Senior Network Security Engineer

Paramount Computer Systems Co

Dubai

On-site

AED 360,000 - 480,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Paramount Computer Systems Co. is seeking a Senior Network Security Engineer / Consultant specialized in Check Point for a Dubai-based engagement.

The role covers design, migration, and support of a multi-vendor firewall estate transitioning to Check Point Quantum Force hardware across multiple sites. The successful candidate will lead the delivery lifecycle, from estate discovery and policy audit to staging, cutover and post-implementation support, working in a high-availability,

Qualifications

  • 8+ years in network security with a minimum of 5 years hands-on Check Point delivery.
  • Experience migrating multi-vendor firewall estates to Check Point.
  • Strong background in high-throughput carrier networks and multi-domain architectures.
  • Proven design, implementation and migration capabilities in large environments.

Responsibilities

  • Produce high-level and low-level designs for Check Point gateway clusters and management architecture.
  • Define target security policy architecture and NAT and VPN topologies.
  • Lead policy conversion from legacy platforms and implement cutover plans with minimal downtime.
  • Develop and execute migration and testing plans, including post-migration support and handover.

Skills

Check Point firewall
GAiA OS
ClusterXL
Multi-Domain Security Management
Threat Prevention
VPN design
High availability

Education

Check Point CCSE certification

Tools

SmartMove
SmartEvent
fw monitor

Job description

Position Title Senior Network Security Engineer / Consultant — Check Point Firewall

Function Network Security Delivery / Professional Services

Reports To Project Manager / Practice Lead — Network Security

Location Work location : Dubai, UAE – Travel to other region as project required.

Engagement Type Full Time

Experience Required 8+ years in network security, with a minimum of 5 years hands-on Check Point delivery

Positions Open 2

1. Role Overview

We are seeking an accomplished Check Point firewall specialist to join the delivery team for a large-scale, multi-vendor security transformation programme. The engagement involves migrating an existing mixed firewall estatecomprising Juniper, Huawei and Cisco platforms onto a new Check Point Quantum Force high-end appliance estate across different locations, deployed as high-availability clusters and managed through a Multi-Domain Smart-1 architecture.

The successful candidate will take a lead technical role across the full delivery lifecycle: source estate discovery and policy audit, target architecture and low-level design, policy conversion and rationalization, staging and commissioning, migration cutover under strict change control, and post-implementation support. This is a hands-on senior position requiring both design authority and the operational discipline to execute cutovers on a live carrier network where the tolerance for service impact is effectively zero.

2. Key Responsibilities
  • Produce high-level and low-level designs for Check Point gateway clusters, covering ClusterXL high-availability design, interface and bonding architecture, VLAN and addressing plans, and routing integration with the carrier core.
  • Design the multi-domain management and logging architecture, including domain structure, global policy layers, administrator models, log retention and event correlation.
  • Define the target security policy architecture ordered and inline policy layers, object standards, NAT design and VPN topologies and establish the standards that operational teams will work to thereafter.
  • Design Threat Prevention and sandboxing profiles, including IPS, Anti-Virus and Anti-Bot baselines and a staged detect-to-prevent rollout strategy appropriate to high-throughput carrier traffic.
  • Develop migration architecture: parallel installation approach, traffic-swing methodology, soak criteria and technically credible rollback design.
Implementation & Migration
  • Lead policy conversion from Juniper, Huawei and Cisco source platforms using Check Point SmartMove and scripted or manual conversion methodologies, followed by manual review, rule rationalization and object normalization.
  • Build and commission high-end Check Point appliances: OS installation and hardening, cluster formation, interface and bonding configuration, SIC establishment and onboarding to the correct management domain.
  • Configure and validate high-speed interfaces in line cards, including optics validation and link aggregation at scale.
  • Build the Smart-1 management and logging infrastructure, including Multi-Domain Server deployment, SmartEvent configuration and SIEM log forwarding.
  • Author detailed cutover method statements and execute migrations within approved change windows, including on-site presence, live traffic verification and rollback execution where triggers are met.
Testing, Support & Handover
  • Develop and execute acceptance test plans covering high-availability failover, routing convergence, policy parity against the legacy estate, throughput validation and Threat Prevention behaviour.
  • Provide post-migration hypercare support: incident diagnosis, policy and Threat Prevention tuning, performance optimisation and vendor TAC escalation management.
  • Perform advanced troubleshooting using packet-level and kernel-level diagnostics, cluster state analysis and acceleration path investigation.
  • Produce as-built documentation and operational runbooks, and deliver structured knowledge transfer to customer network operations and security operations teams.
  • Represent the delivery organisation in customer design reviews, technical workshops, change advisory boards and acceptance sign-off sessions.
  • Work within a phased, wave-based rollout model, meeting entry and exit gate criteria per wave and maintaining delivery quality across parallel site activity.
  • Mentor junior engineers and contribute to the internal Check Point practice through reusable design patterns, conversion tooling and lessons learned.
  • Minimum 5 years of hands-on experience designing, implementing and supporting Check Point security gateways, including at least two enterprise or carrier-scale deployments or migrations.
  • Deep expertise across the Check Point portfolio: Gaia OS, SmartConsole, Security Management and Multi-Domain Management (MDS/MLM), ClusterXL, Management API, SecureXL and CoreXL acceleration.
  • Demonstrable experience with high-end Check Point appliances and high-throughput deploymentsmulti-hundred-gigabit or terabit-class environments, high-density line cards and performance tuning under sustained load.
  • Proven policy migration experience from third-party firewall vendors like Cisco, Juniper or ScreenOS, Huawei, Fortinet including practical use of SmartMove and post-conversion validation.
  • Strong command of Threat Prevention blades and sandboxing: IPS, Anti-Virus, Anti-Bot, Threat Emulation and Threat Extraction, including profile design and false-positive management.
  • Solid networking foundation: TCP/IP, routing protocols (OSPF, BGP), VLANs and trunking, link aggregation, NAT, IPSec VPN and high-availability design principles.
  • Advanced troubleshooting capability using fw monitor, tcpdump, kernel debug, cpview, cphaprob and related diagnostic tooling.
  • Experience executing changes on production networks under formal change management, including method statement authorship, risk assessment and rollback planning.
  • Strong documentation and communication skills, with the ability to present and defend technical designs to senior customer stakeholders.
4. Certification Requirements

