Principal Network Security Engineer

Jobtailor

Penang

On-site

MYR 180,000 - 260,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Altera seeks a senior network security architect to shape and implement our security strategy across data center, campus, cloud, and hybrid environments. You will lead design reviews, guide complex decisions, and drive program governance to reduce risk and improve resilience.

Join a cross-functional team to translate security requirements into actionable designs, telemetry, and automation, while mentoring engineers and aligning with business goals in a dynamic enterprise environment.

Qualifications

  • 8+ years of progressive experience in enterprise networking and cybersecurity, including substantial experience designing security architecture for large, distributed environments.

Responsibilities

  • Define and evolve Altera’s enterprise network security strategy, target-state architecture, technical roadmap, and reusable reference patterns.

Skills

Enterprise network architecture
Zero Trust
Firewall management
Incident response
Network security automation
Packet capture
Security design review
Network telemetry

Tools

Cisco
Palo Alto Networks
Tufin
Azure
AWS
SIEM

Job description

  • Define and evolve Altera’s enterprise network security strategy, target-state architecture, technical roadmap, and reusable reference patterns.
  • Serve as the senior technical authority for complex network security decisions, design exceptions, and modernization initiatives.
  • Drive adoption of Zero Trust, least-privilege access, micro-segmentation, and secure-by-design network principles.
  • Establish architecture standards, decision criteria, and measurable outcomes for attack-path reduction, rule hygiene, segmentation coverage, resilience, and network visibility.
  • Architect and review secure designs for data center, campus, laboratory, cloud, WAN, remote-access, and hybrid environments.
  • Design segmentation and traffic-control models using security zones, VRFs, next-generation firewalls, secure routing, identity-aware access, and workload-level controls.
  • Evaluate and guide adoption of ZTNA, SWG, SASE, SD-WAN, NDR, IDS/IPS, firewall, and network-security automation capabilities.
  • Partner with network, cloud, platform, product security, and operations teams to translate security requirements into implementable designs.
  • Validate architecture through design reviews, configuration analysis, packet and flow analysis, resilience testing, and post-implementation verification.
  • Conduct ongoing firewall administration and operations including policy lifecycle management, rule administration, hardening, and exception governance.
  • Provide senior technical expertise during investigations involving network intrusion, lateral movement, command-and-control activity, privilege misuse, and data exfiltration.
  • Design and improve network telemetry, logging, detection coverage, and correlation across SIEM, NDR, firewalls, proxies, DNS, VPN, and cloud network services.
  • Perform or guide packet capture, flow analysis, protocol troubleshooting, and root-cause analysis for complex security events.
  • Act as a technical escalation point during major incidents and translate findings into architecture improvements, detection enhancements, and remediation plans.
  • Perform security architecture and risk assessments for new systems, cloud services, network changes, and exceptions.
  • Author and maintain network security standards, reference architectures, technical guidelines, and control requirements.
  • Align designs with NIST CSF, NIST SP 800-53, NIST SP 800-207, and ISO/IEC 27001.
  • Provide technical evidence and remediation guidance for audits, assessments, and control-validation activities.
  • Serve as a trusted technical advisor to IT and Engineering teams and stakeholders across Network Engineering, Cloud, Infrastructure, DevOps, Product Security, Risk, Privacy, and Legal.
  • Facilitate architecture workshops and design reviews, documenting decisions, risks, assumptions, and required controls.
  • Translate complex technical risks into practical, business-aligned recommendations for engineering and executive audiences.
  • Influence delivery teams without direct authority and mentor engineers through technical guidance, peer review, and knowledge sharing.
Requirements
  • 8+ years of progressive experience in enterprise networking and cybersecurity, including substantial experience designing security architecture for large, distributed environments.
  • Demonstrated success serving as a principal engineer, architect, or senior technical authority for complex network-security programs and transformations.
  • Proven ability to own technical outcomes from discovery and requirements through design, implementation guidance, validation, and operational transition.
  • Deep expertise in enterprise network architecture, TCP/IP, routing, switching, BGP, DNS, TLS, proxies, VPN, firewalls, IDS/IPS, segmentation, and Zero Trust.
  • Hands-on experience with next-generation firewalls, firewall policy governance, ZTNA, SWG, SASE, SD-WAN, NDR, SIEM, and related network-security controls.
  • Strong packet capture, protocol analysis, network-flow analysis, and complex troubleshooting skills.
  • Experience designing secure network connectivity and controls across on-prem, cloud and hybrid environments.
  • Experience with common enterprise platforms such as Cisco, Palo Alto Networks, Tufin, Azure, AWS, or comparable technologies.
  • Strong understanding of high availability, failover, capacity, secure management planes, encrypted connectivity, and resilient architecture.
  • Experience in firewall management, administration, and operations including firewall architecture, policy lifecycle management, rule recertification, configuration hardening, and operational governance.
  • Ability to identify and reduce attack paths, improve rule hygiene, expand segmentation coverage, and strengthen network telemetry.
  • Proficiency in network incident response, technical escalation, root-cause analysis, and remediation design.
  • Ability to establish repeatable engineering processes, architecture review methods, validation criteria, and operational runbooks.
  • Experience automating network-security analysis, policy management, validation, or reporting using Python, APIs, infrastructure-as-code, KQL, or similar technologies.
  • Excellent executive-level communication skills.
  • Ability to translate technical concepts into business-aligned recommendations.
  • Strong stakeholder management across technical and non-technical teams.
Core Competencies

