Senior Associate Network & Security Engineer

Emirates Investment Bank pjsc

Dubai

On-site

AED 300,000 - 540,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Emirates Investment Bank PJSC in Dubai seeks an experienced Enterprise Network & Security Operations Lead to oversee the operation, security, and continuous improvement of our enterprise network and hybrid-cloud connectivity, spanning Cisco routing, switching, firewall infrastructure, NAC, and AAA, with emphasis on resilience and regulatory compliance.

You will manage NGFW and WAF deployments, design cloud networking, implement Zero Trust remote access, monitor performance, conduct incident

Qualifications

  • Essential: Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or related discipline.
  • Desirable: Cisco CCNA/CCNP, Fortinet, Palo Alto Networks, or Microsoft Azure certifications.
  • Hands-on experience with Cisco enterprise routing and switching and network security platforms.
  • Experience with NAC, 802.1X, RADIUS, and AAA in enterprise networks.
  • Experience in regulated environments with change management and security compliance.

Responsibilities

  • Administer, maintain, and secure enterprise LAN/WAN infrastructure including routers, switches, firewalls, VPN services, and related network platforms.
  • Operate network and security platforms including NGFW, WAF, security analytics, logging, monitoring, and management solutions.
  • Perform firmware upgrades, hardening, high-availability maintenance, and policy changes for network and security devices.
  • Manage firewall policies, routing, NAT, VPN, and access-control changes using least-privilege principles.
  • Monitor availability, capacity, performance, and resilience of network and security services; implement improvements to prevent disruption.
  • Design and operate cloud network architectures including hub-and-spoke and hybrid connectivity between on-prem and cloud.
  • Plan and support remote-access; integrate with identity providers via SSO/MFA.
  • Lead incident response and coordinate with vendors and internal teams.

Skills

Cisco routing
Cisco switching
Firewall platforms
NGFW
WAF
NAC
AAA
Azure networking
ZTNA
Disaster recovery
Incident response
Regulatory compliance
Vendor governance
LAN/WAN

Education

Bachelor's degree in Computer Science, Networking, Cybersecurity, or related field

Tools

Cisco ISE
Fortinet
Palo Alto Networks
Microsoft Azure

Job description

About Emirates Investment Bank:

Emirates Investment Bank PJSC (EIBank) is an independent onshore private bank based in Dubai, United Arab Emirates, offering a wide range of banking and investment services to a select group of clients, supporting them through every stage of their wealth journey.

Established in 1976 by prominent UAE business families, EIBank offers bespoke solutions across the full range of wealth management services, from asset management and access to global markets to advisory services.

EIBank is a relationship driven bank, focused on building long-term partnerships. Our flexible and consultative approach enables us to offer customized products and solutions through innovative advice and services.

Job Purpose:

Lead the operation, security, and continuous improvement of enterprise network and hybrid-cloud connectivity. The role covers Cisco routing, switching and firewall infrastructure, network access control and AAA, LAN/WAN, network security platforms, Microsoft Azure networking, application and API protection, Zero Trust remote access, high availability, disaster recovery, monitoring, incident response, vendor governance, and regulatory compliance within a banking environment.

Key Responsibilities:
Enterprise Network & Security Operations
  • Administer, maintain, and secure enterprise LAN/WAN infrastructure including routers, switches, firewalls, VPN services, and related network platforms.
  • Operate network and security platforms including next-generation firewalls (NGFW), web application firewalls (WAF), security analytics, centralized logging, monitoring, and management solutions.
  • Perform firmware and software upgrades, hotfixes, hardening, high-availability maintenance, policy changes, and lifecycle activities for managed network and security devices.
  • Manage firewall policies, routing, NAT, VPN, network segmentation, and access control changes using least-privilege principles and regular rule reviews.
  • Monitor availability, capacity, performance, and resilience of network and security services, identifying and implementing improvements to prevent service disruption.
Network Access Control & Device Administration
  • Administer enterprise routing and switching environments, including Layer 2/Layer 3 switching, VLANs, trunking, routing, ACLs, redundancy, and secure device administration.
  • Administer Network Access Control (NAC) and Authentication, Authorization, and Accounting (AAA) platforms, including 802.1X authentication and RADIUS-based access enforcement.
  • Manage centralized administrative authentication, authorization, and accounting services for routers, switches, firewalls, and network devices using role-based access controls.
  • Troubleshoot endpoint authentication, authorization policies, identity integration, NAC, RADIUS, and device administration issues across network infrastructure.
Cloud Networking & Hybrid Connectivity
  • Design and operate cloud network architectures, including hub-and-spoke and landing-zone models using virtual networks, subnets, network segmentation, security controls, user-defined routing, and controlled traffic flows.
  • Design, implement, and maintain hybrid connectivity between on-premises and cloud environments, including dedicated private connectivity and site-to-site VPN solutions, with appropriate redundancy and disaster recovery capabilities.
  • Implement and troubleshoot cloud networking services, including private connectivity, load balancing, web application security, gateway services, and API connectivity.
  • Design traffic steering through virtual network security appliances and troubleshoot stateful traffic-flow issues, including asymmetric routing, source/destination translation, return-path control, and private connectivity challenges.
  • Participate in architecture and solution reviews to validate segmentation, resilience, scalability, high availability, and secure connectivity before production deployment.
Network Security, WAF & Application Protection
  • Implement and maintain firewall, IDS/IPS, web application firewall (WAF), reverse proxy, and application publishing controls for internet-facing and internal applications.
  • Translate vulnerability assessment and penetration testing findings into network and application security controls such as rate limiting, URL filtering, access policies, TLS enhancements, and security header implementation.
  • Configure and troubleshoot secure application and API traffic flows, path-based routing, digital certificates, certificate chains, and backend service connectivity across network and cloud security platforms.
  • Review network exposure and security policies, remove unnecessary access, and validate changes with application and information security teams.
Zero Trust, Remote Access & Identity Integration
  • Operate secure remote-access and Zero Trust Network Access (ZTNA) solutions, including access-policy management and endpoint connectivity services.
  • Integrate remote-access platforms with enterprise identity providers using federated authentication, single sign-on (SSO), and multi-factor authentication (MFA).
  • Support controlled third-party access through segmented network paths and privileged access management solutions.
  • Plan and support remote-access client upgrades and technology migrations, including transitioning from legacy connectivity methods to modern secure access protocols.
Performance, Troubleshooting & Incident Response
  • Provide Level 2/Level 3 support for complex network, security, cloud, and application connectivity incidents across on-premises and cloud environments.
  • Perform packet captures, traffic-flow analysis, TCP/TLS troubleshooting, route validation, latency analysis, and security device investigations to isolate root causes.
  • Troubleshoot connectivity across load balancers, private connectivity services, web application firewalls, gateways, and virtual network appliances.
  • Conduct root cause analysis for major incidents and recurring faults, implementing corrective actions to improve service availability and performance.
  • Coordinate technical incident response with internal teams, managed service providers, cloud service providers, and vendor support teams through to resolution.
Governance, Compliance & Change Management
  • Work within formal change management and governance processes, assess technical risk, validate implementation and rollback plans, and ensure approved changes are executed and documented.
  • Define and enforce network and cloud governance standards covering IP addressing, segmentation, security zoning, routing, firewall policies, and secure connectivity.
  • Support audits and regulatory reviews by providing configuration evidence, network diagrams, security-control documentation, and remediation status reports.
  • Coordinate internal and external vulnerability assessments and penetration testing activities and track remediation actions through closure.
  • Maintain network architecture documentation, security policy records, IP address management records, standard operating procedures, and operational runbooks.
Technical Leadership & Vendor Management
  • Act as a technical focal point for network, cloud, security, SOC/NOC, and managed service operations, validating proposed configurations before production deployment.
  • Lead technical discussions for new solutions, migrations, architecture changes, and incident resolution with infrastructure, cloud, application, information security, and business stakeholders.
  • Review service performance, SLA/KPI achievements, recurring incidents, and operational risks, escalating material gaps to management as required.
  • Provide technical direction, mentoring, knowledge transfer, and troubleshooting support to engineering and operations teams, and review technical documentation from suppliers and service providers.
  • Support onboarding of new technologies and service providers, including design validation, implementation planning, operational handover, and readiness assessments.
Essential & Desirable Requirements

