Senior Infrastructure Engineer

Nike Inc

Karnataka

On-site

INR 2,800,000 - 4,000,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Nike Inc in India’s Karnataka is seeking a Senior Firewall Engineer to design, deploy, and operate the global Network Security Platform. You will lead Firewall-as-Code, Zero Trust initiatives, and cloud security transformations in collaboration with security architects, cloud engineers, and platform teams.

The role requires 5+ years in enterprise network security, deep hands-on with Palo Alto NGFW, Panorama, Cloud NGFW, Prisma Access, and TLS decryption at scale.

Qualifications

  • 5+ years of experience in Network Security Engineering in enterprise environments.
  • Deep hands-on expertise with Palo Alto NGFW, Panorama, and Cloud NGFW.
  • Strong understanding of Zero Trust, segmentation, and micro-segmentation strategies.
  • Experience with REST APIs, JSON, YAML, and API-driven automation.
  • Proficient in Python for automation and integration tasks.

Responsibilities

  • Design, deploy, and support Palo Alto NGFW, Panorama, Cloud NGFW, and Prisma Access.
  • Lead Tier-3 troubleshooting involving policy enforcement, SSL decryption, and cloud integration.
  • Develop production-grade design documents, runbooks, and RCA reports.
  • Implement Firewall-as-Code with Git-based workflows and IaC principles.
  • Build Python-based automation for policy management and deployment.
  • Integrate firewall platforms with ITSM, CMDB, observability, and orchestration tools.

Skills

Enterprise network security
Automation mindset
Python automation
REST APIs & YAML/JSON
Git-based workflows

Tools

Palo Alto NGFW
Panorama
Cloud NGFW
Prisma Access
SSL/TLS decryption tooling
Cisco ISE
Terraform
Ansible

Job description

WHO YOU’LL WORK WITH

As a Senior Firewall Engineer (Level 3), you will provide expert‑level technical engineering and design for enterprise network security infrastructure. You will be responsible for working complex firewall deployments, handling high‑level tier‑3 troubleshooting, and driving innovation in advanced cloud firewall capabilities. This role requires an expert understanding of network security principles, deep hands‑on technical experience with enterprise firewall technologies, and the ability to solve complex infrastructure challenges. Primary customers and peer groups will be Core Infrastructure Engineering, Corporate Information Security, and Nike Operations Center

WHO WE ARE LOOKING FOR

The ideal candidate brings strong enterprise network security expertise combined with an engineering mindset focused on automation, platform scalability, and operational excellence. This individual should possess deep technical knowledge of Palo Alto security platforms, cloud security architectures, security automation, and modern software engineering practices. The candidate will play a critical role in designing, building, automating, and supporting Nike's next‑generation Network Security Platform while contributing to Firewall‑as‑Code, Zero Trust, and cloud security transformation initiatives.

  • 5+ years of experience in Network Security Engineering with demonstrated expertise in enterprise‑scale network security environments.

  • Deep hands‑on expertise with Palo Alto Networks NGFW, Panorama, Log Collectors, Device Groups, Template Stacks, and enterprise firewall architectures.

  • Strong understanding of enterprise networking fundamentals including routing, switching, TCP/IP, DNS, DHCP, WAN, cloud networking, and application traffic flows.

  • Hands‑on experience with Cloud NGFW, Prisma Access (SASE/SSE), and modern cloud‑delivered security platforms.

  • Experience designing and supporting SSL/TLS decryption solutions at scale, with an understanding of privacy and regulatory requirements including GDPR, DPDP, and CCPA.

  • Experience with Network Access Control platforms such as Cisco ISE, including TACACS+, RADIUS, posture assessment, profiling, and identity‑based access controls.

  • Strong understanding of Zero Trust principles, identity‑aware security policies, network segmentation, and micro‑segmentation strategies.

  • Advanced troubleshooting capabilities including packet captures, session analysis, flow analysis, log correlation, performance troubleshooting, and root cause analysis.

  • Experience integrating firewall telemetry and operational data with Panorama, Splunk, SIEM platforms, and enterprise observability solutions.

  • Strong proficiency in Python development for automation, API integrations, workflow orchestration, and operational tooling.

  • Experience working with REST APIs, JSON, YAML, and API‑driven infrastructure automation.

  • Proficiency with Git‑based development workflows including branching strategies, pull requests, code reviews, and version control best practices.

  • Hands‑on experience with automation technologies such as Ansible, Terraform, and Infrastructure‑as‑Code methodologies.

  • Experience building and supporting CI/CD pipelines using GitHub Actions, Jenkins, Azure DevOps, GitLab CI, or similar technologies.

