Network Security Engineer

PTR Global

Irving (TX)

Hybrid

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PTR Global is seeking an Information Security Engineer to advance our Zero Trust micro-segmentation program. You will operate a SaaS-based Illumio platform with limited on-prem presence, manage VEN agents across Windows and Linux, and ensure least-privilege policies are verifiable via telemetry.

You will analyze ingestion pipelines and SIEM telemetry, lead incident response, and coordinate with Network, NOC/NMC, and application teams to deploy changes safely across hybrid environments.

Qualifications

  • 4+ years of Information Security Engineering experience or equivalent.
  • Experience with production change management and incident response.
  • Ability to translate telemetry into executive-level summaries.
  • Experience designing least-privilege segmentation policies.
  • Familiarity with hybrid on-prem and cloud environments.

Responsibilities

  • Operate and mature the Illumio micro-segmentation platform (SaaS with limited on-prem presence).
  • Design, validate, and deploy least-privilege segmentation policies with verifiable telemetry.
  • Analyze traffic flow telemetry and delay metrics across ingestion pipelines and SIEM tooling.
  • Lead incident response and vendor escalation with Illumio engineering.
  • Coordinate production changes and policy deployments with cross-functional teams.
  • Maintain security standards, baselines, and deployment guidance.
  • Support large-scale onboarding and migration efforts, including SaaS cutovers.

Skills

SIEM proficiency
Telemetry analysis
Linux administration
Windows server administration
Incident response
Policy design
Executive-level communication

Tools

Illumio
VEN agent lifecycle

Job description

Traffic and Telemetry Analysis:
  • Strong proficiency with SIEM tools (especially time-based analysis, distributions, and baselining).
  • Ability to reason about event ingestion pipelines and end-to-end telemetry delivery.
Operating Systems and Infrastructure:
  • Solid Linux and Windows server fundamentals.
  • Understanding of application communication patterns, service dependencies, and network flows.
Operational Maturity:
  • Experience with production change management and incident response.
  • Ability to halt or delay enforcement when telemetry or validation is insufficient.
Communication and Influence:
  • Ability to clearly communicate technical risk, impact, and recommendations to engineers, leadership, and vendors.
  • Comfortable translating telemetry and failures into executive-level summaries.
Mission (Overarching Goal):
  • Advance the enterprise Zero Trust micro-segmentation program, delivering safe, auditable, and scalable traffic visibility and policy enforcement across hybrid environments (on-prem and cloud). This role ensures operational reliability, policy confidence, and vendor accountability for Illumio SaaS–based segmentation at enterprise scale.
Day-to-Day Responsibilities:
  • Operate and mature the Illumio micro-segmentation platform (SaaS with limited on-prem presence), including VEN agent lifecycle management across Windows, Linux, and future AIX workloads.
  • Design, validate, and deploy least-privilege segmentation policies, ensuring policy changes can be safely verified via traffic telemetry before and after enforcement.
  • Analyze traffic flow telemetry and delay metrics across ingestion pipelines and SIEM tooling to validate platform health, identify regressions, and distinguish policy issues from platform or vendor constraints.
  • Lead incident response and vendor escalation with Illumio engineering, including capacity constraints, SaaS scaling events, maintenance windows, and potential data integrity risks.
  • Partner with Network Engineering, NOC/NMC, application teams, and platform owners to coordinate production changes, policy deployments, and change-management activities.
  • Maintain and evolve security standards, baselines, and deployment guidance for enterprise micro-segmentation, aligning to internal governance, audit, and risk requirements.
  • Support large-scale onboarding and migration efforts, including SaaS cutovers, phased policy enforcement, and certification of segmentation controls for high-risk and payment applications.
Nice-to-Haves (Certifications / Extras):
Security and Architecture:
  • CISSP, CCSP, or comparable security architecture certification
  • Zero Trust–focused training or vendor micro-segmentation certifications
Cloud and Identity:
  • Familiarity with Azure and enterprise IAM concepts (SaaS authentication, RBAC, API access)
Advanced Platform Integration:
  • Experience integrating segmentation telemetry into SIEM, data lakes, or automation pipelines
  • Exposure to policy certification, audit traceability, or regulatory reporting.
Additional Skills:
In this contingent resource assignment, candidate may:
  • Consult on or participate in moderately complex initiatives and deliverables within Information Security Engineering and contribute to large-scale planning related to Information Security Engineering deliverables.
  • Review and analyze moderately complex Information Security Engineering challenges that require an in-depth evaluation of variable factors.
  • Contribute to the resolution of moderately complex issues and consult with others to meet Information Security Engineering deliverables while leveraging solid understanding of the function, policies, procedures, and compliance requirements.
  • Collaborate with client personnel in Information Security Engineering.
Required Qualifications:
  • 4 plus years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect and ZeroTrust Solution Engineer
Security Architect and ZeroTrust Solution Engineer

Estée Lauder Companies • New York (NY)

On-site
USD 140,000 - 180,000
Zero Trust Segmentation Engineer (SaaS Illumio)
Zero Trust Segmentation Engineer (SaaS Illumio)

PTR Global • Irving (TX)

Hybrid
USD 120,000 - 150,000
Senior Security Architect
Senior Security Architect

Compunnel, Inc. • Rhode Island

On-site
USD 120,000 - 160,000
Network Segmentation Analyst
Network Segmentation Analyst

Compunnel, Inc. • Town of Texas (WI)

On-site
USD 100,000 - 130,000
Remote Illumio Microsegmentation Engineer, Zero Trust
Remote Illumio Microsegmentation Engineer, Zero Trust

System One • Vienna (VA)

On-site
Sr. Member of Technical Staff - Platform
Sr. Member of Technical Staff - Platform

Illumio • San Jose (CA)

On-site
USD 160,000 - 210,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Liberty Personnel Services, Inc. • Feasterville-Trevose

Hybrid
USD 90,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

ASSA ABLOY Sicherheitstechnik GmbH • New Haven (CT)

On-site
USD 120,000 - 160,000
Healthcare options
401k matching
Paid time off
+1
Senior Security & Infrastructure Engineer
Senior Security & Infrastructure Engineer

Zentalis Pharmaceuticals • San Diego (CA)

On-site
USD 150,000 - 210,000