Summary
What you’ll impact
The Senior Network Security Engineer will lead the design, implementation, and automation of hyperscale network security infrastructure, mentor engineering teams, and handle critical security incidents. This role requires deep expertise in network and security engineering, automation, and leadership to ensure compliance and integration of security best practices across the technology stack.
Responsibilities
What you'll do
- Mentoring junior and mid-level engineers, overseeing team activities and providing guidance in complex troubleshooting and architecture decisions
- Implementing and managing advanced security solutions using firewalls, proxy, system hardening, treat profile and segmentation strategies to secure the intellectual data
- Acting as a lead escalation for critical security incidents
- Developing automation playbooks, network security policies framework and consolidation, treat model and drive root cause analysis with corrective actions
- Overseeing network vulnerability assessments, penetration testing coordination and remediation planning
- Championing the integration of automated tools for infrastructure build, day two support and lifecycle management of all security infrastructure using platforms like Python, Terraform, and vendor APIs, leveraging tools such as Algosec, Tufin, Jenkins and Git
- Working closely with infrastructure, DevOps and application teams to embed security best practices throughout the technology stack
Requirements
What you’ll bring
- Extensive experience in network engineering and security engineering, along with proven architectural experience in trusted, untrusted and DMZ environments
- Proven leadership experience in a senior or lead engineering role, with the ability to drive the team and work individually
- Strong understanding of network protocols and the OSI model, with hands-on experience in TCP/UDP-based applications, routing, switching and load balancing
- Extensive knowledge of network security technologies, including firewalls, VPNs, proxies, MACsec, IPsec, HTTPS, certificate chains, DNS, NTP, AAA, and domain-based authentication and authorisation
- Expertise with multiple security vendors, such as, Palo Alto, Fortinet, Check Point and F5
- Strong understanding of Zero Trust principles, segmentation, and secure cloud networking in AWS or Azure
- Familiarity with scripting and automation using Python, Ansible, or Terraform for example
- Certifications such as CISSP, CCIE Security, GIAC (GSEC/GCIH/GXPN), Palo Alto, Fortinet or equivalent highly preferred
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future