Job Summary
We are seeking an experienced Network Security Engineer to support and maintain enterprise network and cybersecurity infrastructure.
The successful candidate will be responsible for day-to-day operational support across network security environments, including firewalls, IPS/IDS, proxy, VPN, remote access, LAN/WAN infrastructure, load balancers, DNS/DHCP and vulnerability remediation.
The role requires strong troubleshooting and incident-management capabilities, together with hands-on experience supporting enterprise network and security technologies in a production environment.
The engineer will also work closely with Level 1 teams, technology teams and business stakeholders to resolve security incidents, implement changes, maintain infrastructure security and support network security projects.
Key Responsibilities
- Provide Level 2 production support for network and security infrastructure.
- Handle security-related incidents, service requests and change requests.
- Troubleshoot and resolve network and security issues within agreed service levels.
- Support firewall flow management, firewall policy changes and security rule administration.
- Manage and support VPN, remote access and IP-related services.
- Support proxy infrastructure and related connectivity issues.
- Monitor and maintain the performance and effectiveness of network security infrastructure.
- Support vulnerability remediation and security hardening activities.
- Perform network security infrastructure upgrades and technology refresh activities.
- Support the implementation of network security projects and infrastructure changes.
- Maintain accurate documentation, SOPs, operational procedures and knowledge articles.
- Maintain network security IT assets and CMDB information.
- Support routers, switches, firewalls, LAN, WAN and VPN infrastructure.
- Perform installation, configuration and maintenance of firewalls, VPN solutions, routers and IDS/IPS technologies.
- Provide technical guidance and support to Level 1 security/network teams.
- Investigate and respond to security incidents, including malware, phishing and potential data-security incidents.
- Support security infrastructure monitoring, troubleshooting and continuous improvement.
- Manage and maintain DNS and DHCP services.
- Work with relevant technology teams to identify root causes and implement permanent solutions.
- Ensure changes and operational activities follow established security, compliance and change-management processes.
Network & Security Technologies
Candidates should have hands-on experience with one or more of the following enterprise technologies:
Cisco
- Cisco ACI
- Cisco Nexus
- Cisco Catalyst
- Cisco DNA Center (DNAC)
- Cisco ISE
- Cisco IOS
- Cisco NX-OS
Arista
- Arista switches
- Arista EOS
Fortinet
- FortiGate Firewall
- Fortinet IPS
F5
- F5 LTM
- F5 ASM
- F5 APM
- F5 TMOS
Infoblox
Skyhigh
- Proxy / Secure Web Gateway technologies
Ivanti
Check Point
- Check Point Firewall
- Check Point Management / MDS
Trend Micro
- IPS / IDS and security solutions
Tools & Automation
Experience with the following will be advantageous:
- Python
- Bash
- Ansible
- Wireshark
- TShark
- NetFlow
Required Skills & Experience
- Minimum 3 years of experience in Cybersecurity / Network Security support, or approximately 6 years of overall IT systems/network infrastructure experience with relevant financial-services experience.
- Strong understanding of LAN, WAN, MAN and VPN network environments.
- Strong understanding of network security concepts.
- Hands-on experience supporting enterprise firewalls, VPN, proxy, IPS/IDS and network infrastructure.
- Good understanding of network security concepts including encryption, certificates and authentication technologies such as Kerberos.
- Experience troubleshooting complex network and security issues in a production environment.
- Experience with incident, request and change-management processes.
- Experience with vulnerability remediation and infrastructure hardening.
- Good understanding of network topology and enterprise connectivity.
- Exposure to emerging network and cybersecurity technologies.
- Strong analytical and logical troubleshooting skills.
- Excellent communication and interpersonal skills.
- Customer-service oriented with the ability to work effectively as part of a team.
- Ability to work under pressure and manage multiple incidents or priorities.
- Willingness to work rotational shifts and participate in on-call support.
Financial Services Experience
Experience working in a banking, financial-services or other regulated environment will be highly advantageous.
Candidates should understand the importance of security controls, operational procedures, compliance requirements, documentation and controlled change management within a regulated technology environment.
Compliance Responsibilities
- Comply with applicable legal, regulatory and internal compliance requirements.
- Follow organizational security, risk and compliance policies and procedures.
- Maintain the required knowledge and competency to perform the role effectively.
- Complete mandatory training and maintain relevant technical and compliance competencies.
- Follow established information-security and operational-risk management procedures.
Working Environment
This is a 24x7 operational environment requiring rotational shift coverage.
The expected shift patterns are:
- 7:00 AM – 4:00 PM
- 2:00 PM – 11:00 PM
- 5:00 PM – 2:00 AM
The successful candidate will also participate in rotational weekday and weekend on-call support, with weekend support expected approximately once or twice per month.
Key Competencies
- Network Security
- Cybersecurity Operations
- L2 Production Support
- Firewall Administration
- VPN & Remote Access
- Proxy Management
- IPS / IDS
- LAN / WAN / MAN
- DNS / DHCP
- Vulnerability Remediation
- Security Hardening
- Incident Management
- Change Management
- Network Troubleshooting
- Infrastructure Monitoring
- Security Operations
- Technical Documentation
- Stakeholder Management