Tower Lead (Support & Operations)
India
Job Description
Tower Lead (Support & Operations)
Bengaluru, Karnataka

Job Summary

Primary Technologies: Cisco ISE, Zscaler, Illumio, and Palo Alto Networks Position Overview We are seeking an experienced Network Security L3 Lead to provide technical leadership and expert-level operational support across enterprise security platforms. The role will own complex troubleshooting, major incident resolution, security policy governance, platform lifecycle management, service improvement, and mentoring of L1/L2/L3 engineers. The successful candidate will bring strong hands-on expertise in Cisco Identity Services Engine (ISE), Zscaler, Illumio , and Palo Alto Networks firewalls within a global enterprise or managed services environment. Key Responsibilities Lead day-to-day network security operations across Cisco ISE, Zscaler, Illumio, and Palo Alto Networks platforms. Act as the highest technical escalation point for complex incidents, service requests, security events, and customer escalations. Lead major incident bridge calls, coordinate cross-functional troubleshooting, communicate business impact, and drive restoration within agreed service levels. Perform root cause analysis for recurring incidents and implement corrective and preventive actions. Own security changes from risk assessment and implementation planning through peer review, validation, rollback readiness, and post-change closure. Monitor platform health, capacity, availability, licensing, certificates, software lifecycle, vulnerabilities, and support status. Review security policies, access rules, segmentation controls, and exceptions to ensure least-privilege access and compliance with organizational standards. Define and maintain operational standards, runbooks, standard operating procedures, knowledge articles, architecture diagrams, and configuration baselines. Track SLA, KPI, backlog, ageing, change success, recurring incidents, and operational risk; develop measurable improvement plans. Mentor engineers, perform technical reviews, conduct knowledge-transfer sessions, and promote consistent troubleshooting and documentation practices. Coordinate with network, cloud, server, workplace, identity, application, compliance, vendor, and customer teams. Support audits, risk assessments, vulnerability remediation, disaster recovery exercises, platform upgrades, migrations, and security improvement initiatives. Identify opportunities for automation to reduce manual effort and configuration errors. Technical Expertise Cisco ISE Administer, support, and troubleshoot distributed and highly available Cisco ISE deployments, including PAN, PSN, and MnT personas. Design and manage policy sets, authentication and authorization rules, downloadable ACLs, device administration, and identity-based access controls. Provide expert support for RADIUS, TACACS+, 802.1X, MAB, EAP-TLS, PEAP, certificate-based authentication, profiling, posture, guest access, and BYOD workflows. Integrate Cisco ISE with Active Directory, LDAP, PKI, certificate authorities, MDM, network devices, firewalls, and security platforms. Troubleshoot authentication failures using live logs, endpoint attributes, packet captures, policy evaluation results, certificates, and network-device debugging. Plan and execute patches, upgrades, node replacement, backup and restore, certificate renewal, licensing, and disaster recovery activities. Apply segmentation concepts including Security Group Tags and TrustSec where applicable. Zscaler Administer and troubleshoot Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for users, locations, branches, and private applications. Design and optimize policies for secure web gateway, cloud firewall, URL filtering, SSL inspection, sandboxing, advanced threat protection, CASB, DLP, and zero trust access. Manage App Connectors, Client Connector, service edges, forwarding profiles, PAC files, GRE and IPsec tunnels, application segments, segment groups, and access policies. 

Key Responsibilities

Primary Technologies: Cisco ISE, Zscaler, Illumio, and Palo Alto Networks Position Overview We are seeking an experienced Network Security L3 Lead to provide technical leadership and expert-level operational support across enterprise security platforms. The role will own complex troubleshooting, major incident resolution, security policy governance, platform lifecycle management, service improvement, and mentoring of L1/L2/L3 engineers. The successful candidate will bring strong hands-on expertise in Cisco Identity Services Engine (ISE), Zscaler, Illumio , and Palo Alto Networks firewalls within a global enterprise or managed services environment. Key Responsibilities Lead day-to-day network security operations across Cisco ISE, Zscaler, Illumio, and Palo Alto Networks platforms. Act as the highest technical escalation point for complex incidents, service requests, security events, and customer escalations. Lead major incident bridge calls, coordinate cross-functional troubleshooting, communicate business impact, and drive restoration within agreed service levels. Perform root cause analysis for recurring incidents and implement corrective and preventive actions. Own security changes from risk assessment and implementation planning through peer review, validation, rollback readiness, and post-change closure. Monitor platform health, capacity, availability, licensing, certificates, software lifecycle, vulnerabilities, and support status. Review security policies, access rules, segmentation controls, and exceptions to ensure least-privilege access and compliance with organizational standards. Define and maintain operational standards, runbooks, standard operating procedures, knowledge articles, architecture diagrams, and configuration baselines. Track SLA, KPI, backlog, ageing, change success, recurring incidents, and operational risk; develop measurable improvement plans. Mentor engineers, perform technical reviews, conduct knowledge-transfer sessions, and promote consistent troubleshooting and documentation practices. Coordinate with network, cloud, server, workplace, identity, application, compliance, vendor, and customer teams. Support audits, risk assessments, vulnerability remediation, disaster recovery exercises, platform upgrades, migrations, and security improvement initiatives. Identify opportunities for automation to reduce manual effort and configuration errors. Technical Expertise Cisco ISE Administer, support, and troubleshoot distributed and highly available Cisco ISE deployments, including PAN, PSN, and MnT personas. Design and manage policy sets, authentication and authorization rules, downloadable ACLs, device administration, and identity-based access controls. Provide expert support for RADIUS, TACACS+, 802.1X, MAB, EAP-TLS, PEAP, certificate-based authentication, profiling, posture, guest access, and BYOD workflows. Integrate Cisco ISE with Active Directory, LDAP, PKI, certificate authorities, MDM, network devices, firewalls, and security platforms. Troubleshoot authentication failures using live logs, endpoint attributes, packet captures, policy evaluation results, certificates, and network-device debugging. Plan and execute patches, upgrades, node replacement, backup and restore, certificate renewal, licensing, and disaster recovery activities. Apply segmentation concepts including Security Group Tags and TrustSec where applicable. Zscaler Administer and troubleshoot Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for users, locations, branches, and private applications. Design and optimize policies for secure web gateway, cloud firewall, URL filtering, SSL inspection, sandboxing, advanced threat protection, CASB, DLP, and zero trust access. Manage App Connectors, Client Connector, service edges, forwarding profiles, PAC files, GRE and IPsec tunnels, application segments, segment groups, and access policies. 

Skill Requirements

Primary Technologies: Cisco ISE, Zscaler, Illumio, and Palo Alto Networks Position Overview We are seeking an experienced Network Security L3 Lead to provide technical leadership and expert-level operational support across enterprise security platforms. The role will own complex troubleshooting, major incident resolution, security policy governance, platform lifecycle management, service improvement, and mentoring of L1/L2/L3 engineers. The successful candidate will bring strong hands-on expertise in Cisco Identity Services Engine (ISE), Zscaler, Illumio , and Palo Alto Networks firewalls within a global enterprise or managed services environment. Key Responsibilities Lead day-to-day network security operations across Cisco ISE, Zscaler, Illumio, and Palo Alto Networks platforms. Act as the highest technical escalation point for complex incidents, service requests, security events, and customer escalations. Lead major incident bridge calls, coordinate cross-functional troubleshooting, communicate business impact, and drive restoration within agreed service levels. Perform root cause analysis for recurring incidents and implement corrective and preventive actions. Own security changes from risk assessment and implementation planning through peer review, validation, rollback readiness, and post-change closure. Monitor platform health, capacity, availability, licensing, certificates, software lifecycle, vulnerabilities, and support status. Review security policies, access rules, segmentation controls, and exceptions to ensure least-privilege access and compliance with organizational standards. Define and maintain operational standards, runbooks, standard operating procedures, knowledge articles, architecture diagrams, and configuration baselines. Track SLA, KPI, backlog, ageing, change success, recurring incidents, and operational risk; develop measurable improvement plans. Mentor engineers, perform technical reviews, conduct knowledge-transfer sessions, and promote consistent troubleshooting and documentation practices. Coordinate with network, cloud, server, workplace, identity, application, compliance, vendor, and customer teams. Support audits, risk assessments, vulnerability remediation, disaster recovery exercises, platform upgrades, migrations, and security improvement initiatives. Identify opportunities for automation to reduce manual effort and configuration errors. Technical Expertise Cisco ISE Administer, support, and troubleshoot distributed and highly available Cisco ISE deployments, including PAN, PSN, and MnT personas. Design and manage policy sets, authentication and authorization rules, downloadable ACLs, device administration, and identity-based access controls. Provide expert support for RADIUS, TACACS+, 802.1X, MAB, EAP-TLS, PEAP, certificate-based authentication, profiling, posture, guest access, and BYOD workflows. Integrate Cisco ISE with Active Directory, LDAP, PKI, certificate authorities, MDM, network devices, firewalls, and security platforms. Troubleshoot authentication failures using live logs, endpoint attributes, packet captures, policy evaluation results, certificates, and network-device debugging. Plan and execute patches, upgrades, node replacement, backup and restore, certificate renewal, licensing, and disaster recovery activities. Apply segmentation concepts including Security Group Tags and TrustSec where applicable. Zscaler Administer and troubleshoot Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for users, locations, branches, and private applications. Design and optimize policies for secure web gateway, cloud firewall, URL filtering, SSL inspection, sandboxing, advanced threat protection, CASB, DLP, and zero trust access. Manage App Connectors, Client Connector, service edges, forwarding profiles, PAC files, GRE and IPsec tunnels, application segments, segment groups, and access policies. 

