As an experienced Network Security Engineer, you will play a key role in designing, implementing, securing, and optimising enterprise network security services across on-premises, cloud, and hybrid environments. Your expertise will be utilised to strengthen the organisation’s cyber defence capabilities, drive network security innovation, automate security operations, and ensure resilient, secure, and scalable connectivity solutions.
You will work closely with architecture, engineering, operations, cloud, and business teams to deliver secure network services, respond to emerging threats, and support the adoption of modern network security technologies. The role requires a strong focus on automation, continuous improvement, operational excellence, and adherence to security and regulatory requirements.
Primary Responsibilities
Network Security Engineering & Delivery
- Design, implement, and maintain secure enterprise network infrastructure and security controls aligned to organisational strategy and security standards.
- Drive network security enhancements and modernisation initiatives within agreed budgets, timelines, and risk appetites.
- Support the delivery of secure connectivity solutions across cloud, on-premises, and hybrid environments.
- Collaborate with architects and engineers to develop High Level Designs (HLDs) and Low Level Designs (LLDs) into operational solutions.
Network Security Operations & Governance
- Lead operational readiness and transition requirements from design/build phase to BAU
- Lead policy governance, including rule review, optimisation, recertification, and compliance management processes.
- Drive continuous improvement of network security operations through automation, policy simplification, and control standardisation.
- Identify opportunities to reduce operational risk through proactive firewall rule analysis, remediation, and optimisation activities.
- Partner with Infrastructure, Security Architecture, Engineering, and Cyber Defence teams to deliver secure network services and strategic security initiatives.
- Collaborate with leadership teams to align network security capabilities with broader technology, resilience, and cyber security strategies.
- Security Automation & Engineering
- Develop and implement automated solutions for network security administration, policy management, compliance validation, and operational processes.
- Drive the adoption of Infrastructure as Code (IaC), Security as Code, and automated governance controls across network security platforms.
- Contribute to enterprise-wide initiatives focused on network visibility, security posture improvement, and operational efficiency.
Security Operations & Risk Management
- Monitor, analyse, and respond to network security incidents, vulnerabilities, and emerging threats.
- Support threat detection, containment, remediation, and post-incident reviews.
- Ensure network security controls remain effective, compliant, and aligned with evolving cyber threats.
- Conduct security assessments, rule reviews, and network segmentation activities.
Security Architecture & Standards
- Ensure network architectures comply with security standards, secure-by-design principles, and software development lifecycle requirements.
- Support the implementation of Zero Trust, defence-in-depth, and least privilege security models.
- Maintain awareness of current industry threats, vulnerabilities, and security technologies.
- Strong understanding of SWG controls
- Strong understanding of TLS interception
- Proxy & Secure Web Gateway Technologies
- Zero Trust Network Access (ZTNA)
- Strong understanding of authentication method at enterprise level
- Strong understanding of content controls (request and response mode)
- Network Security Automation (Python, PowerShell, APIs, Terraform)
- Cloud Security & Secure Connectivity
- Identity Integration (Entra ID, Conditional Access, MFA)
- Clipboard controls
- File upload and download restrictions
- Session protection
- Secure application access controls
- Downstream SWG
- Conditional Access
- Security Information and Event Management (SIEM) platforms
Network Security Operations
- Strong operational experience supporting enterprise network security environments.
- Experience managing security incidents, policy changes, exceptions, and operational support within regulated organisations.
- Understanding of compliance management, governance processes, audit requirements, and regulatory controls.
- Experience working within ITIL-aligned Incident, Problem, Change, and Service Management frameworks.
- Understanding of compliance management, governance processes, audit requirements, and regulatory controls.
- Strong stakeholder management and relationship-building skills across technical and executive audiences.
- Ability to influence and drive security improvements across infrastructure, cloud, engineering, and operational teams.
- Strong analytical approach to risk identification, remediation, and operational optimisation.
- Excellent written and verbal communication skills with the ability to present complex technical issues in a clear and concise manner.
- Demonstrated ability to balance security, operational resilience, regulatory obligations, and business requirements.
- Experience implementing SWG within large-scale enterprise environments.
- Experience with Zero Trust Network Architecture (ZTNA), SASE, and Security Service Edge (SSE) technologies.
- Experience within large-scale financial services, banking, or other highly regulated environments.
- Knowledge of regulatory frameworks including PCI-DSS, ISO27001, NIST Cyber Security Framework, CIS Controls, and relevant financial industry regulations.
- Experience supporting network security transformation, cloud migration, and hybrid networking programmes.
Security Automation & Engineering
- Experience automating network security processes, including:
- Policy validation
- Compliance reporting
- Security control enforcement
- Operational workflows
- Proficiency in PowerShell, Python, Bash, and API-based integrations to support automation objectives.
- Experience with automation platforms and configuration management tools such as Ansible, Terraform, Chef, or equivalent solutions.
- Strong stakeholder management and relationship-building skills across technical and executive audiences.
- Ability to influence and drive security improvements across infrastructure, cloud, engineering, and operational teams.
- Strong analytical approach to risk identification, remediation, and operational optimisation.
- Excellent written and verbal communication skills with the ability to present complex technical issues in a clear and concise manner.
- Demonstrated ability to balance security, operational resilience, regulatory obligations, and business requirements.
- Experience implementing SWG within large-scale enterprise environments.
- Experience with Zero Trust Network Architecture (ZTNA), SASE, and Security Service Edge (SSE) technologies.
- Experience within large-scale financial services, banking, or other highly regulated environments.
- Knowledge of regulatory frameworks including PCI-DSS, ISO27001, NIST Cyber Security Framework, CIS Controls, and relevant financial industry regulations.
- Experience supporting network security transformation, cloud migration, and hybrid networking programmes.