Role Overview:We are seeking a Lead Network Security Engineer with deep expertise in firewall management, network segmentation, and Microsoft Defender security suite. This role involves designing, implementing, and optimizing robust security policies and architectures to protect enterprise networks and cloud environments, ensuring a strong Zero Trust posture.
Key Responsibilities:- Manage and optimize firewalls, including policy creation, maintenance, and rule base cleanup.
- Configure and tune App-ID, User-ID, Content-ID, IPS/IDS signatures, and SSL decryption policies.
- Administer Panorama centralized management and integrate with SIEM solutions.
- Design and implement access control and intrusion policies.
- Configure FMC (Firepower Management Center).
- Design, implement, and manage the Microsoft Defender Security suite, including attack surface reduction and EDR capabilities.
- Create advanced KQL queries for threat hunting and automate security workflows using Defender API.
- Drive security posture improvement through Secure Score recommendations.
- Design and implement enterprise network micro segmentation strategies, supporting Zero Trust architecture and least-privilege access models.
- Develop segmentation policies for data centers, cloud environments, critical business applications, and user endpoints.
- Define security zones, control east-west traffic, and conduct traffic flow analysis.
- Collaborate with network and infrastructure teams to enforce segmentation policies and reduce lateral movement risks.
Required Skills:- Firewalls management (Palo Alto, Check Point, Fortinet, Cisco)
- Firewall Rules policies creation and maintenance
- Rule base Optimization and cleanup
- App-ID, User-ID, Content-ID tuning
- IPS/IDS signature tuning
- SSL decryption policy management
- Panorama centralized management
- Integration with SIEM
- Access control policy design
- Intrusion policy optimization
- FMC (Firepower Management Center) configuration
- MS Defender
- MS Purview
- Network Security
- Network Segmentation & Microsegmentation
- NAC Solutions
- TCP/IP, Routing & Switching
- VPN Technologies
- Zero Trust Architecture
Qualifications:- Bachelor's degree in a relevant field.
- 6 to 10 Years of experience in network security engineering.
Preferred Skills:- Microsoft Defender Security Engineering
- MS Purview expertise