Job Summary
Job Summary : Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations. 2. Role Purpose & Business Outcomes • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues. • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure. • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls. • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence. • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews. 3. Key Roles & Responsibilities • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues. • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams. • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability. • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support. • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues. • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection. • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options. • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Key Responsibilities
Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations. 2. Role Purpose & Business Outcomes • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues. • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure. • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls. • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence. • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews. 3. Key Roles & Responsibilities • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues. • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams. • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability. • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support. • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues. • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection. • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options. • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Skill Requirements
Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations. 2. Role Purpose & Business Outcomes • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues. • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure. • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls. • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence. • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews. 3. Key Roles & Responsibilities • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues. • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams. • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability. • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support. • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues. • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection. • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options. • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.
Other Requirements
Detailed Job Description Network Security Engineer - Firewall, VPN Management & Monitoring (L3) 24x7 Deep SME Support - Security Architecture - High-Risk Changes - Major Incident & RCA Ownership Role Level L3 / Network Security SME Experience 8-12+ years preferred Support Window 24x7 escalation / on-call Function Network Security Primary Technologies Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA Primary Processes Major Incident, Problem/RCA, Complex Change, Risk, Compliance Core Tools Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, Wireshark Delivery Context Burlington 24x7 managed network security operations Certifications PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL preferred Document Type Reusable detailed L3 staffing profile 1. Role Summary The Network Security Engineer - Firewall, VPN Management & Monitoring (L3) is a deep subject matter expert responsible for advanced operations, architecture validation, optimization, major incident resolution, RCA leadership, complex change ownership, governance and mentoring for enterprise firewall and VPN environments. This role provides 24x7 escalation support for Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, segmentation, security inspection, SIEM/SOAR integration and log/monitoring capabilities. The engineer owns complex issues that L1/L2 teams cannot resolve and ensures secure, resilient, compliant and well-documented network security operations. 2. Role Purpose & Business Outcomes • Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA and security platform issues. • Lead major incident restoration and RCA for business-impacting network security outages or security incidents affecting managed network infrastructure. • Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation and preventive controls. • Own high-risk firewall/VPN changes and ensure change plans include impact analysis, peer review, rollback, testing and evidence. • Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training and escalation quality reviews. 3. Key Roles & Responsibilities • Advanced Firewall/VPN Escalation: Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access and application connectivity issues. • Major Incident Leadership: Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options and coordinate with SOC, network, application, identity, field and OEM teams. • Firewall Architecture & Optimization: Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns and platform scalability. • Complex Change Ownership: Plan, peer-review and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes and platform redesign support. • VPN & Remote Access SME: Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing and tunnel performance issues. • Threat Prevention & Inspection: Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection and content inspection. • Deep Log & Packet Analysis: Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables and packet captures to determine root cause and remediation options. • Governance, Standards & Compliance: Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention and change documentation expectations.