Principal Security Engineer (L3) - Checkpoint & PaloAlto

TekWissen LLC

Pune District

Remote

INR 3,500,000 - 5,200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TekWissen is seeking a Principal Security Engineer (L3) for Check Point and Palo Alto to lead bank-grade network-security architecture. Location: Pune, with remote work options. You will own design standards, drive major migrations, and mentor engineers across teams.

You will shape the security strategy, ensure regulatory alignment, and work with OEM vendors to influence product roadmaps while delivering robust protection for critical banking services.

Qualifications

  • BA/MA in computer science, engineering or related field.
  • Strong hands-on mastery of Check Point and Palo Alto platforms.
  • Experience with enterprise network-security design and architecture.

Responsibilities

  • Define target-state architecture and roadmaps for firewall and network-security estates.
  • Lead deep platform engineering on Check Point and Palo Alto, including migrations and upgrades.
  • Drive automation with APIs, IaC, and CI/CD for security tooling.
  • Govern risk, audits and regulatory engagements with a strong security posture.

Skills

Security Architecture
Networking
Automation
IaC

Education

Bachelor's or Master's in CS/Engineering

Tools

Check Point
Palo Alto
F5

Job description

Overview

TekWissen is a global workforce management provider throughout India and many other countries in the world. The below job opportunity is one of our clients which has been a one-stop solution for professional digital services.

Position
Principal Security Engineer (L3) - Checkpoint & PaloAlto

Location: Pune

Job Type: Full Time

Work Type: Remote

Job Summary
  • The Principal Security Engineer is the bank's most senior technical authority for network-security and firewall architecture, setting the target-state design, standards and engineering direction for the Check Point and Palo Alto estate across production, DMZ, DR and cloud.
  • Operating as a hands-on design leader rather than a people manager, the role owns architecture decisions, complex programme delivery (migrations, refreshes, segmentation), threat-prevention strategy, automation, and the highest level of incident and problem escalation driving resilience, security posture and regulatory assurance for business-critical and customer-facing banking services.
  • The role influences across teams and vendors and mentors senior and L3 engineers.
Key Responsibilities
  • Architecture & Technical Strategy
    • Own the target-state architecture and technical roadmap for the firewall and network-security estate (Check Point and Palo Alto), aligned to Enterprise Architecture and Information Security strategy.
    • Define and enforce security design standards, reference architectures, hardening baselines and rule-lifecycle governance across the bank.
    • Lead network segmentation and Zero-Trust / micro-segmentation strategy, DMZ and east-west security design, and secure connectivity for cloud and hybrid environments.
    • Provide design authority and technical sign-off on high-impact changes, new solutions and HLD/LLD across the security estate
  • Deep Platform Engineering Check Point & Palo Alto
    • Act as the deepest technical escalation and design authority on Check Point (Gaia, MDS/Provider-1, ClusterXL, VSX, Maestro hyperscale) and Palo Alto (PAN-OS, Panorama, App-ID/User-ID/Content-ID, Threat Prevention, WildFire, GlobalProtect).
    • Design and validate high-scale, highly-available firewall deployments, including capacity, throughput and interface/uplink planning to eliminate single points of failure and chokepoints.
    • Set threat-prevention, IPS and SSL-decryption strategy and tuning standards for a banking threat profile.
    • Lead complex platform migrations, refreshes and major version upgrades end-to-end, with robust rollback and minimal business impact.
  • Automation & Engineering Excellence
    • Drive automation of policy, configuration and change (Check Point Management API, Palo Alto AS3/XML API, Ansible/Python) to improve consistency, speed and auditability.
    • Establish infrastructure-as-code and configuration-standardisation practices for the security estate.
    • Champion observability, config backup/compliance (SolarWinds NCM) and continuous posture monitoring.
  • Governance, Risk & Assurance
    • Serve as senior technical lead for audits and regulatory engagements (SAMA / CBUAE, PCI-DSS); own remediation strategy and evidence for network-security findings.
    • Partner with Information Security (ISG), Risk and Enterprise Architecture on security posture, standards and technology selection.
    • Lead root-cause analysis and problem management for major (P1) security incidents and define preventive controls.
  • Technical Leadership & Mentoring
    • Mentor and uplift senior, L3 and L2 engineers; set engineering standards and review complex designs and changes.
    • Represent the bank in senior technical engagements with OEMs/vendors (Check Point, Palo Alto, F5) and influence product roadmaps and support outcomes.
  • Required Skills & Experience
    • Expert-level, current hands-on mastery of Check Point (incl. MDS, VSX, Maestro) and Palo Alto (incl. Panorama, advanced Threat Prevention).
    • Strong architecture capability - segmentation, Zero Trust, DMZ, hybrid/cloud security connectivity, and HA/DR design.
    • Advanced networking - routing/switching, NAT, VPN (IPsec/SSL), BGP/OSPF, and high-throughput/interface design.
    • Automation and IaC - Check Point/Palo Alto APIs, Ansible, Python; CI/CD for network security desirable.
    • Adjacent controls - IPS/IDS, WAF/F5, proxy/SASE/SSE, and SIEM integration.
    • Strong grasp of security frameworks and regulatory requirements relevant to banking.
  • Certifications (Preferred)
    • Check Point CCSM (Master) - CCSE required as a minimum.
    • Palo Alto PCNSE (and PCSAE/ architecture credentials desirable).
    • CISSP and/or security architecture certification (e.g. SABSA, TOGAF) strongly preferred.
    • Cloud security certification (Azure / AWS) an advantage.
  • Experience & Qualifications
    • Bachelor's or Master's degree in Computer Science, Engineering, Information Security or related field.
    • 12+ years in network/security engineering, including significant time as a senior/lead or architect owning firewall and network-security design at enterprise scale.
    • Demonstrable track record leading large migrations, segmentation programmes and multi-vendor security architecture.
    • Banking or large regulated-enterprise experience with business-critical, customer-facing environments strongly preferred.
  • Behavioral / Leadership Skills
    • Recognised technical authority - sets direction and makes high-stakes design decisions with confidence and sound judgement.
    • Excellent communication - able to influence leadership, articulate risk, and align stakeholders and vendors.
    • Strong ownership, and a disciplined approach to change, documentation, risk and assurance.
    • Collaborative technical leader who elevates the capability of the wider engineering team.
  • Preferred Industry Experience
    • Banking
    • Financial Services
    • Insurance (BFSI)
    • Large Enterprise Security Operations Environment
  • Work Model
    • Full-time Remote/ customer onsite deployment at customer location
    • Willingness to support after-hours activities during critical incidents or planned maintenance
    • Participation in on-call support rotation if required

