OPERATIONAL SECURITY ENGINEER – NETWORK FILTERING
BE Bucharest, Romania
Marketing Services · 51-200 employees
About the role
The Operational Security Engineer is responsible for implementing and maintaining firewall rules, proxy configurations, and WAF policies across the network infrastructure. They also manage security incidents, ensure operational readiness, and collaborate with technical teams to optimize security solutions.
What they look for
Requirements
Candidates should have strong experience with network security tools like Check Point, Fortinet, and Palo Alto, along with proficiency in incident management and Agile methodologies. Professional certifications such as CCNP, CCIE, or F5 are considered an advantage for this role.
Full description
Profile: Network Filtering
As a member of the Network Filtering team, the main responsibilities of the Operational Security Engineer – Filtering include:
- Implementing firewall rules and traffic flows across the various filtering infrastructure devices, in accordance with approved requests submitted through Tufin or DSO tools;
- Ensuring the proper deployment of Group and Local Security Policies on the Firewall, Proxy, and WAF devices under our responsibility;
- Acting as a partner to projects and ITRM teams in the implementation of traffic flows, including application flows;
- Performing the technical investigations required to resolve incidents or encountered blockers.
Scope of Application
All Network Filtering security solutions, including Firewalls, Routers, Proxies, WAFs, etc.
Responsibilities
- Ensure the implementation of filtering rules across all filtering devices (Firewall, Router, Proxy, WAF, etc.), in compliance with the security policies currently in place and described in the Firewall Request Management procedure;
- Maintain coordination with:• Security functions within business entities;
- Production Security teams;
- Technical Architecture teams, in order to evolve risk analysis matrices according to business needs, with a strong focus on automation;
- Act as the main point of contact and technical reference for suppliers regarding their filtering solutions and products;
- Communicate and implement security best practices, proactively propose improvements, and contribute to continuous improvement initiatives;
- Operationally implement the security policies applicable to Filtering tools.
Maintaining Operational Readiness of Filtering Security Solutions
- Manage incidents within the assigned scope, including continuous monitoring of the relevant solutions;
- Configure and maintain the tools within the assigned perimeter;
- Ensure the long-term sustainability of technical solutions and manage technology obsolescence;
- Ensure the proper functioning, maintainability, and scalability of applications, including access, logging, and monitoring;
- Analyze and resolve functional or technical issues reported by users of operational security solutions;
- Manage version upgrades and changes within the application perimeter, while ensuring consistency across the application portfolio;
- Ensure that the objectives defined in the action plan for the assigned scope are achieved, including availability rates and incident resolution times;
- Formalize and maintain an adequate procedural framework to govern the execution of operational processes.
Key Interactions
- Within ProdSec (BGL and Group) – primarily with the Filtering teams;
- Within BGL – Technical teams, suppliers, solution integrators, Global IT Production;
- IT Risk Management (ITRM);
- Agile Production Support;
- Technical Architects;
- Tribes;
- Telecom & Workspace.
Required Skills
Technical Skills
Incident Management
- Ability to register, track, and manage the full incident lifecycle in ServiceNow;
- Ability to perform troubleshooting in order to resolve incidents;
- Good knowledge of JIRA.
Frameworks / Certifications
- NIST / CIS;
- ISO 27001;
- Cisco certifications (CCNP, CCIE) and F5 certifications are considered an advantage.
Tools / Technologies
- Firewalls: Check Point, Fortinet, Palo Alto;
- Change management across network security layers and environments (600+ clusters and standalone devices);
- Micro-segmentation, such as Illumio solutions (approximately 30,000 VEN agents on VMs);
- Resolution of, or contribution to the resolution of, production and security incidents;
- Consulting and technical assistance for projects, audits, etc.;
- Contribution to projects aimed at improving network security;
- Proxy: McAfee Web Gateway;
- F5 Advanced Web Application Firewall (AWAF);
- F5 BIG-IP, including:• Application Security Manager (ASM);
- Access Policy Manager (APM);
- Wireshark.
Environments
- Linux;
- Windows;
- IBM Cloud.
Methodologies
- Strong command of Agile methodologies, including Scrum and Kanban;
- Adoption of a DevOps-oriented approach.
Behavioral Skills
- Ability to collaborate and work effectively as part of a team;
- Strong organizational skills;
- Rigor and attention to detail;
- Proactivity;
- Strong oral and written communication skills;
- Ability to synthesize information and simplify complex topics;
- Adaptability;
- Curiosity and willingness to learn.
Language Skills
- Fluent French;
- Good written and spoken English.
Similar roles
-
Security Engineer (French Speaker) | BPCE-SI
Natixis in Portugal Portugal
-
Cybersecurity Operations Engineer - Singpass
Assurity Trusted Solutions Singapore, Singapore
-
Lead Cybersecurity Analyst
TerraPay Bengaluru, Karnataka, India
-
Senior Cloud Security Engineer | Remote
Tasq Staffing Solutions, Inc. Philippines
-
Cybersecurity Senior Full-Stack Engineer (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany
-
Bitcoin Security Engineer
MicroStrategy Tysons, Virginia, United States · $104K–$187K/yr