Network Security Lead Engineer
Theomnihire Alandur, Tamil Nadu, India
Staffing and Recruiting
About the role
The Network Security Lead Engineer is responsible for supporting, upgrading, and migrating network security components including firewalls, VPNs, and web proxies across global regions. They will analyze business requirements to provide secure solutions and identify opportunities to strengthen the security posture of datacenter and cloud environments.
What they look for
Requirements
Candidates must have extensive hands-on experience with Fortinet, Palo Alto, and cloud-native firewalls, as well as proficiency in SDWAN and Zscaler proxy environments. A strong background in IP networking, troubleshooting complex traffic flows, and creating network architecture diagrams is required.
Full description
Requirements
Responsibilities:
- Overall, the job requires supporting the firewalls and other network security components in the Olam environment located across various regions and countries.
- Supporting the setup, upgrade and migration of firewalls, VPN, web proxies etc.
- Analyze the new requirements based on input from various IT teams and provide solutions to meet the business requirements while maintaining the security posture of the enterprise.
- Identify opportunities for strengthening network security posture in the datacenter, regions, and cloud.
Skills and Qualifications:
- Level 2-3 support of firewall technologies includes Fortinet firewalls, Palo Alto Firewalls, Azure native firewalls, AWS native firewalls & other next- gen firewalls.
- Hands-on experience on centralized management of firewalls through Panorama, Forti-Manager etc.,
- Hands-on experience of configuring firewalls into SDWAN networks
- Working knowledge on handling security related issues on cloud environments primarily on Azure, AWS, etc.,
- Must have experience on handling Zscaler web proxy environment.
- Must have experience on handling Cloud networking environment either on Azure, AWS handling on NSG, Application Gateway, Load Balancer, Peering etc.
- Must have experience in handling and troubleshooting Client to site VPN environment.
- Must have experience analyzing and implementing complex firewall rules on security devices (FortiGate, Palo Alto, AWS & Azure native Firewalls).
- Demonstrated ability to analyze network traffic flows to reverse-engineer the required firewall ports and rules to allow secure access of applications
- Strong technical ability to troubleshoot firewall problems in a large enterprise involving complex network application flows between multiple hosts spanning multiple firewalls/security zones and different geographic locations
- A comprehensive knowledge of IP networking and network security including Intrusion Detection, DMZ, encryption, IPsec, SSL VPNs, MPLS/VPN, Site to Site VPN tunnels, SSL/VPN, proxy services etc.
- Must have strong analytical and problem-solving skills and a solid understanding of how to troubleshoot connectivity and performance issues that involve firewalls, SDWAN, MPLS network connectivity and applications
- Must have experience on handling NAC (Network Access/Admission Control).
- Other security components are value added like DNS security, MFA etc.,
- Good hands-on experience in creating network diagrams, Network architecture diagram, Schematic diagrams in using MS Visio.
- Able to support on night shifts based on client requirements.