Network Security Engineer
The job description
Tech stack. Palo Alto, Fortinet, or Cisco firewalls, IDS/IPS (Snort, Suricata), ZTNA platforms, Wireshark, VPN technologies (IPsec, SSL), network segmentation design, Python, firewall policy auditing tools
About the role
You will own the network security layer for a technology company with offices, datacenters, and a large remote workforce spread across multiple regions. The team designs the segmentation, inspection, and access controls that every packet traverses, and you will be the engineer who keeps that fabric both secure and performant under real traffic. You will modernize legacy VPN access, rationalize years of accumulated firewall rules, and build the visibility engineers need during incidents. This role matters because a well-architected network contains breaches to single segments instead of letting them spread company-wide, and your designs are precisely what make that containment possible when it counts.
What you will achieve
- Redesign firewall policy sets to cut rule sprawl 40 percent while closing overly permissive any-any rules that auditors consistently flag.
- Deploy microsegmentation across the datacenter so lateral movement requires defeating an independent control at every hop, validated by red team exercises.
- Roll out ZTNA to replace legacy VPN for 80 percent of remote access use cases within a year, improving both security posture and everyday user experience.
- Tune IDS/IPS signatures to hold true positive rates above 90 percent on validated attack traffic without dropping or delaying legitimate business flows.
- Document the complete network security architecture so any engineer can trace a traffic flow end to end during a high-pressure incident.
What you will bring
Must-haves
- 2 to 5 years working with enterprise firewalls, IDS/IPS sensors, and VPN infrastructure in production networks.
- Strong TCP/IP fundamentals: routing behavior, NAT, VLANs, and common protocols analyzed at the packet level.
- Experience writing and auditing firewall policy in complex, multi-zone environments containing hundreds of rules.
- Ability to capture and analyze traffic with Wireshark or tcpdump during live investigations and outages.
- Understanding of network segmentation strategies, DMZ design principles, and east-west traffic controls.
- Scripting skills in Python or Bash for configuration auditing, compliance checks, and policy automation.
- Methodical troubleshooting discipline that isolates faults without making changes blindly.
Nice-to-haves
- PCNSE, NSE, or CCNP Security certification.
- Experience with SASE or ZTNA platforms such as Zscaler or Cloudflare Access.
- Familiarity with BGP, OSPF, and modern datacenter fabric architectures.
- Exposure to DDoS mitigation platforms and scrubbing workflows.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta