Position Summary
The Network Security Engineer is responsible for designing, implementing, and maintaining the security of the organization’s network infrastructure. The role focuses on securing routers, switches, firewalls, VPNs, and other network devices while ensuring the network remains resilient against cyber threats, optimized for performance, and aligned with security and compliance requirements. The incumbent will actively monitor network activity, manage perimeter defense, and enforce network security policies across all environments.
Key Responsibilities
- Design and implement secure network architectures across LAN, WAN, and DMZ environments.
- Configure, harden, and maintain network devices including routers, switches, firewalls, and related infrastructure in line with security best practices.
- Manage firewall rules and access policies across enterprise firewall platforms such as Cisco ASA, Palo Alto, Fortinet, or Check Point.
- Configure and maintain secure VPN connectivity including IPSec, SSL, site-to-site, and client-based remote access solutions.
- Implement, manage, and optimize IDS/IPS technologies to detect, prevent, and respond to network-based threats.
- Set up and manage network access control solutions to ensure that only authorized devices and users connect to the network.
- Monitor network traffic using tools such as NetFlow, Wireshark, and other monitoring or packet analysis solutions to identify anomalies, suspicious activity, and performance issues.
- Investigate and respond to network security threats, incidents, and operational issues in real time.
- Work closely with SOC, infrastructure, and IT teams during incident response, forensic investigations, and remediation activities.
- Implement network segmentation, VLANs, and access control lists to enforce least privilege and reduce the risk of lateral movement.
- Support identity-based access control integration using technologies such as RADIUS and TACACS+.
- Maintain secure network configurations and ensure network device firmware is updated in line with security standards and operational requirements.
- Maintain accurate documentation of network topology, firewall rules, VPN configurations, and change management records.
- Conduct network security assessments and support compliance initiatives related to standards such as PCI-DSS, ISO 27001, and NIST.
- Contribute to continuous improvement of network resilience, performance, and security posture.
Educational Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related field.
Experience Requirements
- Minimum 5 years of hands-on experience in network engineering and network security.
- Proven experience in securing enterprise network environments and managing perimeter security technologies.
- Experience with routing, switching, firewall administration, VPN technologies, and network segmentation.
- Experience in network traffic analysis, troubleshooting, and threat detection.
- Experience supporting compliance-driven or security-sensitive environments is preferred.
Technical Skills
- Strong knowledge of network protocols including TCP/IP, DNS, DHCP, BGP, OSPF, VLANs, and NAT.
- Proficiency with enterprise firewall and network security platforms such as Cisco, Fortinet, Palo Alto, and Check Point.
- Strong hands-on experience with VPN technologies and secure remote access solutions.
- Experience with IDS/IPS, NAC, packet capture, traffic analysis, and network monitoring tools.
- Good understanding of routing, switching, network design, and performance optimization.
- Familiarity with zero-trust network architecture principles and secure configuration baselines.
- Ability to manage network segmentation, ACLs, VLANs, and identity-integrated access controls.
- Knowledge of compliance frameworks and network security controls aligned with PCI-DSS, ISO 27001, and NIST.
Preferred Certifications
- CCNP
- Cisco Security certifications
- Fortinet NSE
- Palo Alto PCNSA or PCNSE
- CompTIA Security+
- Other equivalent network security certifications