We are looking for a Senior Network Security Engineer with deep expertise in perimeter security, traffic visibility, and inline security infrastructure, with hands‑on experience managing Palo Alto Networks, Forcepoint, Keysight ThreatArmor and Ixia iBypass.
Key Responsibilities
- Design, implement, and maintain enterprise perimeter security architecture using Palo Alto Networks NGFW.
- Perform advanced firewall configuration & hardening,
- Security Policies, NAT, Zones
- Routing (Static, OSPF, BGP)
- App-ID, User-ID, Threat Prevention, WildFire
- Manage ThreatArmor Evision for
- Threat visibility & traffic classification
- Monitoring attack behavior & suspicious patterns
- Threat scoring and security analytics
- Manage Ixia iBypass for
- Inline security high availability
- Automatic traffic bypass during device failure
- Maintaining uninterrupted security enforcement
- Administer Forcepoint Web Security & DLP,
- Web filtering & content control
- Data classification & insider threat protection
- Perform advanced troubleshooting for
- Latency, asymmetric routing, packet loss, inspection bottlenecks
- SSL inspection issues and performance degradation
- Integrate security infrastructure with SIEM, SOAR, Threat Intelligence Platforms
- Lead
- Firmware upgrades
- Signature & threat updates
- License management
- Capacity planning
- Develop and maintain technical documentation, SOPs, and security architecture diagrams
Collaborate closely with SOC, Network, System, and DevOps teams.
Minimum Qualifications
Mandatory Qualifications
- 3-5+ years of experience in Network Security Engineering
- Strong hands‑on experience with
- Palo Alto NGFW & Panorama
- Forcepoint Web Security & DLP
- Strong knowledge of
- BGP, OSPF, VLAN, NAT
- IPsec & SSL VPN
- DMZ, Proxy, and Secure Network Design
- Proven experience with
- High Availability (HA), Failover, and Inline Security Architecture
- Firewall & SIEM Integration
- Root Cause Analysis & Performance Tuning
- Able to handle network-level security incidents and provide strategic recommendations
Nice to Have
- Experience in large-scale enterprise, financial, data center, or government environments
- Experience with Python, Ansible, or Firewall API automation
- Experience supporting 24/7 SOC as L3 escalation
Preferred Certifications
- ✅ PCNSE – Palo Alto Networks Certified Network Security Engineer
- ✅ PCNSA – Palo Alto Networks Certified Network Security Administrator
- ✅ CompTIA CySA+
- ✅ Forcepoint Web Security / DLP Specialist