Senior Network Security Engineer – Microsegmentation

UST

Bengaluru

On-site

INR 2,000,000 - 4,000,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

UST is seeking a Senior Network Security Engineer to design, implement, and operate secure global network environments from Bengaluru. You will drive segmentation-led security transformations, reduce lateral movement, and enforce least-privilege access across data centres, campuses, and hybrid clouds.

The role requires 7+ years of hands-on experience with microsegmentation platforms, next-gen firewalls, cloud security, SIEM and NAC, and strong collaboration with application and infrastructure

Qualifications

  • Bachelor's degree in CS/IT or related field or equivalent experience.
  • 10+ years in enterprise network security engineering, architecture, or operations.
  • Hands-on microsegmentation experience in large enterprises.

Responsibilities

  • Translate business and security objectives into scalable enterprise network security architectures.
  • Lead end-to-end architecture across data centers, campus, and hybrid clouds.
  • Design secure, highly available network security solutions aligned with standards.
  • Develop multi-year network security roadmaps focused on Zero Trust and segmentation.
  • Perform reviews for new implementations and migrations.
  • Identify gaps and propose improvements to reduce risk.

Skills

microsegmentation
Zero Trust
security architecture
enterprise network security
firewalls
NAC
SDN/SD-WAN
cloud security
SIEM
data center networking

Education

Bachelor's degree in CS/IT or related

Tools

Guardicore
Akamai Segmentation
Fortinet FortiGate
Palo Alto
Juniper
SIEM
EDR/XDR
NAC
Cloud security tools

Job description

Role Description

We are seeking a highly experienced Senior Network Security Engineer with strong expertise in enterprise network security, microsegmentation, Zero Trust, and security architecture to design, implement, and operate secure global network environments. The ideal candidate will have 7+ years of experience in network security engineering and architecture, with hands-on expertise in microsegmentation platforms such as Guardicore/Akamai Segmentation, next-generation firewalls, cloud security, SIEM, NAC, SDN/SD-WAN, and enterprise networking. This role will be responsible for driving segmentation-led security transformation, reducing lateral movement risk, enforcing least-privilege access, and integrating network security controls across data centre, campus, and hybrid cloud environments.

