Job Title: Lead Network Security Engineer
Employment Type: Full-Time
Location: Remote
Job Summary:
We are looking for an experienced Senior Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure. The ideal candidate will have strong hands-on experience with firewalls, VPNs, network security technologies, cloud security, monitoring, and troubleshooting.
Key Responsibilities:
Design, implement, and maintain secure enterprise network infrastructure.
Configure and manage firewalls such as Palo Alto, Fortinet, Cisco ASA/Firepower.
Manage VPN, IPS/IDS, NAC, SSL/IPSec, and network access controls.
Monitor network traffic and investigate security incidents.
Perform network security troubleshooting and root-cause analysis.
Implement security policies, standards, and access controls.
Work with routing and switching technologies including TCP/IP, BGP, OSPF, VLANs, DNS, DHCP, and LAN/WAN.
Support cloud networking and security environments such as AWS, Azure, or Google Cloud Platform.
Configure and manage security tools such as SIEM, IDS/IPS, vulnerability scanners, and network monitoring solutions.
Participate in security audits, vulnerability assessments, and remediation activities.
Develop and maintain network diagrams, documentation, and security procedures.
Collaborate with infrastructure, cloud, SOC, and application teams.
Provide technical guidance and mentoring to junior engineers.
Required Skills:
14+ years of experience in network engineering/security.
Strong knowledge of TCP/IP, routing, switching, LAN/WAN, DNS, DHCP, VPN.
Hands-on experience with Palo Alto, Fortinet, Cisco ASA/Firepower, or similar firewalls.
Experience with IPS/IDS, NAC, SIEM, SSL/IPSec VPNs.
Knowledge of AWS, Azure, or Google Cloud Platform networking/security.
Strong troubleshooting and incident-response skills.
Knowledge of network security frameworks and best practices.
Experience with network automation/scripting using Python, Ansible, or similar tools is a plus.
Strong hands-on experience configuring and managing Fortinet FortiGate firewalls in enterprise environments.
Configure and maintain FortiGate firewall policies, NAT, security profiles, routing, and access control rules.
Manage FortiManager and FortiAnalyzer for centralized firewall administration, monitoring, logging, and reporting.
Implement and troubleshoot IPSec Site-to-Site VPN, SSL VPN, and Remote Access VPN solutions.
Configure VPN tunnels, encryption parameters, authentication, IKE Phase 1/Phase 2, and VPN failover.
Troubleshoot VPN connectivity, tunnel instability, routing issues, and authentication problems.
Design and implement high-availability firewall clusters (HA) and firewall redundancy.
Perform firewall rule reviews, cleanup, optimization, and security policy audits.
Configure IPS/IDS, Application Control, Web Filtering, Antivirus, SSL Inspection, and DNS Filtering on FortiGate.
Monitor firewall and VPN traffic using logs and security analytics to identify suspicious activity.
Manage firewall upgrades, security patches, configuration backups, and change management.
Experience with Cisco ASA/Firepower, Palo Alto, Check Point, or other enterprise firewall technologies is a plus.
Preferred Certifications:
CCNP Security / CCIE Security
Palo Alto PCNSE
Fortinet NSE/FCP
CompTIA Security+
CISSP
Cloud security certifications are a plus.