Security Engineer – Network Security

USER EXPERIENCE RESEARCHERS PTE. LTD

Singapore

On-site

SGD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

USER EXPERIENCE RESEARCHERS PTE. LTD. is seeking a senior network security engineer to lead design, deployment, and governance of secure hybrid/multicloud networks across data centers.

Responsibilities include architecting security architectures, integrating with Cisco ACI, and guiding SME-level troubleshooting. The role emphasizes automation and collaboration with security and cloud teams.

Qualifications

  • Bachelor's or Master's degree in CS/IT or related field.
  • Certifications CISSP/CCSA/CCSE/PCNSE/ICE/BIG-IP ASM or equivalent preferred.
  • 10–15 years of experience in Network Security technologies.
  • Experience with NGFWs, IDPS, WAF, DNS security, and micro-segmentation.

Responsibilities

  • Lead design, engineering, and execution of next-gen network transformation solutions.
  • Collaborate with cloud, security, and app stakeholders to align infra with business needs.
  • Provide technical leadership to build resilient, scalable, and secure hybrid/multicloud networks.
  • Architect and deploy Network Security across data centers (DC1 & DC2).
  • Integrate with Cisco ACI environments for secure connectivity and performance.
  • Serve as escalation point for operations on network security issues (L3/SME).
  • Collaborate with vendors, TAC, and internal teams to resolve incidents.
  • Develop and enforce policy-driven network security architectures; leverage Ansible, Python for automation.
  • Maintain network security diagrams, runbooks, and documentation; ensure governance and compliance.
  • Lead knowledge sharing and mentorship on network security technologies.

Skills

Network Security
Firewalls
IDPS
WAF
Micro-segmentation
DNS
NAC
SIEM
Zero Trust
Cloud/Hybrid

Education

Bachelor's degree in Computer Science / IT
Master's degree in related field
Certifications: CISSP, CCSA, CCSE, PCNSE, ICE, BIG-IP ASM Specialist

Tools

Ansible
Python
Cisco ACI
Illumio
Guardicore
Infoblox
Wireshark
Riverbed AppResponse
Cisco ThousandEyes
Splunk
Elastic

