Senior Network Security Engineer

UST

Bengaluru

On-site

INR 2,400,000 - 4,200,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UST is seeking a Senior Network Security Engineer to design, implement, and operate secure global networks with emphasis on microsegmentation and Zero Trust. The role requires 7+ years of hands-on experience and architecture leadership across data centers, campus, and cloud environments.

You will lead architecture, define segmentation policies, integrate security controls, and work with firewall and cloud security technologies to reduce lateral movement and enforce least-privilege access.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or a related discipline.
  • 10+ years of experience in enterprise network security engineering, architecture, or operations.
  • Strong hands-on experience designing and implementing microsegmentation in large enterprise environments.
  • Practical experience with Guardicore/Akamai Segmentation or equivalent microsegmentation platforms.
  • Strong understanding of Zero Trust, least privilege, application dependency mapping, and east-west traffic security.
  • Extensive experience with enterprise firewalls such as Palo Alto, Fortinet, and/or Juniper.

Responsibilities

  • Translate business and security objectives into scalable enterprise network security architectures, technical requirements, and conceptual designs.
  • Lead end-to-end network security architecture across global data center, campus, and hybrid cloud environments.
  • Design secure, highly available, resilient, and high-performing network security solutions aligned with enterprise security standards.
  • Develop and maintain a multi-year network security and architecture roadmap aligned with Zero Trust and segmentation strategies.
  • Conduct security architecture and design reviews for new implementations, migrations, and infrastructure changes.
  • Identify security gaps and recommend improvements to strengthen overall enterprise security posture.

Skills

Network security engineering
Zero Trust
Microsegmentation
Firewall management
Cloud security
SIEM/NAC/EDR-XDR
Data center networking

Education

Bachelor's degree in Computer Science, Information Technology, or related field

Tools

Guardicore/Akamai Segmentation
Fortinet FortiGate
Palo Alto Networks
Juniper

Job description

Role Description

Senior Network Security Engineer - Microsegmentation & Zero Trust

We are seeking a highly experienced Senior Network Security Engineer with strong expertise in enterprise network security, microsegmentation, Zero Trust, and security architecture to design, implement, and operate secure global network environments.

The ideal candidate will have 7+ years of experience in network security engineering and architecture, with hands-on expertise in microsegmentation platforms such as Guardicore/Akamai Segmentation, next-generation firewalls, cloud security, SIEM, NAC, SDN/SD-WAN, and enterprise networking.

This role will be responsible for driving segmentation-led security transformation, reducing lateral movement risk, enforcing least-privilege access, and integrating network security controls across data center, campus, and hybrid cloud environments.