A valid, current certification is mandatory for this role. Candidates without an active certification at the required level will not be considered.

Mandatory
  • Check Point Certified Security Expert (CCSE) must be valid and current on a supported software release.
Highly Desirable
  • Check Point Certified Security Master (CCSM) or CCSM Elite.
  • Check Point Certified Multi-Domain Security Management Specialist.
  • Check Point Certified Troubleshooting Expert (CCTE) or Automation Specialist (CCAS).
  • Complementary networking or security certification: CCNP/CCIE Security, JNCIP/JNCIE-SEC, HCIP/HCIE-Security
5. Preferred — Telecommunications Domain Experience

Candidates with service provider or telecommunications experience will be given clear preference. The following are considered significant advantages:

  • Prior delivery experience with a telecom operator, mobile network operator or internet service provider, particularly in a mobile packet core, MPBN or carrier backbone environment.
  • Understanding of telecom network architecture and the security demarcation between the transport layer and the security layer — including Gi/SGi firewall, roaming and peering security concepts.
  • Familiarity with modern carrier transport technologies: EVPN, Segment Routing (SR-MPLS) and SRv6, and how firewall clusters attach to and interoperate with such fabrics.
  • Experience operating within carrier-grade service level commitments, restricted maintenance windows and formal telecom change governance.
  • Exposure to carrier-scale traffic profiles and the performance engineering considerations that accompany them, including asymmetric routing and high session-rate environments.
  • Experience with regulatory, lawful intercept or telecom-specific compliance requirements as they affect security infrastructure design.
6. Personal Attributes
  • Composure and sound judgement when executing high-risk changes on live production networks during constrained maintenance windows.
  • Methodical and evidence-driven approach to diagnosis, with the discipline to document decisions and follow agreed process.
  • Ability to work independently on customer sites while maintaining alignment with programme governance and reporting.
  • Willingness to travel to customer locations as required and to work extended or night-time maintenance windows during cutover phases.
  • Collaborative approach with customer teams, with the credibility to advise and, where necessary, respectfully challenge on technical risk.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network & Security Engineer -Abu Dhabi
Senior Network & Security Engineer -Abu Dhabi

K20s - Kinetic Technologies Private Limited • Abu Dhabi

On-site
AED 300,000 - 420,000
Senior Network Engineer
Senior Network Engineer

K20s Kinetic Technologies • United Arab Emirates

On-site
AED 180,000 - 300,000
Senior Check Point Network Security Engineer Carrier-Grade
Senior Check Point Network Security Engineer Carrier-Grade

Paramount Computer Systems Co • Dubai

On-site
AED 360,000 - 480,000
Technical Specialist
Technical Specialist

Intertec Systems • Dubai

On-site
AED 200,000 - 300,000
Senior Technical Support Engineer
Senior Technical Support Engineer

Intertec Systems • Dubai

On-site
AED 180,000 - 240,000
Senior Network Engineer (Enterprise Networking, Security & SD-WAN) | HTP Global Technologies | UAE (Dubai, Sharjah, Ajman, Ras Al Khaimah & Fujairah)
Senior Network Engineer (Enterprise Networking, Security & SD-WAN) | HTP Global Technologies | UAE (Dubai, Sharjah, Ajman, Ras Al Khaimah & Fujairah)

HTP Global Technologies • United Arab Emirates

On-site
AED 112,000 - 134,000
Senior Network Engineer - UAE
Senior Network Engineer - UAE

K20s - Kinetic Technologies Private Limited • Dubai

On-site
AED 180,000 - 300,000
Network Security Engineer | CNS Middle East | Dubai, UAE
Network Security Engineer | CNS Middle East | Dubai, UAE

CNS Middle East • Dubai

On-site
Network and Security Engineer (Contract)
Network and Security Engineer (Contract)

TalentOne • Abu Dhabi

On-site
AED 134,000 - 179,000
Senior Network & Security Engineer
Senior Network & Security Engineer

Dautom • Abu Dhabi

On-site
AED 320,000 - 520,000