  • Understanding of software development lifecycle (SDLC), testing methodologies, release management, and engineering best practices.

  • Experience building reusable automation services, engineering tools, and platform capabilities that improve operational efficiency and engineering productivity.

  • Understanding of Firewall‑as‑Code, Policy‑as‑Code, and Infrastructure‑as‑Code concepts and implementation patterns.

  • Experience leveraging telemetry, monitoring, and observability platforms to improve operational visibility and platform reliability.

  • Strong understanding of service health monitoring, alerting strategies, troubleshooting workflows, and operational analytics.

WHAT YOU’LL WORK ON

You will be responsible for designing, engineering, automating, and operating Nike's global Network Security Platforms. As a Senior Network Security Platform Engineer, you will serve as a key technical contributor driving Firewall‑as‑Code, Zero Trust, cloud security, observability, and security automation initiatives. You will partner closely with security architects, cloud engineers, platform engineers, and infrastructure teams to build scalable, reliable, and automation‑first security services.

  • Serve as a senior technical engineer within the Network Security Platform team, delivering secure, scalable, and highly available firewall solutions across global environments.

  • Design, deploy, and support Palo Alto NGFW, Panorama, Cloud NGFW, and Prisma Access solutions while ensuring adherence to architectural standards and security best practices.

  • Lead complex Tier‑3 troubleshooting activities involving network connectivity, application flows, security policy enforcement, SSL decryption, routing, and cloud integrations.

  • Develop production‑grade technical documentation, including High‑Level Designs (HLDs), Low‑Level Designs (LLDs), implementation plans, operational runbooks, and Root Cause Analysis (RCA) reports.

  • Design and implement Firewall‑as‑Code capabilities leveraging Git‑based workflows, Infrastructure‑as‑Code principles, APIs, and automation frameworks.

  • Build and maintain Python‑based automation solutions to automate firewall policy management, configuration deployment, compliance validation, and operational workflows.

  • Develop reusable automation modules, frameworks, and self‑service capabilities that reduce manual effort and improve engineering efficiency.

  • Integrate firewall platforms with enterprise systems including ITSM, CMDB, observability, and orchestration platforms through API‑driven automation.

  • Implement Policy‑as‑Code and automated validation frameworks to improve change quality and deployment consistency

  • Contribute to Infrastructure‑as‑Code implementations using Terraform, Ansible, and related automation technologies.

  • Build and support CI/CD pipelines for firewall policy deployment, platform configuration management, and security automation workflows.

  • Participate in code reviews, testing, release management, and engineering governance processes to maintain high‑quality engineering standards.

  • Collaborate with platform engineering teams to integrate network security capabilities into enterprise DevSecOps pipelines.

  • Support Nike's Zero Trust initiatives through network segmentation, identity‑aware security policies, micro‑segmentation, and secure access architectures.

  • Evaluate and implement cloud‑native security services, SASE/SSE technologies, and emerging cloud firewall capabilities.

Preferred Qualification / Nice to Have:
  • PCNSE / CCNP security certification

  • CCNA Routing & Switching certification

  • Any cloud provider certification

  • Coding language (Other than python, Ansible, if any)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Infrastructure Engineer
Lead Infrastructure Engineer

Nike • Karnataka

On-site
INR 4,200,000 - 7,000,000
Network Engineer
Network Engineer

SourcingXPress • Hyderabad

On-site
INR 1,200,000 - 3,000,000
Senior Security Engineer (Palo Alto Network)
Senior Security Engineer (Palo Alto Network)

Careernet • Hyderabad

Hybrid
INR 2,800,000 - 4,200,000
Network Security Automation
Network Security Automation

LTM • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Staff Professional Service Consultant - Customer Success Engineer
Staff Professional Service Consultant - Customer Success Engineer

Palo Alto Networks • Bengaluru

On-site
INR 3,000,000 - 4,200,000
Palo Alto Security Engineer
Palo Alto Security Engineer

Zappsec Inc. • India

On-site
INR 4,000,000 - 6,500,000
Principal Network Engineer
Principal Network Engineer

Keka Inc. • Gurugram District

On-site
INR 4,000,000 - 6,000,000
Learning & Development programs
Mentorship
Internal Job Postings
+1
Senior Network Security Engineer / Security Architect
Senior Network Security Engineer / Security Architect

Sb Hr Consultancy Kolkata • Dadri, Greater Noida

On-site
INR 900,000 - 1,300,000
SME-NETWORKING
SME-NETWORKING

SHI Solutions India Pvt. Ltd. • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Network and Security Engineer
Network and Security Engineer

Cigres Technologies Private Limited • Bengaluru

On-site
INR 800,000 - 1,200,000