×
Register Here to Apply for Jobs or Post Jobs. X

Consultant - Network Security

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: EPAM Systems Inc
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Systems Engineer
Salary/Wage Range or Industry Benchmark: 140000 - 200000 USD Yearly USD 140000.00 200000.00 YEAR
Job Description & How to Apply Below

We are seeking a Consultant – Network Security to design, implement, and operate secure, compliant network segmentation between regional environments and Global networks. This role leverages a standardized control stack including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), and Cloudflare for DDoS mitigation, WAF, and application protection. The position blends architecture, hands-on engineering, automation, and L3/L4 operational leadership to deliver policy-driven connectivity under strict regulatory and operational requirements.

Responsibilities
  • Define trust zones, routing boundaries, and inter-zone controls for regional and Global Network, covering north-south and east-west paths, micro-segmentation for sensitive tiers, and explicit cross-border allow-lists
  • Produce HLD/LLD, threat models, and control mappings aligned to internal standards and regional regulation to enable secure communication between regional and Global customer sites
  • Design and operate dual-vendor firewall perimeters with clear control allocation, HA/cluster design, deterministic failover, NAT domain strategy, SSL/TLS inspection governance, and Threat Prevention/Wild Fire/URL filtering tuned for jurisdiction
  • Engineer ZIA for identity-aware egress controls, SSL inspection with jurisdiction-aware bypasses, inline CASB/DLP, and sanctioned SaaS governance
  • Implement ZPA for per-application zero-trust access, with connector placement, posture checks, conditional access, and app segmentation replacing legacy VPN where feasible
  • Design and deliver Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site for cloud hybrid connectivity
  • Deploy Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, and integrate with on-prem perimeters for layered defence
  • Engineer SD-WAN/MPLS/SASE paths with policy-based routing, strong encryption, and defined key custody/rotation by jurisdiction
  • Translate regulatory and internal control requirements into enforceable technical controls for logging, data residency, TLS inspection scope, and lawful intercept considerations
  • Normalise telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM with regional data handling rules, and build detections for cross-border anomalies and policy drift
  • Lead L3/L4 incidents, coordinate issue containment, and drive RCAs with corrective actions codified
  • Manage firewall, Zscaler, and Cloudflare policy through Terraform/Ansible and vendor APIs, and implement CI/CD with policy linting, unit tests, and path simulation
Requirements
  • 5+ years of experience in network security architecture and operations, with a focus on cross-border or multi-region connectivity
  • Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management
  • Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture
  • Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies
  • Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing
  • Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols
  • Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept
  • Familiarity with SIEM platforms and telemetry normalisation for cross-border security monitoring
  • Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration
  • Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary