Turn this role into an interview — a resume and cover letter built around what this employer wants.
The Lubrizol Corporation in São Paulo, Brazil, is seeking a Senior Network Security Engineer to design, implement, and sustain a secure global network infrastructure across 80+ facilities. You will drive SDN/SD-WAN, cloud networking, segmentation, and Zero Trust-aligned controls.
Collaborate with cross-functional IT teams to deliver reliable connectivity, lead incident response, and produce runbooks and standards. Expect global scope, mentorship of engineers, and ongoing security modernization.
Select how often (in days) to receive an alert: Create Alert
The Lubrizol Corporation, a Berkshire Hathaway company, is a market-driven global company serving customers in more than 100 countries. We own andoperatemanufacturing facilities in 17 countries, as well as sales and technical offices around the world. Through our global sales and manufacturing networks, wecandeliver the products and services our customers need, where and when they need them. At Lubrizol, our mission is straightforward: We improve lives as an essential partner in our customers’ success, delivering efficiency,reliability,or wellness to their end users.
Lubrizol is looking for a SeniorNetwork Security Engineer to join our IT team and support the planning, design, implementation, and sustainability of a secure network infrastructure—with an emphasis on core network and WAN capabilities across Lubrizol’s 80+ facilities globally. In this role, you will help modernize our network and security architecture (e.g., software-defined networking, cloud networking, segmentation/Zero Trust-aligned controls, and automation), while also contributing to security standards, procedures, and compliance alignment. You will partner closely with Network Operations/Delivery and cross-functional IT teams to deliver reliable, secure connectivity and provide second/third-level troubleshooting and incident support. This is an exciting time to join our organization as we sharpen our focus on operational excellence and cybersecurity—ideal for motivated problem-solvers who thrive in a collaborative, global environment.
Drive the transition from traditional networking to a next-generation secure network, including SDN/SD-WAN, cloud network infrastructure, segmentation/micro-segmentation, and automation of network services.
Evaluate emerging networking and security solutions (e.g., SASE/SSE, NGFW, ZTNA, NAC) and propose roadmap-aligned improvements based on business requirements and risk.
Design, implement, andmaintainsecure network architectures and configurations that meet availability, performance, and security requirements, following documented standards.
Provide technical leadership to Network Operations and Delivery teams to enable consistent global deployment, operations, and lifecycle management of network and security services.
Mentor engineers and contribute to engineering excellence through standards, reference designs, runbooks, and operational training.
Produce high-quality documentation that enables repeatable deployments and effective support (designs, diagrams, standards, change plans, validation steps, and support playbooks).
Collaborate with cross-functional IT partners (cloud, identity, endpoint, SOC, application, and OT/plant teams) to plan and execute network-related initiatives and reduce end-to-end risk.
Own vendor/partner engagement for assigned technologies (roadmaps, escalations, feature planning, and technical advisories).
Participate in technical crisis/major incident management, driving root-cause analysis, corrective actions, and post-incident improvements.
Execute changes in alignment with change management/CAB processes, ensuringappropriate riskassessment, testing, and back-out planning.
Troubleshoot complex (L3) networking and network security issues using protocol analysis and observability/tooling to drivetimelyresolution and prevention.
Bachelor’s degree in an IT-related field (or equivalent experience).
7–10+ years of experience in network/infrastructure roles, including 3–5+ years supportinga globalenterprise WAN and security controls.
Strong fundamentals in TCP/IP, subnetting, routing/switching, DNS, and DHCP; ability to apply these in complex, multi-region environments.
Hands-on experience implementing and troubleshooting WAN technologies (internet/MPLS, BGP/OSPF/EIGRP as applicable) and SD-WAN.
Experience withfirewalland network security policy design/implementation (e.g., NGFW), VPN, and secure remote access patterns.
Experience with network access control and identity-based networking (e.g., NAC, 802.1X, TACACS+/RADIUS, EAP-TLS).
Working knowledge of network security principles and best practices (e.g., segmentation, least privilege, secure management planes, logging/monitoring, and vulnerability/risk remediation).
Experience with protocol analysis and troubleshooting tools (e.g., Wireshark)and withtechnical crisis/major incident and change management (CAB) processes.
Certifications such as CCNP (or higher), PCNSA/PCNSE, and/or GIAC (e.g., GSEC) or equivalent.
Hands-on experience with enterprise switching/routing, wireless, andfirewallplatforms (e.g., Cisco, Arista, Palo Alto).
Experience with cloud networking (AzureVNets, NSGs, routing, private connectivity) and hybrid network security patterns.
Experience deploying and supporting SD-WAN solutions (e.g., VeloCloud, Meraki) andoperatingmixed internet/MPLS WAN environments.
Experience with network management platforms (e.g., Cisco DNA Center/Catalyst Center) and NAC platforms (e.g., Aruba ClearPass).
Exposure to Zero Trust and SASE/SSE capabilities (e.g., ZTNA, SWG, CASB) and integrating network telemetry with SOC workflows.
Demonstrated capability in scripting/programming and automation (API integrations, Python, Ansible, Git) and comfort working with Linux; experiencewith infrastructure-as-code is a plus.
Experience building relationships and working effectively in a collaborative, matrix-driven, global environment; priormanufacturing/OT networking exposure is a plus.