy, or traffic‑flow issues require cross‑team support.
- This is not intended to be a primary F5 BIG-IP/LTM/GTM/ASM/Advanced WAF or load‑balancer administration role unless specifically assigned.
- Provide daily, weekly, monthly, and annual operational support for assigned network security systems, including ticket resolution, email/phone support, health checks, troubleshooting, metrics, status reporting, and operational validation.
- Respond to system alerts, monitoring events, customer requests, incidents, problem tickets, vulnerability notices, and urgent or critical project assignments.
- Perform configuration backups, log backup checks, configuration changes, configuration troubleshooting, backup/recovery validation, and post‑change verification.
- Maintain operational continuity by supporting device replacement, hardware fixes, vendor cases, maintenance windows, and emergency troubleshooting with minimal service disruption.
- Provide Tier II‑IV technical support for complex network security, VPN, MFA, firewall, content filtering, NAC, and connectivity issues.
- Design, configure, administer, maintain, and troubleshoot enterprise firewall solutions, including firewall rule bases, NAT, segmentation, threat prevention, VPN integration, logging, high availability, and secure configuration baselines.
- Install, configure, maintain, patch, and upgrade firewall hardware and software in new and existing network and cloud‑connected environments.
- Perform firewall rule reviews, rule recertification, policy cleanup, decommissioning of obsolete rules, configuration audits, and risk‑based optimization.
- Diagnose and resolve firewall issues involving connectivity, routing, DNS, VPNs, TLS/certificates, application flows, utilization, performance, packet captures, and log analysis.
- Ensure firewall capabilities are integrated with enterprise monitoring, logging, alerting, SIEM, incident response, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).