Network Security Engineer III
Listed on 2026-06-18
-
IT/Tech
Cybersecurity
Category/Area of Expertise
IT & Technology
JobRequisition
485754
AddressUSA-MA-Quincy-1385 Hancock Street
Store CodeInfrastructure-Network (5118708)
Ahold Delhaize Group is one of the world’s largest food retail groups and a leader in both supermarkets and e‑Commerce. Its family of great, local brands serves more than 50 million customers each week in Europe, the United States and Indonesia. Together, these brands employ more than 420,000 associates in more than 7,000 grocery and specialty stores. Our Ahold Delhaize Group is based in Zaandam in the Netherlands, but Ahold Delhaize Group associates also work in all the countries we serve.
This team supports all our great local brands in finance, HR, IT, legal, communications, sustainable retailing, and other key functions.
The Sr. Network Security Engineer will lead the engineering, delivery, and operations of ADUSA’s network security platforms with a key focus on zero trust architecture, next‑generation firewalls, and secure connectivity across the enterprise. This role is responsible for the technical design, implementation, and management of mission‑critical network security infrastructure spanning ADUSA’s data centers, cloud environments, retail locations, corporate offices and distribution centers.
The Sr. Network Security Engineer will drive the multi‑year strategy to transform ADUSA’s network security posture, championing zero trust principles and ensuring all network traffic is inspected, segmented and secured in alignment with PCI‑DSS, HIPAA and other regulatory compliance frameworks. This role has overall responsibility for the delivery of secure connectivity, threat mitigation, incident response coordination, firewall and proxy platform management, and policy enforcement across all brands.
Flexible/HybridWork Schedule
Our flexible/hybrid work schedule includes 3 in‑person days at one of our core locations and 2 remote days. Our core office locations are Salisbury, NC & Quincy, MA.
Work AuthorizationApplicants must be currently authorized to work in the United States on a full‑time basis.
Duties and Responsibilities- Lead the design, engineering and operations of ADUSA’s network security platforms including next‑generation firewalls (Palo Alto, Fortinet), secure web gateways and cloud security solutions (Zscaler ZIA/ZPA), ensuring high availability, performance and compliance across all environments.
- Architect and implement zero trust network security frameworks across the enterprise, defining and enforcing micro‑segmentation, least‑privilege access policies, identity‑based authentication and continuous verification strategies to minimise the attack surface.
- Manage and maintain firewall rule sets, security policies, NAT configurations and VPN infrastructure across Palo Alto and Fortinet platforms, ensuring policies are optimised, documented and aligned with PCI‑DSS, HIPAA and corporate security standards.
- Oversee Zscaler cloud security platform administration including ZIA (Zscaler Internet Access) and ZPA (Zscaler Private Access), managing URL filtering, SSL inspection, DLP policies, cloud firewall rules and application access policies for all users and locations.
- Drive compliance initiatives by implementing and maintaining network security controls required for PCI‑DSS, HIPAA, SOX and other regulatory frameworks; lead audit preparation activities, evidence collection and remediation of security findings.
- Act as a subject matter expert in network security design and architecture, evaluating emerging threats and technologies, and providing recommendations to the Network Architecture team for continuous improvement of the security posture.
- Participate in security incident response and forensic analysis, working with the SOC, threat intelligence and risk teams to investigate network‑based threats, contain breaches and implement preventive controls.
- Develop and maintain network security automation to streamline firewall provisioning, policy deployment, configuration compliance checks and security reporting across all platforms.
- Review and establish security documentation, standard operating procedures and runbooks; ensure these standards…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).