Key Responsibilities
Network Security Architecture
  • Translate business and security objectives into scalable enterprise network security architectures, technical requirements, and conceptual designs.
  • Lead end-to-end network security architecture across global data center, campus, and hybrid cloud environments.
  • Design secure, highly available, resilient, and high-performing network security solutions aligned with enterprise security standards.
  • Develop and maintain a multi-year network security and architecture roadmap aligned with Zero Trust and segmentation strategies.
  • Conduct security architecture and design reviews for new implementations, migrations, and infrastructure changes.
  • Identify security gaps and recommend improvements to strengthen overall enterprise security posture.
Microsegmentation & Zero Trust
  • Architect, implement, and operationalize microsegmentation strategies across data center, campus, cloud, and hybrid environments.
  • Apply Zero Trust Architecture principles to enforce least-privilege access and minimize unauthorized lateral movement.
  • Perform application dependency discovery, traffic-flow analysis, and application mapping to identify communication patterns and segmentation requirements.
  • Design and implement application-aware, identity-driven, and label/tag-based segmentation policies.
  • Develop policies through simulation, testing, enforcement, monitoring, optimization, and continuous improvement.
  • Define and manage segmentation policy lifecycle, governance, standards, and operational procedures.
  • Lead enterprise adoption and implementation of Guardicore/Akamai Segmentation or equivalent microsegmentation technologies.
  • Integrate microsegmentation capabilities with firewalls, SIEM, IAM, EDR/XDR, NAC, and cloud-native security controls.
  • Collaborate closely with application, infrastructure, cloud, and cybersecurity teams to validate application dependencies and ensure successful segmentation rollouts.
  • Establish metrics to measure segmentation effectiveness, policy compliance, risk reduction, and security posture improvement.
Network Security Engineering
  • Design, implement, and optimize enterprise network security controls across LAN/WAN, data center, campus, Internet, and hybrid cloud environments.
  • Provide technical leadership for firewall architecture, policy design, NAT, routing, application control, threat prevention, VPN, IDS/IPS, and NAC.
  • Hands-on experience with enterprise firewall technologies such as:
    • Fortinet FortiGate
    • Palo Alto Networks
    • Juniper
  • Design and implement secure connectivity across AWS, Azure, and GCP environments.
  • Design and integrate Web Application and API Protection (WAAP) solutions.
  • Work with forward/reverse proxies, load balancers, Internet gateways, and application security controls.
  • Support SDN and SD-WAN architectures, particularly security and segmentation use cases.
  • Evaluate emerging network security technologies and recommend solutions based on business and security requirements.
Security Monitoring, Risk & Compliance
  • Manage and optimize SIEM integrations to provide effective security monitoring and visibility.
  • Integrate network security telemetry with SIEM, EDR/XDR, IAM, and other security platforms.
  • Develop and track security risk metrics, control effectiveness, compliance status, and security posture indicators.
  • Support internal and external security audits and compliance assessments.
  • Ensure network security controls align with recognized frameworks and standards such as NIST, CIS, and Zero Trust principles.
  • Maintain awareness of emerging cyber threats and continuously improve security policies and controls.
Network & Infrastructure Expertise
  • Routing: BGP, OSPF, RIP, MPLS
  • Network services: DNS, DHCP, NTP
  • Networking: IPv4/IPv6, QoS, ACLs, NAT, NetFlow, multicast
  • Wireless: 802.11 technologies and enterprise wireless security
  • VPN: Site-to-site, remote access, and enterprise VPN technologies
  • Load balancing: F5 GTM/LTM
  • Proxy technologies: Forward and reverse proxies
  • Network security: Firewalls, IDS/IPS, DLP, NAC, SIEM
  • Data center networking: Aruba, Arista, Juniper
  • SDN/SD-WAN: Architecture, security controls, and segmentation
Data Center & Cloud Security
  • Design and secure enterprise data center network environments.
  • Implement security controls across on-premises and cloud infrastructure.
  • Secure east-west and north-south traffic flows.
  • Apply segmentation and workload protection principles across physical, virtual, and cloud workloads.
  • Work with cloud networking and security services across AWS, Azure, and GCP.
  • Ensure security architectures support availability, resilience, scalability, and disaster recovery requirements.
Operations & Lifecycle Management
  • Plan, execute, and document network security changes, upgrades, migrations, and technology refreshes.
  • Troubleshoot complex network security and connectivity issues across enterprise environments.
  • Participate in incident, problem, and change management in accordance with ITIL processes.
  • Develop and maintain technical documentation, architecture diagrams, standards, policies, and operating procedures.
  • Provide technical guidance and mentorship to network and security engineering teams.
  • Participate in on-call or escalation support for critical security infrastructure where required.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related discipline, or equivalent professional experience.
  • 10+ years of experience in enterprise network security engineering, architecture, or operations.
  • Strong hands-on experience designing and implementing microsegmentation in large enterprise environments.
  • Practical experience with Guardicore/Akamai Segmentation or equivalent microsegmentation platforms.
  • Strong understanding of Zero Trust, least privilege, application dependency mapping, and east-west traffic security.
  • Extensive experience with enterprise firewalls such as Palo Alto, Fortinet, and/or Juniper.
  • Strong networking fundamentals with expertise in routing, switching, TCP/IP, DNS, DHCP, NAT, VPN, and network security protocols.
  • Experience securing on-premises, data center, and public cloud environments.
  • Strong analytical, troubleshooting, architecture, and problem-solving skills.
  • Excellent communication skills with the ability to work effectively with application, infrastructure, cloud, cybersecurity, and business stakeholders.
Preferred Certifications
  • CCNP / CCIE
  • JNCIE
  • CISSP
  • CISM
  • Vendor-specific firewall or security certifications
  • Relevant cloud security certifications
Skills

Access Control Lists, Compliance Management, Data Loss Prevention, Microsoft Azure

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

Uvation • India

Hybrid
INR 800,000 - 1,500,000
Health insurance
Flexible working hours
Professional development opportunities
Sr. Network Security Engineer with Microsegmentation
Sr. Network Security Engineer with Microsegmentation

Birlasoft • Bengaluru

On-site
INR 3,500,000 - 7,000,000
SME-NETWORKING
SME-NETWORKING

SHI Solutions India Pvt. Ltd. • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Network and Security Engineer - Microsegmentation Specialist
Network and Security Engineer - Microsegmentation Specialist

Birlasoft Limited • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Senior Network & Information Security Engineer
Senior Network & Information Security Engineer

SolarEdge Technologies • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Sr Network Security Engineer With Microsegmentation
Sr Network Security Engineer With Microsegmentation

Birlasoft • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Network and Security Engineer
Network and Security Engineer

Cigres Technologies Private Limited • Bengaluru

On-site
INR 800,000 - 1,200,000
Information Security
Information Security

ESP Engineered • Sahibzada Ajit Singh Nagar

On-site
INR 800,000 - 1,200,000
Network Security Engineer
Network Security Engineer

Aviva India • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Sr. Network Security Engineer
Sr. Network Security Engineer

Bosch Global Software Technologies • Hyderabad, Coimbatore District, Bengaluru

On-site
INR 1,800,000 - 2,400,000