Job DescriptionThe Systems Network Engineer III leads the design, standardization, and continuous improvement of network security infrastructure across ABS's global hybrid-cloud environment. This role bridges engineering execution with strategic architecture, developing network security best practices using industry frameworks, driving automation, and establishing governance processes that strengthen the organization's infrastructure posture. The Engineer III, Network Security provides technical leadership to the engineering team through documentation, standards development, and architectural oversight, while advancing Zero Trust initiatives including identity-based access controls, firewall policy lifecycle management, and infrastructure-as-code adoption.
What You Will Do:- Define and maintain the enterprise network security infrastructure roadmap, ensuring alignment with Zero Trust principles, NIST 800-171/CMMC compliance frameworks, and business objectives.
- Design secure, scalable, high-availability network architectures across on-premises, Azure, Oracle Cloud, and multi-cloud environments.
- Develop network security best practices using industry frameworks and translate security policy requirements into infrastructure designs that enforce them.
- Evaluate emerging technologies and provide architectural recommendations to IT leadership.
- Serve as the technical authority on firewall, segmentation, VPN, and remote access infrastructure decisions.
- Develop and maintain reference architectures, design patterns, and standards for network security infrastructure.
- Evaluate and integrate technologies that provide comprehensive user-to-resource mapping across on-premises, cloud, and remote access environments.
- Develop infrastructure standards for identity-based policy enforcement that reduce the attack surface and support Zero Trust maturity across the organization.
- Design and implement a firewall policy cleanup and ownership workflow, establishing clear rule ownership, periodic review cadences, and decommission processes.
- Lead firewall rulebase optimization efforts, identifying unused, shadowed, overly permissive, and redundant rules across security and NAT policies.
- Identify repeatable, manual engineering workflows and lead the effort to standardize and automate them, reducing human error and improving deployment consistency.
- Establish documentation standards and templates for the engineering team to follow, ensuring knowledge is captured and transferable.
- Provide architectural guidance and mentorship to network and firewall engineers, ensuring engineering execution aligns with architectural standards.
- Lead cross-functional collaboration with security operations, cloud engineering, identity/access management, and application teams.
- Partner with the security team to understand policy requirements and translate them into infrastructure designs and configurations.
- Serve as subject matter expert and escalation point for complex firewall, VPN, routing, and multi-cloud connectivity issues.
- Support security audits, compliance assessments, and incident response with architectural context and technical expertise.
What You Will Need:Education and Experience
- 8+ years of progressive experience in network security engineering, with at least 3 years in an senior engineer or technical lead capacity. Must include 5+ years of hands-on experience with Palo Alto NGFW and Panorama in a global enterprise environment with hybrid-cloud infrastructure.
- Typically requires a college degree or recognized equivalent, preferably in Computer Science, Computer Engineering, or related field, from an accredited university or comparable on-the-job experience. Technical certifications are a plus.
- Palo Alto PCNSA / PCNSE
- Cisco CCNP (Security or Enterprise)
- Cloud certifications (Azure, OCI, GCP)
- NIST / CMMC related certifications
- Cloudflare ASE/ACE, Zscaler ZDTA,ZDTE,ZDXA
Knowledge, Skills and Abilities
- Deep expertise in designing enterprise-grade network security infrastructure across hybrid-cloud environments (on-prem, Azure, OCI, GCP).
- Advanced knowledge of Palo Alto NGFW, Panorama (device groups, templates, template stacks, variables), App-ID, Threat Prevention, GlobalProtect, and Security Zone design.
- Proven experience redesigning and optimizing large-scale firewall rulebases (1000+ rules) with a focus on segmentation, least privilege, and policy lifecycle governance.
- Strong command of BGP, OSPF, EIGRP, VPC, HSRP, VLAN design, SD-WAN, and DMVPN architectures.
- Extensive experience with IPSec VPN (site-to-site and third-party), GlobalProtect, SSL VPNs, SAML/MFA integration, and failover design.
- Hands-on experience with Azure VNet, NSG, Azure Firewall, OCI VCN/DRG, and cloud interconnects (Megaport, ExpressRoute).
- Working knowledge of Zero Trust architecture principles, microsegmentation strategies, NIST 800-171, NIST 800-53, and CMMC frameworks.
- Demonstrated ability to produce clear, actionable technical documentation including runbooks, SOPs, design documents, and training materials.
- Ability to articulate architectural decisions to both technical and non-technical stakeholders; experience mentoring engineers and leading technical initiatives.
- Experience evaluating and implementing automation tools and frameworks for network infrastructure provisioning, configuration management, and policy deployment is a plus.
- F5 LTM/GTM, A10, and/or Azure Application Gateway experience is a plus.
- A10 WAF, Azure WAF, and OWASP Top-10 policy enforcement familiarity is a plus.
- Cloudflare/Zscaler experience is a plus.
- SolarWinds NPM, HPNA, or equivalent network monitoring/management platform experience is a plus.
- Familiarity with Python, Bash, or similar scripting for ad-hoc automation and tooling is a plus.
- Understanding of ITAR compliance requirements and their impact on infrastructure design.
- Working knowledge of the ABS Health, Safety, Quality and Environmental Management System.
Reporting Relationships:The incumbent reports directly to IMS Management, as appropriate. Direct reports may include outside contractors.
Notice:This position requires access to information that is subject to control by the Export Administration Regulations and/or the International Traffic in Arms Regulations. Any offer of employment shall be contingent upon the Company's verification that the candidate is a "U.S. Person" or upon the receipt of all necessary export licenses or authorizations that may be required by U.S. export control laws. "U.S. Persons" are defined as U.S. citizens, U.S. lawful permanent residents (i.e., "green card" holders), or any individual granted protected status under the Immigration and Nationality Act (8 U.S.C. a7 1324b(a)(3)), including asylees and refugees. In the event a candidate refuses or cannot otherwise provide the necessary information for the Company to determine whether such licenses may be required, or for the Company to obtain any required licenses, the Company shall maintain the exclusive right to discontinue the application process and/or withdraw any contingent offer that has been made.
About Our Benefits ABS Bureau proudly offers a variety of industry-leading benefits designed to enhance the life and well-being of our employees and their families. These benefits include, but are not limited to, medical insurance (PPO and HD), dental and vision insurance, Health Savings Account (HSA), Flexible Savings Account (FSA), life insurance, accidental death and dismemberment insurance, disability leave programs, parental leave program, paid holidays, and paid vacation time. The Company provides an Employee Assistance Plan (EAP) that offers support in personal wellness, including work-life services. ABS Bureau also offers a 401K plan with a generous company match, subject to plan requirements.
Notice ABS and Affiliated Companies (ABS) will not pay a fee to any third-party agency without a valid ABS Master Service Agreement (MSA) authorized and signed by Human Resources. Any resume, CV, application, or other forms of candidate submission provided to any employee of ABS without a valid MSA on file will be considered property of ABS, and no fee will be paid.
Other This job description is not intended, and should not be construed, to be an all-inclusive list of responsibilities, skills, efforts or working conditions associated with the job of the incumbent. It is intended to be an accurate reflection of the principal job elements essential for making a fair decision regarding the pay structure of the job. #ogjs