Remote job
Network Security Engineer
Job details
About this role
Role overview A hybrid network engineering and cybersecurity role within the Network team, responsible for implementing end-to-end network security architectures across enterprise and data center backbone and fabric environments. The position partners with network architects and management to guide designs through security review and approval, then operates and maintains the implemented solutions day-to-day, with a strong hands-on focus on leading firewall platforms and complex routing and switching designs.
Responsibilities - Implement and maintain Zero Trust-aligned security architectures for both enterprise and data center networks. - Configure Layer 3/4 and Multi-VRF segmentation, security policies, and secure remote access. - Implement and test large hyperscale data center security solutions, including IPS/NDR and Anti-DDoS systems. - Integrate next-generation firewall (NGFW) platforms with identity providers such as Microsoft Entra ID and Okta, and maintain NGFW management, automation, and logging capabilities. - Implement and maintain security capabilities including Layer 7 application inspection, IPS, user identification, ZTNA, and SASE integrations. - Integrate and operate monitoring tools such as Zabbix, Grafana, and Akvorado. - Perform regular security hardening, vulnerability management, and patching on network and infrastructure devices, verifying the effectiveness of these procedures.
Requirements - Experience in networking and security protocols including TCP/IP, HTTP(S), DNS, TLS, IPsec, and routing protocols. - Knowledge of backbone and data center technologies such as EVPN, L3VPN MPLS, MP-BGP, and L2VPN. - Hands-on experience with next-generation firewalls such as Palo Alto Networks, Check Point, or similar platforms. - Experience with automation using Python, Go, or equivalent languages. - Proficiency in Unix/Linux and experience with major network vendors such as Cisco, Juniper, or Aruba. - Experience configuring and troubleshooting NGFW capabilities and integrations, including IPS, User-ID, Microsoft Entra ID, and ZTNA. - Professional working proficiency in English.
Nice to have - Good knowledge of IPv6. - Experience with automation tools such as Ansible, Terraform, NetBox, or SaltStack. - Experience with large-scale, highly available distributed systems. - Familiarity with Zero Trust principles and micro-segmentation approaches. - Relevant certifications such as CCNP/CCIE, PCNSE, or NSE 4/7. - Familiarity with monitoring, logging, and security analytics tools such as Splunk; EDR/XDR platforms such as CrowdStrike; and centralized NGFW management platforms such as Panorama, Strata Cloud Manager, or FortiManager. - Exposure to DevSecOps practices, CSPM/CWPP platforms, offensive security, or frameworks such as ISO/IEC 27001, NIST CSF, and GDPR.
Benefits and work setup - Competitive compensation with career growth opportunities. - Flexibility, ownership, and a collaborative, innovative culture. - Opportunity to contribute to high-impact AI infrastructure projects alongside international teams.