Track Manager (Support & Operations)

HCL Technologies Limited

New Jersey

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

HCLTech is seeking a Network Security Engineer (L3) to provide expert firewall and VPN management, 24x7 monitoring, and major incident RCA leadership. You will own complex changes, ensure secure operations, and mentor junior staff across Palo Alto, Fortinet, Check Point, and Cisco platforms.

The role requires deep L3 knowledge, certifications, and experience with security tooling such as Panorama, SIEM/SOAR, and ServiceNow. Strong coordination with SOC and OEM teams is essential.

Qualifications

  • Advanced firewall/VPN expertise required.
  • L3 escalation ownership for complex issues.
  • Experience with major incident restoration and RCA leadership.
  • Knowledge of firewall architecture, policy hierarchy and NAT design.
  • ITIIL and security governance awareness.

Responsibilities

  • Advanced Firewall/VPN Escalation: act as L3 escalation point for complex firewall and VPN issues.
  • Major Incident Leadership: lead network security recovery during P1/P2 incidents and coordinate with SOC and OEM teams.
  • Firewall Architecture & Optimization: review and optimize firewall architecture and segmentation patterns.
  • Complex Change Ownership: plan and execute high-risk changes with testing and evidence.
  • VPN & Remote Access SME: manage IPSec, SSL VPN, ZTNA, and related components.
  • Threat Prevention & Inspection: support IPS/IDS, malware, URL filtering and SSL decryption.
  • Deep Log & Packet Analysis: analyze logs and captures to determine root cause and remediation options.
  • Governance, Standards & Compliance: define governance standards, audit controls, and log retention.

Skills

Firewall expertise
VPN expertise
Incident management
Security architecture
L3 expertise

Education

PCNSE
NSE4/5/7
CCNP/CCIE Security
CCSA/CCSE
ITIL

Tools

Panorama
FortiAnalyzer
FortiManager
SmartConsole
SIEM/SOAR
ServiceNow
Wireshark

Job description

Job Summary : Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations.

2. Role Purpose & Business Outcomes

  • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues.
  • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure.
  • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls.
  • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence.
  • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews.

3. Key Roles & Responsibilities

  • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues.
  • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams.
  • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability.
  • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support.
  • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues.
  • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection.
  • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options.
  • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Key Responsibilities

Job Summary : Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations.

2. Role Purpose & Business Outcomes

  • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues.
  • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure.
  • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls.
  • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence.
  • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews.

3. Key Roles & Responsibilities

  • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues.
  • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams.
  • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability.
  • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support.
  • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues.
  • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection.
  • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options.
  • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Skill Requirements

Job Summary : Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations.

2. Role Purpose & Business Outcomes

  • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues.
  • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure.
  • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls.
  • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence.
  • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews.

3. Key Roles & Responsibilities

  • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues.
  • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams.
  • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability.
  • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support.
  • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues.
  • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection.
  • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options.
  • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Other Requirements

Job Summary : Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations.

2. Role Purpose & Business Outcomes

  • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues.
  • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure.
  • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls.
  • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence.
  • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews.

3. Key Roles & Responsibilities

  • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues.
  • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams.
  • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability.
  • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support.
  • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues.
  • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection.
  • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options.
  • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Technical Support Engineer (CNGFW)
Senior Technical Support Engineer (CNGFW)

Palo Alto Networks • Plano (TX)

On-site
USD 103,000 - 167,000
Senior Network Engineer
Senior Network Engineer

HCLTech • Highlands Ranch (CO)

On-site
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Sr Administrator (Support & Operations)
Sr Administrator (Support & Operations)

HCL Technologies Limited • Town of Florida (NY)

On-site
USD 50,000 - 75,000
Medical insurance
Dental insurance
Vision insurance
+3
Cyber Security Architect
Cyber Security Architect

HCLTech • Dallas (TX)

On-site
USD 130,000 - 185,000
Performance-based bonuses
Medical/Dental/Vision insurance
401(k) retirement plan
+2
Palo Alto Firewall Lead Engineer
Palo Alto Firewall Lead Engineer

Wipro • Tulsa (OK)

On-site
USD 80,000 - 158,000
Senior Technical Support Engineer (CNGFW)
Senior Technical Support Engineer (CNGFW)

Palo Alto Networks, Inc. • Plano (TX)

On-site
USD 103,000 - 167,000
—
—
Senior Network Engineer
Senior Network Engineer

HCLTech • Downers Grove (IL)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2
Solutions Architect
Solutions Architect

HCL Technologies Limited • Seattle (WA)

On-site
USD 130,000 - 175,000
Staff Cloud Network Engineer
Staff Cloud Network Engineer

Eliassen Group • Indianapolis (IN)

Remote
USD 83,000 - 124,000
Medical, Dental, Vision benefits
401k with company matching
Life insurance
Staff Cloud Network Engineer
Staff Cloud Network Engineer

Eliassen Group • Hagåtña (GU)

Remote
USD 83,000 - 124,000
Medical benefits
Dental benefits
Vision benefits
+2