Summary
What you’ll impact
The Network Security Engineer at the organization will design, implement, and maintain the network security architecture for its hyperscale HPC and cloud environments. Reporting to the Manager of Network and Infrastructure Security, the role serves as the technical subject matter expert, collaborating with infrastructure and cloud teams to protect the infrastructure at scale.
Responsibilities
What you'll do
- Design, implement, and maintain network security architecture including firewalls, IDS/IPS, VPNs, and related controls across on-premises and cloud environments
- Serve as the team's primary subject matter expert for network security technologies, providing guidance and technical direction on complex security challenges
- Evaluate and recommend new network security technologies and solutions to continuously improve the organization's security posture
- Collaborate with infrastructure, cloud, and IT operations teams to ensure network security controls are integrated into new and existing environments
- Monitor network security events and alerts, investigate anomalies, and lead response efforts for network-based threats
- Develop and maintain network security standards, policies, and technical documentation
- Support network segmentation and micro-segmentation efforts by providing technical expertise on traffic flows, access controls, and policy enforcement
- Participate in security architecture reviews for new projects, systems, and third-party integrations to ensure network security requirements are addressed
- Mentor junior security engineers and contribute to the overall growth and development of the network security team
Requirements
What you’ll bring
- 5+ years of experience in network security engineering, with hands-on experience across trusted, untrusted, and DMZ environments
- Strong understanding of network protocols and the OSI model, with practical experience in TCP/UDP-based applications, routing, switching, and load balancing
- Experience securing both on-premises and cloud network environments (AWS, Azure, or GCP)
- Solid knowledge of network security technologies including firewalls, VPNs, proxies, MACsec, IPsec, HTTPS, certificate chains, DNS, NTP, AAA, and domain-based authentication and authorization
- Experience with one or more leading security vendors such as Palo Alto, Fortinet, Check Point, or F5
- Familiarity with Zero Trust principles, network segmentation, and secure cloud networking in AWS or Azure
- Hands-on experience with scripting and automation using Python, Ansible, or Terraform
- Excellent communication skills with the ability to document technical findings and present recommendations to both technical and non-technical audiences