Key Responsibilities
  • Translate business and security objectives into scalable enterprise network security architectures, technical requirements, and conceptual designs.
  • Lead end-to-end network security architecture across global data center, campus, and hybrid cloud environments.
  • Design secure, highly available, resilient, and high-performing network security solutions aligned with enterprise security standards.
  • Develop and maintain a multi-year network security and architecture roadmap aligned with Zero Trust and segmentation strategies.
  • Conduct security architecture and design reviews for new implementations, migrations, and infrastructure changes.
  • Identify security gaps and recommend improvements to strengthen overall enterprise security posture.
Microsegmentation & Zero Trust
  • Architect, implement, and operationalize microsegmentation strategies across data center, campus, cloud, and hybrid environments.
  • Apply Zero Trust Architecture principles to enforce least-privilege access and minimize unauthorized lateral movement.
  • Perform application dependency discovery, traffic-flow analysis, and application mapping to identify communication patterns and segmentation requirements.
  • Design and implement application-aware, identity-driven, and label/tag-based segmentation policies.
  • Develop policies through simulation, testing, enforcement, monitoring, optimization, and continuous improvement.
  • Define and manage segmentation policy lifecycle, governance, standards, and operational procedures.
  • Lead enterprise adoption and implementation of Guardicore/Akamai Segmentation or equivalent microsegmentation technologies.
  • Integrate microsegmentation capabilities with firewalls, SIEM, IAM, EDR/XDR, NAC, and cloud-native security controls.
  • Collaborate closely with application, infrastructure, cloud, and cybersecurity teams to validate application dependencies and ensure successful segmentation rollouts.
  • Establish metrics to measure segmentation effectiveness, policy compliance, risk reduction, and security posture improvement.
Network Security Engineering
  • Design, implement, and optimize enterprise network security controls across LAN/WAN, data center, campus, Internet, and hybrid cloud environments.
  • Provide technical leadership for firewall architecture, policy design, NAT, routing, application control, threat prevention, VPN, IDS/IPS, and NAC.
  • Hands-on experience with enterprise firewall technologies such as: Fortinet FortiGate, Palo Alto Networks, Juniper.
  • Design and implement secure connectivity across AWS, Azure, and GCP environments.
  • Design and integrate Web Application and API Protection (WAAP) solutions.
  • Work with forward/reverse proxies, load balancers, Internet gateways, and application security controls.
  • Support SDN and SD-WAN architectures, particularly security and segmentation use cases.
  • Evaluate emerging network security technologies and recommend solutions based on business and security requirements.
Security Monitoring, Risk & Compliance
  • Manage and optimize SIEM integrations to provide effective security monitoring and visibility.
  • Integrate network security telemetry with SIEM, EDR/XDR, IAM, and other security platforms.
  • Develop and track security risk metrics, control effectiveness, compliance status, and security posture indicators.
  • Support internal and external security audits and compliance assessments.
  • Ensure network security controls align with recognized frameworks and standards such as NIST, CIS, and Zero Trust principles.
  • Maintain awareness of emerging cyber threats and continuously improve security policies and controls.
Network & Infrastructure Expertise
Strong Knowledge And Hands-on Experience With
  • Routing: BGP, OSPF, RIP, MPLS
  • Network services: DNS, DHCP, NTP
  • Networking: IPv4/IPv6, QoS, ACLs, NAT, NetFlow, multicast
  • Wireless: 802.11 technologies and enterprise wireless security
  • VPN: Site-to-site, remote access, and enterprise VPN technologies
  • Load balancing: F5 GTM/LTM
  • Proxy technologies: Forward and reverse proxies
  • Network security: Firewalls, IDS/IPS, DLP, NAC, SIEM
  • Data center networking: Aruba, Arista, Juniper
  • SDN/SD-WAN: Architecture, security controls, and segmentation
Data Center & Cloud Security
  • Design and secure enterprise data centre network environments.
  • Implement security controls across on-premises and cloud infrastructure.
  • Secure east-west and north-south traffic flows.
  • Apply segmentation and workload protection principles across physical, virtual, and cloud workloads.
  • Work with cloud networking and security services across AWS, Azure, and GCP.
  • Ensure security architectures support availability, resilience, scalability, and disaster recovery requirements.
Operations & Lifecycle Management
  • Plan, execute, and document network security changes, upgrades, migrations, and technology refreshes.
  • Troubleshoot complex network security and connectivity issues across enterprise environments.
  • Participate in incident, problem, and change management in accordance with ITIL processes.
  • Develop and maintain technical documentation, architecture diagrams, standards, policies, and operating procedures.
  • Provide technical guidance and mentorship to network and security engineering teams.
  • Participate in on-call or escalation support for critical security infrastructure where required.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related discipline, or equivalent professional experience.
  • 10+ years of experience in enterprise network security engineering, architecture, or operations.
  • Strong hands-on experience designing and implementing microsegmentation in large enterprise environments.
  • Practical experience with Guardicore/Akamai Segmentation or equivalent microsegmentation platforms.
  • Strong understanding of Zero Trust, least privilege, application dependency mapping, and east-west traffic security.
  • Extensive experience with enterprise firewalls such as Palo Alto, Fortinet, and/or Juniper.
  • Strong networking fundamentals with expertise in routing, switching, TCP/IP, DNS, DHCP, NAT, VPN, and network security protocols.
  • Experience securing on-premises, data centre, and public cloud environments.
  • Strong analytical, troubleshooting, architecture, and problem-solving skills.
  • Excellent communication skills with the ability to work effectively with application, infrastructure, cloud, cybersecurity, and business stakeholders.
Skills
  • Access Control Lists, BGP, AWS, Software-Defined Networking
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Engineer
Network Engineer

ITC Infotech • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SME-NETWORKING
SME-NETWORKING

SHI Solutions India Pvt. Ltd. • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Network Security Engineer
Network Security Engineer

Newell Brands • Chennai District

On-site
INR 1,200,000 - 2,100,000
Manager IT
Manager IT

Kansai Nerolac • Mumbai

On-site
INR 4,000,000 - 7,000,000
Senior Network & Information Security Engineer
Senior Network & Information Security Engineer

SolarEdge Technologies • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Network Lead
Network Lead

C3iHub, IIT Kanpur • Kanpur

On-site
INR 3,500,000 - 5,500,000
Senior Technical Lead - Network Security
Senior Technical Lead - Network Security

Meta Infotech • Thane

On-site
INR 1,800,000 - 3,200,000
Network and Security Engineer
Network and Security Engineer

Cigres Technologies Private Limited • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior Network Engineer
Senior Network Engineer

Eurofins • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Network Security Engineer
Network Security Engineer

SHI Solutions India Pvt. Ltd. • Hyderabad

On-site
INR 700,000 - 1,100,000