Get more replies from employers
Send a job-specific resume in minutes.
Visionpool Business Servies is seeking a REMOTE Network Security Consultant to act as a senior SME responsible for governance, architecture, and oversight of enterprise security controls across on-premises and hybrid cloud environments.
The role focuses on Cisco-based security platforms, with emphasis on FTD, FMC, Umbrella/OpenDNS, and WSA, guiding security-aligned designs and zero trust implementation. Travel within Canada may be required.
Visionpool Business Servies is hiring a REMOTENetwork Security Consultant Resourcewhowill serve as a senior subject matter expert responsible for the governance, architecture, and oversight of enterprise network security controls across on-premises and hybrid cloud environments. The Consultantwillprovidesecurity guidance on network and application designs, with a focus on Cisco-based security platforms, ensuring alignment with enterprise standards,zoningand segmentation models, and zero trust principles.
Design, implement, and manage enterprise network security controls across Cisco security platforms including Cisco Firepower Threat Defense (FTD) firewalls (LINA and SNORT engines), Cisco FMC (Firepower Management Center), Cisco Umbrella DNS / OpenDNS, Cisco Web Security Appliances (WSA), Cisco Secure Malware Analytics (Sandboxing).
Provide governance oversight and securityexpertisefor remote access solutions, including VPN services on Cisco FTD platforms, ensuring configurations align with enterprise security standards, access control policies, and zero trust principles.
Act as a subject matter expert for troubleshooting and triaging network security incidents, alerts, and anomalies related tofirewall, IPS, DNS, and web security technologies.
Perform continuous review and tuning of Intrusion Prevention System (IPS) / Intrusion Detection System (IDS) signatures,firewallrules, and traffic inspection policies to improve detection capabilities and reduce false positives.
Participate in Architecture Review Board (ARB) meetings as the designated Network Security representative to review solution architectures.
Evaluate proposed network and application architectures to ensure alignment with enterprise security standards, zoning models, and segmentation requirements.
Review and approvefirewallrule changes and ensure proper implementation of network segmentation and zone-based security controls within datacenter and hybrid environments.
Provide security design guidance and recommendations for new and existing services, ensuring adherence to zero-trust principles and enterprise security frameworks.
Design and secure hybrid environments integrating on-premises datacenter infrastructure with Azure cloud services.
Provide expertise in Azure networking and security controls, including Virtual networks(VNets), subnets, and network security groups (NSGs), Azure Firewall and application gateways, Identity and Access Management (IAM), Privileged Access Management (PAM),Conditional Access, and Role-Based Access Control (RBAC)
Support security integration efforts related to Broadcom VMware Cloud Foundation (VCF) technologies and associated virtualized networking/security stacks.
Evaluate and integrate emerging network security technologies, including automation, orchestration, and Artificial Intelligence (AI) / Machine Learning (ML) -based threat detection capabilities.
Conduct deep traffic analysis and threat investigations using network telemetry, packet capture tools, and security analytics platforms.
Lead or support incident response activities related to network security breaches, including containment, root cause analysis, and remediation.
Identifysecurity gaps, misconfigurations, and risks in network security infrastructure and recommend remediation strategies aligned to best practices and compliance requirements.
Collaborate with security and infrastructure teams toidentify, assess, and remediate network-related vulnerabilities.
Support andparticipatein network security penetration testing and validation activities.
Contribute to the design and validation of disaster recovery (DR) and business continuity plan (BCP) strategies from a network security perspective.
Strong understanding of load balancing technologies, particularly F5 load balancers, with the ability to review and assess traffic flow configurations, including traffic distribution and redirection to backend servers, ensuring alignment with enterprise securitycontrolsanddesign standards.
Ensure critical network security controls are resilient, recoverable, and aligned with failover and replication strategies across datacenters.
Develop andmaintainhigh-quality documentation including network security architecture designs, standards, and operational procedures.
Act as a trusted advisor to cross-functional teams, providing guidance on secure network design and implementation.
Minimum of 10 yearsof progressively responsible, hands-on information technology experience
Minimum 8years of direct experience in one or moreof the following areas:
Must hold at leastone (1) activeprofessional-level or expert-level certification from the following list:
Must be able to travel within Saskatchewan asrequiredto support site visits across multiple locations.
Bachelor's degree in Information Security, Computer Science, Engineering, or a related field
Minimum 10years of experience in network security and enterprise infrastructure environments.
Strongexpertisein network security architecture, design, and governance,including segmentation, zoning, and zero trust principles.
Demonstrated hands-on experience with enterprise network security technologies, including Cisco Firepower Threat Defense (FTD), FMC, IPS/IDS,DNSand web security controls (Cisco Umbrella/OpenDNS, Web Security Appliances)
Deep understanding of network security controls including firewalls, IPS/IDS, VPNs, encryption, Uniform Resource Locator (URL) / Domain Name System (DNS) filtering, and network segmentation.
Solid foundational knowledge of networking concepts including routing, switching, and common protocols.
Experience in network traffic analysis, threat detection, and incident response using industry-standard monitoring and forensic tools.
Familiarity with Security Information and Event Management SIEM), Security Orchestration, Automation, and Response (SOAR), Network Detection and Response (NDR), Endpoint Detection and Response (EDR), and vulnerability management platforms.
Ability toidentifysecurity gaps, misconfigurations, and risks and recommend remediation strategies aligned with security best practices.
Experience reviewing andvalidatingnetwork and security architectures to ensure alignment with enterprise security standards and compliance requirements.
Ability to provide security governance, design recommendations, and risk assessments for new and existing solutions.
Strong understanding of hybrid cloud security models, particularly within Microsoft Azure environments.
Familiarity with network security penetration testing concepts and methodologies.
Understandingofdisaster recovery (DR) and business continuity planning (BCP) from a network security perspective.
Proven ability to work with cross-functional teams, including infrastructure, cloud, and architecture teams.
Strong communicationskills with the ability to act as a subject matter expert and trusted advisor on network security matters.
Cisco certifications such as CCNP Security or CCIE Security.
Industry certifications such as CISSP, CISM,CCSPor equivalent.
Cloud security certifications (e.g.,Microsoft Azure Security) are an asset.