Other Requirements

Primary Technologies: Cisco ISE, Zscaler, Illumio, and Palo Alto Networks Position Overview We are seeking an experienced Network Security L3 Lead to provide technical leadership and expert-level operational support across enterprise security platforms. The role will own complex troubleshooting, major incident resolution, security policy governance, platform lifecycle management, service improvement, and mentoring of L1/L2/L3 engineers. The successful candidate will bring strong hands-on expertise in Cisco Identity Services Engine (ISE), Zscaler, Illumio , and Palo Alto Networks firewalls within a global enterprise or managed services environment. Key Responsibilities Lead day-to-day network security operations across Cisco ISE, Zscaler, Illumio, and Palo Alto Networks platforms. Act as the highest technical escalation point for complex incidents, service requests, security events, and customer escalations. Lead major incident bridge calls, coordinate cross-functional troubleshooting, communicate business impact, and drive restoration within agreed service levels. Perform root cause analysis for recurring incidents and implement corrective and preventive actions. Own security changes from risk assessment and implementation planning through peer review, validation, rollback readiness, and post-change closure. Monitor platform health, capacity, availability, licensing, certificates, software lifecycle, vulnerabilities, and support status. Review security policies, access rules, segmentation controls, and exceptions to ensure least-privilege access and compliance with organizational standards. Define and maintain operational standards, runbooks, standard operating procedures, knowledge articles, architecture diagrams, and configuration baselines. Track SLA, KPI, backlog, ageing, change success, recurring incidents, and operational risk; develop measurable improvement plans. Mentor engineers, perform technical reviews, conduct knowledge-transfer sessions, and promote consistent troubleshooting and documentation practices. Coordinate with network, cloud, server, workplace, identity, application, compliance, vendor, and customer teams. Support audits, risk assessments, vulnerability remediation, disaster recovery exercises, platform upgrades, migrations, and security improvement initiatives. Identify opportunities for automation to reduce manual effort and configuration errors. Technical Expertise Cisco ISE Administer, support, and troubleshoot distributed and highly available Cisco ISE deployments, including PAN, PSN, and MnT personas. Design and manage policy sets, authentication and authorization rules, downloadable ACLs, device administration, and identity-based access controls. Provide expert support for RADIUS, TACACS+, 802.1X, MAB, EAP-TLS, PEAP, certificate-based authentication, profiling, posture, guest access, and BYOD workflows. Integrate Cisco ISE with Active Directory, LDAP, PKI, certificate authorities, MDM, network devices, firewalls, and security platforms. Troubleshoot authentication failures using live logs, endpoint attributes, packet captures, policy evaluation results, certificates, and network-device debugging. Plan and execute patches, upgrades, node replacement, backup and restore, certificate renewal, licensing, and disaster recovery activities. Apply segmentation concepts including Security Group Tags and TrustSec where applicable. Zscaler Administer and troubleshoot Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for users, locations, branches, and private applications. Design and optimize policies for secure web gateway, cloud firewall, URL filtering, SSL inspection, sandboxing, advanced threat protection, CASB, DLP, and zero trust access. Manage App Connectors, Client Connector, service edges, forwarding profiles, PAC files, GRE and IPsec tunnels, application segments, segment groups, and access policies. 

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.