Lead Consultant - Network Security

Remote • Posted 1 day ago • Updated 2 hours ago
Full Time
Remote
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Network
  • Software Security
  • Architectural Design
  • Leadership
  • High-level Design
  • Documentation
  • Communication
  • Distribution
  • Failover
  • NAT
  • SSL
  • DLP
  • SaaS
  • IPsec
  • High Availability
  • Internal Control
  • Policy Administration
  • Unit Testing
  • Network Security
  • CheckPoint
  • Palo Alto
  • Firewall
  • Internet
  • MAGIC
  • WAF
  • Management
  • Virtual Private Network
  • Cloud Computing
  • Border Gateway Protocol
  • SD
  • WAN
  • MPLS
  • Routing
  • Encryption
  • Regulatory Compliance
  • TLS
  • Inspection
  • SIEM
  • Normalization
  • Terraform
  • Ansible
  • Continuous Integration
  • Continuous Delivery
  • Network Layer
  • Incident Management
  • Root Cause Analysis
  • Corrective And Preventive Action
  • English

Summary

We are looking for a Lead Consultant who will design, build, and manage secure, compliant network segmentation connecting regional environments to Global networks. This position utilizes a standardized security toolset, including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Cloudflare for DDoS protection, WAF, and application security. The role combines architectural design, hands-on engineering, automation, and L3/L4 operational leadership to provide policy-driven connectivity that meets strict regulatory and operational standards. Responsibilities Establish trust zones, routing boundaries, and inter-zone controls across regional and Global Networks, addressing north-south and east-west traffic, micro-segmentation for sensitive layers, and explicit cross-border allow-lists Create HLD/LLD documentation, threat models, and control mappings that align with internal standards and regional regulations to support secure communication between regional and Global customer sites Build and manage dual-vendor firewall perimeters with defined control distribution, HA/cluster architecture, predictable failover, NAT domain strategy, SSL/TLS inspection governance, and jurisdiction-tuned Threat Prevention/WildFire/URL filtering Configure ZIA to provide identity-aware egress controls, jurisdiction-sensitive SSL inspection bypasses, inline CASB/DLP, and governance for approved SaaS applications Deploy ZPA to enable per-application zero-trust access, including connector placement, posture verification, conditional access, and app segmentation to replace legacy VPN solutions where possible Architect and implement Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site to support hybrid cloud connectivity Roll out Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, integrating with on-premises perimeters for layered protection Design SD-WAN/MPLS/SASE pathways featuring policy-based routing, robust encryption, and jurisdiction-specific key custody and rotation practices Convert regulatory and internal control mandates into actionable technical controls covering logging, data residency, TLS inspection scope, and lawful intercept requirements Consolidate telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM following regional data handling policies, and develop detection rules for cross-border anomalies and policy drift Direct L3/L4 incident response efforts, coordinate containment measures, and oversee RCAs with documented corrective actions Oversee firewall, Zscaler, and Cloudflare policy management using Terraform/Ansible and vendor APIs, and establish CI/CD pipelines incorporating policy linting, unit testing, and path simulation Requirements 5+ years of experience in network security architecture and operations, specializing in cross-border or multi-region connectivity Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept Familiarity with SIEM platforms and telemetry normalization for cross-border security monitoring Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning English proficiency at B2 level or higher
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10330481
  • Position Id: c95721ff7259252cd1b0dde58b9e0a89
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or Santa Ana, California

•

Today

Full-time

USD 129,300.00 - 172,300.00 per year

Remote or Springfield, Virginia

•

Today

Full-time

USD 9,700.00 - 15,516.67 per month

Remote or Irving, Texas

•

Today

Full-time

USD 137,000.00 - 228,400.00 per year

Remote

•

Today

Full-time

Search all similar jobs