Senior Network Security Engineer
Key Responsibilities
- Translate high-level business strategic objectives and goals into Enterprise IT requirements and conceptual designs.
- Develop and support comprehensive solutions that meet requirements and align with HPE's global network security and strategy using Juniper SRX platforms.
- Develop and maintain a multi-year strategic network and security architecture roadmap, incorporating Zero Trust and firewall-based segmentation models.
- Lead end-to-end network and security architecture across global platforms ensuring secure, high-performing, fault-tolerant, and resilient environments.
Segmentation & Zero Trust Responsibilities (Juniper SRX Focus)
- Architect and implement network segmentation strategies using Juniper SRX firewalls across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
- Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement using firewall controls.
- Collaborate with application owners to discover, validate, and map application dependencies to enable policy-driven segmentation via firewall rules and security zones.
- Define and enforce granular security policies using zone-based segmentation, VRFs, and SRX policy constructs across hybrid environments.
- Integrate segmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
- Lead adoption and standardization of Juniper SRX as the primary segmentation enforcement platform across enterprise environments.
- Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
________________________________________
Core Network Security Responsibilities
- Participate in network security design reviews and ensure all implementations meet enterprise security standards.
- Analyze business requirements to design and implement security across data centers, campus networks, and hybrid environments.
- Provide ongoing risk metrics, control effectiveness tracking, and security posture reporting.
- Conduct and support internal and external security audits and compliance assessments.
- Maintain awareness of emerging threats and update policies accordingly.
- Develop and manage policies, processes, and procedures ensuring reliability, availability, and security of network systems.
- Manage and optimize Security Information and Event Management (SIEM) systems.
- Collaborate with Cyber Security, infrastructure, and application teams toward compliance and operational excellence.
________________________________________
Technical Qualifications
- Strong hands-on experience in designing and implementing network segmentation using enterprise firewalls (Juniper SRX preferred) in complex environments.
- Proven capability to build application-aware firewall policies based on traffic flow analysis.
- Experience with policy design, enforcement, monitoring, and optimization in firewall-based segmentation environments.
- Strong understanding of east-west traffic inspection, security zoning, and firewall-enforced segmentation.
- Familiarity with Zero Trust Network Access (ZTNA) and identity-driven access models.
________________________________________
Network Security & Infrastructure
- Strong experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
- Expertise in firewall architecture and design with strong hands-on experience in Juniper SRX (primary), along with Fortinet and Palo Alto.
- Deep expertise in:
- Security zones, policies, NAT, routing
- Application control and threat prevention
- High-availability clustering and scale design
- Experience securing public and private cloud (AWS, Azure, Google Cloud Platform) environments.
- Design and implementation of Web Application and API Protection (WAAP) solutions.
- Strong experience in proxy (forward/reverse), load balancing, and application security integration.
- Experience with SDN and SD-WAN architectures, including segmentation use cases.
________________________________________
Networking & Protocol Expertise
- Strong knowledge of:
- Routing protocols: BGP, OSPF, RIP, MPLS
- Network services: DNS, DHCP, NTP
- IPv4/IPv6 architecture and traffic management
- Experience in QoS, NetFlow, ACLs, NAT, multicast, and wireless technologies (802.11 variants).
- Experience with F5 GTM/LTM, VPN technologies, and Internet proxy solutions.
________________________________________
Data Center & Infrastructure
- Experience managing enterprise data center environments with technologies including:
- Aruba, Arista, Juniper switching
- Firewalls, WAN optimization, IDS/IPS, DLP
- Strong understanding of structured cabling and network facilities.
________________________________________
Operations & Lifecycle Management
- Plan, implement, and document infrastructure changes, including upgrades and migrations.
- Work within ITIL frameworks for incident, change, and problem management.
________________________________________
Education & Certifications
- Bachelor's Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
- 10+ years of experience in global network security environments.
- Preferred certifications:
- CCNP / CCIE
- JNCIS/JNCIP/JNCIE (Juniper SRX focus preferred)
- Security certifications (CISSP, CISM, or equivalent) are a plus