About the Role
Work Flexibility: Hybrid Position Summary Designs, implements, and supports enterprise network security technologies that protect organizational infrastructure from cyber threats — managing firewalls, secure remote access, network segmentation, intrusion prevention, secure DNS, VPN, and cloud networking security in partnership with infrastructure and cybersecurity teams. What will you do: Design, engineer, and continuously improve enterprise network security solutions protecting Internet-facing, extranet, third-party, and internal environments, including next-generation firewalls, VPN, IDS/IPS, secure web gateways, DNS security, NAC, DDoS protection, and micro-segmentation. Develop secure network architectures supporting data centers, cloud environments (AWS, Azure, Google Cloud), remote workforce connectivity, and manufacturing locations. Partner with Enterprise Architecture to align network designs with Zero Trust principles and enterprise cybersecurity standards. Engineer secure network segmentation strategies, security zones, and trust boundaries for Internet-facing applications, DMZs, extranets, third-party connectivity, and internal environments to reduce attack surfaces and limit lateral movement. Develop, review, and optimize firewall policies, security rules, access control lists, and routing configurations per corporate standards. Perform network security assessments, configuration reviews, and architecture evaluations to identify gaps and recommend improvements. Lead implementation of new network security technologies, platform upgrades, migrations, and infrastructure modernization initiatives. Monitor network security platforms, investigate security events, and support Security Operations during incident response and containment. Partner with Vulnerability Management to remediate infrastructure vulnerabilities and apply timely patches and firmware updates. Develop automation using scripting, APIs, and infrastructure-as-code to improve operational efficiency. Create and maintain network security standards, architecture diagrams, engineering documentation, procedures, and configuration baselines. Evaluate emerging network security technologies, vendor solutions, and industry best practices. What you need: Bachelor's degree in Computer Science, IT, Cybersecurity, Engineering, or a related discipline required; Master's degree preferred. Certifications preferred: CCNP Security, CCIE Security, Palo Alto PCNSE, Fortinet NSE, Check Point CCSA/CCSE, CISSP, or equivalent. Advanced training in enterprise and cloud networking, Zero Trust Architecture, software-defined networking, firewall engineering, and secure network design preferred. Qualifications & experience Minimum 6 years of enterprise network security experience. Experience designing or reviewing DMZ, extranet, Internet-facing application, and third-party connectivity architectures, including security zones, trust boundaries, firewall policy, permitted traffic flows, management access, encryption, and compensating controls. Administering Palo Alto, Cisco, Check Point, Fortinet, or similar firewall technologies. Experience with VPN, IDS/IPS, NAC, DNS security, and cloud networking. Experience supporting Azure, AWS, or Google Cloud networking. Knowledge of routing, switching, TCP/IP, DNS, DHCP, and network protocols. Familiarity with NIST CSF and CIS Controls. Travel Percentage: 10%