TekWissen® Group is an equal opportunity employer supporting workforce diversity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

Alike Thoughts • Bengaluru, Mumbai

On-site
INR 1,200,000 - 1,800,000
Network Engineer
Network Engineer

SourcingXPress • Hyderabad

On-site
INR 1,200,000 - 3,000,000
Sr. Engineer - Security Engineering
Sr. Engineer - Security Engineering

CBTS • Chennai

On-site
INR 1,000,000 - 1,500,000
Senior Security Engineer (Palo Alto Network)
Senior Security Engineer (Palo Alto Network)

Careernet • Hyderabad

Hybrid
INR 2,800,000 - 4,200,000
Principal Network Engineer
Principal Network Engineer

Keka Inc. • Gurugram District

On-site
INR 4,000,000 - 6,000,000
Learning & Development programs
Mentorship
Internal Job Postings
+1
Security Architect
Security Architect

Accenture in India • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Palo Alto Networks-Consultant-Freelancing
Palo Alto Networks-Consultant-Freelancing

InOpTra Digital • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Presales Solutions Architect - SME
Presales Solutions Architect - SME

Check Point Software • Bengaluru

On-site
INR 4,500,000 - 7,000,000
Market-leading cybersecurity tech
High-visibility role
Staff Professional Service Consultant - Customer Success Engineer Bengaluru, India
Staff Professional Service Consultant - Customer Success Engineer Bengaluru, India

Palo Alto Networks, Inc. • Bengaluru

On-site
INR 3,000,000 - 6,000,000
L3 Endpoint Security Engineer
L3 Endpoint Security Engineer

Terralogic Document Systems, Inc. • Mumbai

On-site
INR 3,200,000 - 6,000,000