Essential: Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related discipline.

Desirable: Strong enterprise networking knowledge covering TCP/IP, VLANs, routing, switching, high availability, LAN/WAN, IPsec/SSL VPN, DNS, and network segmentation.

  • Hands-on experience with Cisco enterprise routing and switching, Cisco firewall platforms, Cisco ISE, Network Access Control (NAC), 802.1X, RADIUS, TACACS+, and AAA.
  • Hands-on experience with next-generation firewalls, WAF, IPS/IDS, SASE/ZTNA, remote access, and security monitoring platforms, preferably across Fortinet and Palo Alto Networks technologies.
  • Hands-on experience with Microsoft Azure networking, hybrid cloud connectivity, network virtual appliances, Private Link/Private Endpoints, load balancing, WAF, and cloud network governance.
  • Strong understanding of HTTP/HTTPS, TLS, certificates, NAT, stateful firewall behaviour, application publishing, and packet-level troubleshooting.
  • Experience working in regulated environments with formal change management, audit evidence, vulnerability remediation, disaster recovery, and security compliance requirements.
  • Relevant professional certifications such as Cisco CCNA/CCNP, Fortinet, Palo Alto Networks, or Microsoft Azure certifications are preferred.
  • Strong written and verbal communication skills with the ability to explain technical risk, coordinate vendors, document solutions, and support critical incidents.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Engineer Hybrid Infrastructure And Cloud
Network Engineer Hybrid Infrastructure And Cloud

CodeArray Technologies Pvt Ltd • Dubai

Hybrid
AED 350,000 - 520,000
Network Security - Emirati Nationals
Network Security - Emirati Nationals

Talents of Endearment • Dubai

On-site
AED 145,000 - 167,000
Senior Network & Security Engineer -Abu Dhabi
Senior Network & Security Engineer -Abu Dhabi

K20s - Kinetic Technologies Private Limited • Abu Dhabi

On-site
AED 300,000 - 420,000
Network Security Emirati Nationals
Network Security Emirati Nationals

Talents Of Endearment Careers • Dubai

On-site
AED 145,000 - 167,000
Network Engineer (Hybrid Infrastructure & Cloud)
Network Engineer (Hybrid Infrastructure & Cloud)

Dicetek LLC • Dubai

On-site
AED 360,000 - 480,000
Senior Network & Security Engineer — Hybrid Cloud & Zero Trust
Senior Network & Security Engineer — Hybrid Cloud & Zero Trust

Emirates Investment Bank pjsc • Dubai

On-site
AED 300,000 - 540,000
Senior Network Engineer - UAE
Senior Network Engineer - UAE

K20s - Kinetic Technologies Private Limited • Dubai

On-site
AED 180,000 - 300,000
Network Engineer (Hybrid Infrastructure & Cloud) at Qode
Network Engineer (Hybrid Infrastructure & Cloud) at Qode

Qode • Dubai

Hybrid
AED 360,000 - 480,000
Network and Security Engineer (Contract)
Network and Security Engineer (Contract)

TalentOne • Abu Dhabi

On-site
AED 134,000 - 179,000
Network Security Architect
Network Security Architect

Good co India • United Arab Emirates

On-site
AED 260,000 - 480,000