Job description

Roles & Responsibilities
  • Part of a team that is responsible for the Network Security Engineering & Deployment function and will play a key rolein Datacenter Migration projects.
Network Transformation Architecture:
  • Lead the design, engineering, and execution of next-generation network transformation solutions.
  • Collaborate with internal teams, including cloud, security, and application stakeholders, to align networkinfrastructure with business needs.
  • Provide technical leadership in building resilient, scalable, and secure hybrid and multicloud network
  • environments.
Design, Deployment, and Operations:
  • Architect and deploy advanced Network Security across data centers (DC1 & DC2).
  • Integrate network security products with Cisco ACI environments to deliver seamless and secure connectivitywith optimal performance.
  • Act as an escalation point for the Operations team on network security issues, providing Level 3troubleshooting and SME-level support.
  • Collaborate with vendors, TAC, and internal teams to resolve complex network & Security incidents andescalations.
Policy Management and Automation:
  • Develop and enforce policy-driven network security architectures.
  • Leverage automation tools (e.g., Ansible, Python, XSOR) to enhance operational efficiency and minimizemanual interventions.
  • Ensure compliance with industry standards and internal governance policies while aligning network securityconfigurations with best practices.
Documentation and Governance:
  • Maintain accurate network security diagrams, operational runbooks, and technical documentation.
  • Ensure all security implementations adhere to governance frameworks and meet regulatory compliance
  • requirements.
Mentorship and Knowledge Sharing:
  • Provide Level3/SME-level support and guidance to peers and stakeholders within the organization.
  • Lead knowledge transfer sessions on network security technologies and best practices.
Job Requirements:
Education:
  • Bachelors or Masters degree in Computer Science, Information Technology, or related field.
  • Certifications: CISSP,CCSA ,CCSE,PCNSE,ICE,BIG-IP ASM Specialist or equivalent will be preferred.
Preferred qualifications and knowledge base:
Technical Expertise:
  • 10 to 15 years of experience in Network Security technologies like Firewalls, Intrusion Detection &Prevention Systems (IDPS), Web Application Firewalls (WAF), Micro-segmentation, Web Proxies, and DNS.
Firewall Technologies:
  • Next-Generation Firewalls (NGFWs): Understanding of advanced features like Application Awareness,Intrusion Prevention, and Deep Packet Inspection.
  • Checkpoint Firewall Architecture: Expertise in Threat Prevention, VPNs, and High Availability (HA)configuration.
  • Palo Alto Networks NGFWs: Knowledge of App-ID, WildFire, and User-ID for enhanced security.
  • Firewall Rule Optimization: Experience in defining and fine-tuning access control policies and inspectingnetwork traffic for threats.
  • Expertise in implementing DNS Security solutions to prevent attacks such as DNS Spoofing, Cache Poisoning,and DDoS attacks targeting DNS infrastructure.
Intrusion Detection and Prevention Systems (IDPS):
  • Signature-Based IDS/IPS: Expertise in configuring and managing signature-based detection.
  • Anomaly-Based IDS/IPS: Deep knowledge of Behavioral Analysis for detecting suspicious patterns and zeroday attacks.
  • Integrated Security Operations: Integration of IDPS with SIEM systems for centralized log management andthreat detection.
Web Application Security:
  • Web Application Firewall (WAF): Expertise in configuring and managing F5 ASM or equivalent WAF solutionsfor protecting applications from vulnerabilities.
  • Bot Protection and DDoS Mitigation: Knowledge of Bot Management and DDoS Defense strategies forprotecting web applications.
Microsegmentation and Zero Trust Security:
  • Microsegmentation: Proficiency in tools like Illumio or Guardicore for isolating and securing workloads withinthe data center and cloud environments.
  • Zero Trust Architecture (ZTA): Expertise in defining and enforcing access policies based on identity and deviceposture, and validating every user and device before granting access.
Network Access Control (NAC):
  • Aruba ClearPass: Expertise in configuring role-based access control and integrating ClearPass with other network
  • security solutions.
  • Cisco Identity Services Engine (ISE): Knowledge of 802.1X, MAB (MAC Authentication Bypass), and Guest Access in NAC
  • environments.
DNS & IP Address Management (IPAM):
  • Infoblox DDI (DNS, DHCP, IPAM): Experience in configuring and managing Infoblox for network address allocation, DNSresolution, and advanced DNS security.
  • DNS Security: Expertise in securing DNS infrastructure through DNSSEC, DNS filtering, and DNS over HTTPS (DoH).Traffic Visibility & Monitoring:
Network Traffic Analysis:
  • Proficiency in using tools like Wireshark, Riverbed App Response , Cisco Thousand Eyes ,NetFlow, and sFlow for trafficanalysis and anomaly detection.
Security Information and Event Management (SIEM):
  • Expertise in integrating network devices with Splunk, Elastic or Equivalent for threat visibility and incident response.
Routing Protocols & VPNs:
  • BGP (Border Gateway Protocol): In-depth understanding of BGP routing policies, route filtering, and peering in largescale network environments.
  • OSPF (Open Shortest Path First): Expertise in dynamic routing configuration, including OSPF multi-area and OSPFv3 forIPv6 support.
  • Site-to-Site and Remote Access VPNs: Knowledge of configuring IPSec VPNs and SSL VPNs for secure communicationsacross branches and remote users.
Soft Skills:
  • Excellent analytical, problem-solving, and decision-making skills.
  • Strong communication and collaboration skills, with the ability to engage with stakeholders acrossdepartments.
  • Self-motivated with a continuous learning mindset and ability to work under pressure.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior ICT Infrastructure Engineer (Network)
Senior ICT Infrastructure Engineer (Network)

INNOVATIQ TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Senior ICT Infrastructure Engineer (Network)
Senior ICT Infrastructure Engineer (Network)

innovatiq technologies pte. ltd. • Shenton Way

On-site
SGD 120,000 - 180,000
Network Specialist
Network Specialist

LPS • Singapore

On-site
SGD 90,000 - 130,000
Network Security Manager
Network Security Manager

Good co India • Singapore

On-site
SGD 120,000 - 180,000
Network Security L3
Network Security L3

HCLTech • Singapore

On-site
SGD 110,000 - 170,000
Senior Network Engineer
Senior Network Engineer

pccw solutions insys pte. ltd. • Singapore

On-site
SGD 120,000 - 180,000
Senior Network Security Engineer - L3 Incident & Cloud
Senior Network Security Engineer - L3 Incident & Cloud

HCLTech • Singapore

On-site
SGD 110,000 - 170,000
Network Security Engineer - L3
Network Security Engineer - L3

HCL Singapore Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
[LPS] Network Engineer
[LPS] Network Engineer

Lenovo PCCW Solutions • Singapore

On-site
SGD 90,000 - 150,000
Engineer/Senior Engineer, Networks and Security
Engineer/Senior Engineer, Networks and Security

Y3 TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 60,000 - 90,000