Perimeter Edge Security Engineer
Malomatia Doha, Qatar
IT Services and IT Consulting · 1,001-5,000 employees
About the role
The engineer will design, administer, and manage the lifecycle of the organization's network perimeter and cloud edge security estate. Responsibilities include policy governance, high-availability resilience, traffic protection, and vulnerability remediation across the security stack.
What they look for
Requirements
Candidates must have a bachelor's degree in Computer Science or a related field and at least 5 years of experience with enterprise NGFW platforms. Strong technical proficiency in multi-cloud NVA deployments, routing, VPN technologies, and incident response is required.
Full description
Own the design, administration, and lifecycle management of the organization's network perimeter and cloud edge security estate — spanning Palo Alto VM-Series, FortiGate HA Cluster (on-premises and multi-cloud NGFW/NVA) and Cloudflare (CDN, DDoS, edge WAF, DNS). Accountable for policy governance, high-availability resilience, VPN connectivity, edge traffic protection, and vulnerability remediation across the full perimeter-to-edge security stack.
Responsibilities
- Design and administer zone-based security architecture, inter-zone policies, and DMZ segmentation on Palo Alto and FortiGate platforms.
- Configure and maintain App-ID, User-ID, Content-ID, SSL/TLS decryption, NAT (DNAT/SNAT/U-turn), and UTM (IPS, AV, Web Filtering, App Control) policies.
- Build and operate Site-to-Site IPSec VPN (IKEv2) with BGP dynamic routing, route-based/policy-based VPNs, and SD-WAN traffic steering where applicable.
- Manage centralized policy platforms — Panorama / Strata Cloud Manager (Palo Alto) and FortiManager / FortiAnalyzer (Fortinet) — for policy push, log aggregation, and reporting.
- Design, deploy, and validate High Availability clusters (Active-Passive / Active-Active); execute and document quarterly failover testing and RCA.
- Lead NVA deployment, migration (e.g., Azure → OCI), firmware/patch lifecycle, hotfixes, and HA-aware patching with rollback planning.
- Integrate firewall/NVA inspection paths with Load Balancer tiers for L4/L7 traffic inspection.
- Administer Cloudflare CDN (cache rules, Workers/Pages), network- and application-layer DDoS protection, and edge WAF (managed rulesets, custom rules, rate limiting, bot management).
- Manage Cloudflare Load Balancing, Public DNS, and URL management; perform ongoing traffic analysis and optimization at the edge.
- Own vulnerability remediation, patching cadence, and upgrade planning for all firewall/NVA and edge security assets.
- Monitor NGFW/UTM threat logs and Cloudflare traffic/attack analytics; manage signature updates and lead incident response and triage for perimeter and edge security events.
Qualifications
Required Qualifications & Experience
- Bachelor's degree in Computer Science, Information Security, or related field.
- 5+ years' experience administering enterprise NGFW platforms (Palo Alto and/or Fortinet) in production environments.
- Hands-on experience with multi-cloud NVA deployments (Azure, GCP, OCI) and cloud edge/CDN security platforms (Cloudflare or equivalent).
- Certifications preferred: PCNSE (Palo Alto), NSE 4/NSE 7 (Fortinet), Cloudflare Certified Administrator.
- Strong understanding of routing (BGP), VPN technologies, DNS, DDoS mitigation, and network segmentation.
- Excellent incident response, documentation, and cross-team coordination skills.
Similar roles
-
Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. Hanscom AFB, Massachusetts, United States · $175K–$185K/yr
-
IT Auditor Cybersecurity and Tech Controls
coni+partner AG Zurich, Zurich, Switzerland
-
Senior Cybersecurity Presales Consultant
SNSIN Chennai, Tamil Nadu, India
-
Security Engineer
Zensar Hyderabad, Telangana, India
-
Cybersecurity Ops Analyst Senior
SAIC Oak Ridge, Tennessee, United States
-
Fire & Security Engineer
Securitas Wakefield, England, United Kingdom