Dear Job seekers,
We have an immediate role in NYC, NY. Its an onsite role for Network Security Engineer. Interested candidates please share you updated to
Network Security Engineer
Location: New York, NY – Full Onsite (Midtown and/or Downtown office)
Interview: Onsite Interview Required
Schedule: Monday–Friday, 9:00 AM–5:00 PM (35 hours/week, 1-hour unpaid break)
Contract: 3–6 months initially, with potential for long-term extensions
Overtime: Possible overtime, weekend/holiday work, and on-call support. Overtime/weekend/holiday hours paid at 1.5x.
Job Summary
We are seeking an experienced Network Security Engineer to design, implement, configure, and maintain secure network infrastructure across a complex enterprise environment.
The ideal candidate will have strong hands-on experience with Palo Alto and FortiGate firewalls, Cisco ACI, Zscaler, Carbon Black, network routing, VPN, vulnerability management, and network security operations. This role requires a combination of network security engineering, troubleshooting, infrastructure support, and hands-on data center work.
Key Responsibilities
Design, implement, configure, and manage enterprise network security solutions.
Develop and enforce network security strategies aligned with industry standards such as NIST and ISO 27001.
Provide hands-on administration and architecture support for Palo Alto and FortiGate firewalls.
Configure and manage firewall policies, NAT, VPN, security rules, upgrades, logging, and troubleshooting.
Support Cisco ACI and enterprise network infrastructure.
Assist with network infrastructure upgrades, including switch replacements and network security enhancements.
Configure and troubleshoot VLANs, OSPF, BGP, TCP/IP, DNS, and DHCP.
Manage and monitor security technologies including Zscaler, Microsoft Defender, and Carbon Black.
Perform vulnerability assessments and support remediation activities across network and cloud environments.
Monitor network traffic, security events, and logs using SIEM and network monitoring tools such as Splunk and SolarWinds.
Investigate security incidents and participate in incident response, threat detection, and recovery activities.
Implement and maintain secure remote access solutions, including IPsec and SSL VPN.
Apply network and system hardening practices across Windows, Linux, UNIX, and other enterprise platforms.
Support security controls involving PKI, SSL/TLS, encryption, and FIPS standards.
Work with cloud environments including AWS, Azure, and Google Cloud Platform to support secure infrastructure deployments.
Support IAM, RBAC, Active Directory, LDAP, SSO, and GPO-related security requirements.
Use scripting and automation tools such as Python, Bash, Ansible, or Terraform to improve operational efficiency.
Analyze network traffic using tools such as Wireshark and troubleshoot complex connectivity and security issues.
Participate in disaster recovery, business continuity, and security recovery activities.
Support compliance requirements including PCI DSS, FISMA, FedRAMP, and ITIL-based processes.
Perform hands-on physical work and troubleshooting in data center environments when required.
Required Qualifications
5+ years of experience in Network Security Engineering or a closely related field.
5+ years of hands-on experience with Palo Alto Firewalls.
5+ years of hands-on experience with FortiGate/Fortinet.
3+ years of experience with Zscaler.
3+ years of experience with Carbon Black.
Strong understanding of enterprise network security architecture and frameworks.
Strong hands-on experience with firewall configuration, security policies, VPN, logging, upgrades, and troubleshooting.
Experience with Cisco ACI and enterprise switching/network infrastructure.
Strong knowledge of OSPF, BGP, VLANs, TCP/IP, DNS, and DHCP.
Experience with vulnerability management and security assessment tools.
Experience with SIEM and network monitoring platforms such as Splunk, SolarWinds, or PRTG.
Strong understanding of network security concepts, incident response, and threat detection.
Experience with Wireshark or similar network traffic analysis tools.
Working knowledge of Python and/or Bash scripting.
Familiarity with AWS, Azure, or Google Cloud Platform security architecture.
Experience with IAM, RBAC, Active Directory, LDAP, SSO, and GPO.
Strong troubleshooting, analytical, and communication skills.
Willingness to work onsite and perform occasional data center physical activities.
Preferred Qualifications
Experience migrating from Cisco ASA to FortiGate.
Experience with Microsoft Defender, Zscaler, and Carbon Black.
Experience with Ansible and/or Terraform.
Knowledge of PCI DSS, FISMA, FedRAMP, NIST, ISO 27001, and ITIL.
Experience with disaster recovery and business continuity planning.
Security certifications such as CISSP, CCNP Security, PCNSE, Fortinet, or equivalent are a plus.
Work Environment
This is a fully onsite position in New York City, with work performed at the client's Midtown and/or Downtown office locations. The position may require occasional overtime, weekend/holiday support, on-call coverage, and hands-on work at a data center.