Demonstrates extensive expertise in enterprise network security architecture, including Zero Trust principles, firewall management, and incident response. Proven ability to translate complex security requirements into actionable designs and recommendations for diverse environments.

Highest-signal resume keywords
  • Enterprise Network Architecture
  • Zero Trust Implementation
  • Next-Generation Firewall Management
  • Packet Capture and Protocol Analysis
  • Cloud Security Design
ATS Optimization Keywords
Hard Skills
  • TCP/IP
  • Routing
  • Switching
  • BGP
  • DNS
  • TLS
  • VPN
  • IDS/IPS
  • Segmentation
  • Network Security Automation
Soft Skills
  • Executive-Level Communication
  • Stakeholder Management
  • Technical Guidance
  • Mentoring
  • Collaboration
Certifications & Qualifications
  • NIST CSF
  • NIST SP 800-53
  • NIST SP 800-207
  • ISO/IEC 27001
Industry Keywords
  • Network Security Strategy
  • Architecture Standards
  • Attack-Path Reduction
  • Rule Hygiene
  • Network Visibility
Tools & Technologies
  • Cisco
  • Palo Alto Networks
  • Tufin
  • Azure
  • AWS
  • SIEM
  • ZTNA
  • SWG
  • SASE
  • SD-WAN
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Network Security Engineer
Principal Network Security Engineer

Altera Corporation • Kuala Lumpur

On-site
MYR 240,000 - 420,000
Principal Network Security Engineer
Principal Network Security Engineer

altera • Malaysia

On-site
MYR 180,000 - 320,000
Network Security Engineer
Network Security Engineer

Singtel • Kuala Lumpur

On-site
Confidential
Principal Network Security Engineer
Principal Network Security Engineer

754 Altera Semiconductor Technology (M) Sdn. Bhd. • George Town

On-site
MYR 260,000 - 420,000
Principal Network Security Engineer
Principal Network Security Engineer

Altera • Bayan Lepas

On-site
MYR 180,000 - 300,000
Senior Network Engineer
Senior Network Engineer

Kagina Pte Ltd • Ipoh

On-site
MYR 120,000 - 180,000
Network Engineer
Network Engineer

Soft Space • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Network Security Engineer
Network Security Engineer

CLOUDENGINE DIGITAL SDN. BHD. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Network Architect
Network Architect

Ad Astra Consultants • Seremban

On-site
MYR 120,000 - 180,000
Network & Security Specialist Engineer
Network & Security Specialist Engineer

ENOVIX Corporation • Penang

On-site
MYR 90,000 - 130,000