EPAM Systems

Lead Consultant - Network Security

EPAM Systems • $125K — $150K *
US-AnywhereRemote in Georgia, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in network security architecture and operations, focusing on cross-border connectivity
  • Expertise in Check Point Security Gateways and Palo Alto Networks firewalls
  • Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
  • Skills in Cloudflare Magic Transit and DDoS mitigation
  • Knowledge of hybrid cloud connectivity and BGP routing
  • Familiarity with regulatory frameworks for data residency and TLS inspection
  • Competency in Terraform and Ansible for policy automation

Responsibilities

  • Establish trust zones and routing boundaries for secure network segmentation
  • Create high-level and low-level documentation aligned with regulatory standards
  • Build and manage dual-vendor firewall perimeters with high availability
  • Configure ZIA for identity-aware egress controls and inline governance
  • Deploy ZPA for zero-trust access and app segmentation
  • Architect Site-to-Site VPN and hybrid cloud connectivity solutions
  • Consolidate telemetry into SIEM and develop detection rules for anomalies

Benefits

  • Flexible work arrangements
  • Professional development opportunities
  • Access to cutting-edge security tools and technologies
  • Collaborative team environment
  • Health and wellness programs
Full Job Description
Lead Consultant - Network Security We are looking for a Lead Consultant who will design, build, and manage secure, compliant network segmentation connecting regional environments to Global networks. This position utilizes a standardized security toolset, including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Cloudflare for DDoS protection, WAF, and application security. The role combines architectural design, hands-on engineering, automation, and L3/L4 operational leadership to provide policy-driven connectivity that meets strict regulatory and operational standards. Responsibilities Establish trust zones, routing boundaries, and inter-zone controls across regional and Global Networks, addressing north-south and east-west traffic, micro-segmentation for sensitive layers, and explicit cross-border allow-lists Create HLD/LLD documentation, threat models, and control mappings that align with internal standards and regional regulations to support secure communication between regional and Global customer sites Build and manage dual-vendor firewall perimeters with defined control distribution, HA/cluster architecture, predictable failover, NAT domain strategy, SSL/TLS inspection governance, and jurisdiction-tuned Threat Prevention/WildFire/URL filtering Configure ZIA to provide identity-aware egress controls, jurisdiction-sensitive SSL inspection bypasses, inline CASB/DLP, and governance for approved SaaS applications Deploy ZPA to enable per-application zero-trust access, including connector placement, posture verification, conditional access, and app segmentation to replace legacy VPN solutions where possible Architect and implement Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site to support hybrid cloud connectivity Roll out Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, integrating with on-premises perimeters for layered protection Design SD-WAN/MPLS/SASE pathways featuring policy-based routing, robust encryption, and jurisdiction-specific key custody and rotation practices Convert regulatory and internal control mandates into actionable technical controls covering logging, data residency, TLS inspection scope, and lawful intercept requirements Consolidate telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM following regional data handling policies, and develop detection rules for cross-border anomalies and policy drift Direct L3/L4 incident response efforts, coordinate containment measures, and oversee RCAs with documented corrective actions Oversee firewall, Zscaler, and Cloudflare policy management using Terraform/Ansible and vendor APIs, and establish CI/CD pipelines incorporating policy linting, unit testing, and path simulation Requirements 5+ years of experience in network security architecture and operations, specializing in cross-border or multi-region connectivity Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept Familiarity with SIEM platforms and telemetry normalization for cross-border security monitoring Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning English proficiency at B2 level or higher

About EPAM Systems

EPAM Systems, Inc. is a leading global provider of digital platform engineering and development services. The company has a strong presence in North America, Europe, and Asia, and serves clients in a variety of industries, including financial services, healthcare, and retail. EPAM's services include software engineering, product development, and digital platform engineering, and the company has a reputation for delivering high-quality solutions that help its clients achieve their business goals. EPAM has been recognized as a leader in the digital services industry by a number of independent research firms, and the company has won numerous awards for its work.
Learn more about EPAM Systems
Size
58,824 employees
Market Cap
$18.2 billion
Industry
Net Income
$327.1 million
Founded
1993
5 Year Trend
+26.5%
Revenue
$2.6 billion
NASDAQ

Similar Jobs

More Jobs at EPAM Systems

More Information Technology Jobs

Find similar Lead Consultant - Network Security jobs: