About the Role
We are looking for a Network Security Engineer to lead the design, deployment, and maintenance of network security solutions for both internal infrastructure and client environments.
This role bridges traditional Network Engineering with Cybersecurity Operations, ensuring secure, resilient, and well-monitored network infrastructures. You will work closely with our Blue Team (SOC, DFIR, and CTI) while serving as the technical lead for network security implementation projects.
Key Responsibilities
Design, deploy, and configure Network Security Perimeter solutions, including Firewalls, WAF, VPN, IPS/IDS, for both internal and client environments.
Implement and manage security platforms such as FortiGate, Sangfor NGAF, AWS WAF/Array WAF, and future deployments including Palo Alto Networks.
Perform preventive and corrective maintenance on network and security infrastructure, including firmware upgrades, patch management, capacity monitoring, and incident troubleshooting.
Implement client-facing security solutions such as Identity & Access Management (Keycloak, LDAP/Active Directory, SSO), Certificate Management, and Endpoint Protection (e.g., CrowdStrike) according to project requirements.
Collaborate closely with the Blue Team (SOC, DFIR, and CTI) to ensure network configurations provide optimal visibility for SIEM (Wazuh) and eliminate monitoring blindspots.
Produce and maintain technical documentation, including network diagrams, configuration baselines, deployment guides, and maintenance SOPs.
Serve as the Technical Lead for network security implementation projects, independently managing technical execution from deployment through project handover.
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Minimum 5 years of experience in Network Engineering, including at least 2–3 years specializing in Network Security with hands-on experience in firewall and WAF implementation.
Strong hands-on experience with multiple enterprise security platforms, such as Fortinet, Sangfor, Palo Alto Networks, Check Point, Cloudflare, or AWS WAF.
Solid understanding of network security architecture, including TCP/IP, routing & switching, VLAN, NAT, VPN (Site-to-Site & Remote Access), IPS/IDS, network segmentation, and High Availability (HA).
Experience implementing and managing Identity & Access Management (IAM) solutions (Keycloak, LDAP, Active Directory, SSO) and Endpoint Security/EDR solutions is highly preferred.
Familiarity with SIEM integration, log forwarding, and security visibility concepts, with the ability to work closely with SOC teams.
Experience leading end-to-end deployment projects, including solution design, implementation, migration, troubleshooting, and technical documentation.
Strong client-facing communication skills with the ability to present technical solutions and manage project deliverables independently.
Working knowledge of Linux operating systems and basic scripting/automation using Python, Bash, or Ansible.
Relevant industry certifications (e.g., Fortinet, Palo Alto, Check Point, AWS Security, or equivalent) are considered an advantage.