The Senior Engineer for Firewall and VPN designs and implements the network security controls that protect the firm's data centers, offices, and cloud environments. The role handles the complex changes and migrations that routine operations cannot absorb, troubleshoots connectivity and tunnel failures end to end, and improves the quality of the rule base over time. It is a hands-on engineering position with strong influence over how policy is written and enforced.
• Design, implement, and validate firewall policy, network address translation, and segmentation changes across on-premises and cloud enforcement points.
• Build and maintain remote access and site-to-site VPN services, including tunnel configuration, certificate and identity integration, and client posture checks.
• Perform platform upgrades, failover testing, and hardware replacements within approved change windows, with tested rollback procedures.
• Troubleshoot complex connectivity and performance problems using packet capture and log analysis, and drive them to root cause with the network and application owners.
• Automate rule analysis, recertification evidence, and configuration backup, and mentor junior engineers on policy design and change discipline.
Required Qualifications
• English B2+
• Five or more years in network or network security engineering, with at least three years administering enterprise firewalls.
• Hands-on expertise with at least one major firewall platform and its central management console, including policy, NAT, routing, and high availability configuration.
• Practical experience delivering IPsec and SSL VPN services, and a solid grasp of TCP/IP, routing protocols, DNS, and TLS.
• Ability to script or use platform APIs to automate configuration, reporting, and rule review tasks.
Preferred Qualifications
• Certification such as PCNSE, NSE 5 or above, CCNP Security, or an equivalent vendor credential.
• Experience with cloud-native firewalls, secure web gateways, or zero trust network access deployments.
Software Powered by ICIMS
www.icims.com