We are seeking a Network Security Engineer to design, implement, and maintain network security solutions that protect critical infrastructure from cyber threats. This role involves securing enterprise networks, cloud environments, firewalls, VPNs, IDS/IPS, and other security appliances.
The ideal candidate will work closely with IT, security, and DevOps teams to ensure a secure, resilient, and compliant network infrastructure.
Responsibilities:
Network Security Design & Implementation
- Design and deploy secure network architectures, including firewalls, routers, switches, VPNs, and IDS/IPS.
- Configure and manage firewalls (e.g., FortiGate, ForiWeb, Cisco).
- Implement Zero Trust Security models and segmented network environments.
- Secure wireless networks, remote access solutions, and internal network zones.
Threat Detection, Monitoring & Incident Response
- Deploy and maintain Intrusion Detection and Prevention Systems (IDS/IPS).
- Monitor network traffic for anomalies, suspicious activities, and potential threats.
- Respond to network security incidents, conduct forensic analysis, and implement countermeasures.
- Collaborate with SOC teams to analyze threats and improve incident response workflows.
Firewall & Perimeter Security Management
- Design, implement, and optimize firewall rules, policies, and ACLs.
- Manage Web Application Firewalls (WAF) and cloud-based security solutions.
- Ensure proper DDoS protection, bot mitigation, and traffic filtering.
Network Security
- Implement secure VPN tunnel solutions.
- Ensure compliance with security best practices (CIS Benchmarks, NIST, ISO 27001).
Access Control & Identity Management
- Implement and manage Network Access Control (NAC) solutions.
- Enforce multi-factor authentication (MFA) and secure network authentication.
- Design least privilege access models for network and system resources.
- Security Audits & Compliance
- Conduct regular network security assessments, penetration testing, and vulnerability scans.
- Ensure compliance with NIST, ISO 27001, PCI-DSS, and other regulatory frameworks.
- Maintain detailed network security documentation and audit reports.
Automation & Security Optimization
- Automate network security tasks using Python, Power Shell, Bash, Ansible , Terraform, or scripting tools.
- Deploy SIEM solutions (Splunk, ELK) to centralize log analysis.
- Optimize network performance while maintaining strong security controls.
Security Awareness & Training
- Train IT and engineering teams on network security best practices.
- Provide guidance on secure network configurations, phishing prevention, and insider threat mitigation.
- Stay updated on emerging network security threats and trends.
Required Skills & Qualification
Technical Skills
✔ Hands-on experience with network security tools (Firewalls, IDS/IPS, VPNs, SIEM, WAF).
✔ Strong understanding of network protocols (TCP/IP, BGP, DNS, HTTP, SSL/TLS, IPSec).
✔ Expertise in configuring and securing enterprise networks (FortiGate, ForiWeb, Cisco).
✔ Knowledge of security frameworks (ISO 27001, NIST, CIS Controls).
✔ Experience with scripting and automation (Python, Power Shell, Bash, Ansible, Terraform).
✔ Familiarity with penetration testing tools (Nmap, Wireshark, Metasploit, Kali Linux).
Soft Skills & Experience
✔ +4 years of experience in Network Security, IT Security, or Cybersecurity Engineering.
✔ Strong analytical and problem-solving skills for troubleshooting security incidents.
✔ Ability to collaborate with IT, DevOps, and SOC teams to strengthen security posture.
✔ Excellent communication skills for training and security awareness programs.