Summary:
The Firewall & Security Engineer (L3) is responsible for the design, implementation, administration, optimization, and support of enterprise security infrastructure. The role serves as the highest level of technical escalation for firewall, VPN, network security, and security related incident management while ensuring availability, performance, compliance, and security best practices.
Key Responsibilities
- Provide L3 support for enterprise firewall and security environments.
- Design, implement, and manage firewall policies, NAT rules, VPNs, and security controls.
- Troubleshoot complex network security incidents and perform root cause analysis.
- Lead major incident resolution and provide expert level technical guidance.
- Implement and maintain site to site VPN, remote access VPN, and IPsec solutions.
- Perform firewall upgrades, migrations, patch management, and platform lifecycle activities.
- Review and optimize security policies to improve security posture and operational efficiency.
- Collaborate with Network, Cloud, SOC, and Application teams for security integration.
- Support audit, compliance, and regulatory requirements.
- Develop technical documentation, SOPs, HLDs, LLDs, and operational runbooks.
- Mentor L1/L2 engineers and provide technical leadership across projects.
Required Technical Skills
- Strong hands-on experience with enterprise firewalls;
ü Palo Alto Networks
ü Fortinet FortiGate
ü Cisco Firepower/ASA
ü Check Point
ü Routing & Switching
ü TCP/IP, BGP, OSPF, EIGRP
ü NAT, ACLs, VLANs
ü IPsec VPN, SSL VPN
ü IDS/IPS
ü URL Filtering
ü Application Control
ü Web Security
ü DDoS Protection
- Experience with Security Management Platforms:
ü Panorama
ü FortiManager
ü Cisco FMC
ü Check Point Smart Console
ü Knowledge of Cloud Security (Azure, AWS, Google Cloud Platform) is preferred.
ü Understanding of Zero Trust, SASE, SD WAN, and Network Segmentation.
Experience
- 8+ years of experience in Network Security and Firewall Administration.
- Proven experience supporting large scale enterprise environments.
- Experience handling critical P1/P2 incidents and security escalations.
- Exposure to security audits, risk assessments, and compliance frameworks.
Certifications (Preferred)
- PCNSE (Palo Alto)
- NSE 4/5/7 (Fortinet)
- CCNP Security
- CCIE Security
- CISSP
- CISM