The OpportunityWe're seeking a client-facing Network & Security Consultant to deliver hands-on design, administration, hardening, and operational support across client network and security infrastructure, and to play a critical supporting role in active incident response (IR) engagements. In this role you'll work remotely and at times on-site, within client environments including sovereign, regulated, and cleared settings providing the technical expertise, composure, and professionalism that define the Malleum delivery experience.
This is a hands-on consulting role for a senior-level practitioner who blends deep technical skill with strong client presence, and who can step up when crises demand long, focused hours alongside our IR team.
What You'll Do- Administer, monitor, and maintain client network infrastructure including routers, switches, firewalls, VPNs, and wireless systems
- Operate and tune client security tooling such as EDR/XDR, SIEM, email security, vulnerability scanners, and identity platforms (Entra ID, Okta)
- Design, deploy, and operate Zero Trust Network Access (ZTNA) solutions, including Cloudflare edge, access, and tunnel services, to enable secure remote access, identity-aware policies, and modern perimeter strategies
- Support Microsoft 365, Azure, AWS, and hybrid environments within each client's security baseline and compliance posture
- Implement and enforce hardening standards aligned with CIS Benchmarks, NIST 800-53/171, ITSG-33, and client-specific frameworks
- Lead patch management, vulnerability remediation, and configuration management across client servers, endpoints, and network devices
- Support active incident response engagements - deploying and tuning tooling, isolating systems, preserving evidence, rebuilding infrastructure, and assisting with containment, eradication, and recovery activities
- Work odd hours, evenings, weekends, and extended shifts during active IR engagements, including rapid mobilization with little notice when clients are under attack
- Partner with Malleum's IR consultants, forensic analysts, and threat hunters to execute response playbooks under pressure
- Maintain client backup, disaster recovery, and business continuity systems with regular testing
- Produce high-quality client deliverables: network diagrams, configuration documentation, runbooks, SOPs, IR action logs, and status reports
- Standardize provisioning, onboarding/offboarding, and access control workflows within client environments
- Serve as a trusted technical point of contact, communicating clearly with client stakeholders ranging from end users to executive leadership during both steady-state and crisis operations
- Contribute to scoping, estimation, and continuous improvement of Malleum's managed, project-based, and IR service offerings
- Participate in an on-call rotation supporting critical client infrastructure and security events
What You Bring- Deep, hands-on, multi-vendor network and firewall experience - routing, switching, segmentation, and firewall policy you can design, deploy, troubleshoot, and demonstrate in a technical interview (Fortinet, Palo Alto, and/or Cisco). This is the core of the role and the bar candidates are measured against.
- Demonstrated success working directly with clients - clear communication, professionalism, and stakeholder management, including explaining technical risk and decisions to non-technical leadership
- Significant progressive experience blending network and cybersecurity responsibilities, ideally in a consulting, MSP, MSSP, or IR setting
- Strong working knowledge of TCP/IP, routing, switching, VLANs, VPNs, DNS, DHCP, and segmentation
- Solid understanding of Zero Trust Network Access (ZTNA) fundamentals: identity-centric access, least privilege, micro-segmentation, device posture, and continuous verification
- ZTNA delivery experience. Hands-on Cloudflare (Cloudflare One / Zero Trust, Access, Tunnel, Gateway, WARP) is strongly preferred. If your ZTNA experience is on another platform (Fortinet, Zscaler, Netskope, Palo Alto Prisma Access), a demonstrated ability to map it across and ramp quickly is welcome
- Hands-on experience with wireless controllers and NAC solutions
- Demonstrated ability to perform under pressure during incidents: calm, methodical, and effective during long, high-intensity engagements
- Willingness and availability to work odd hours, weekends, and extended shifts when supporting active IR matters
- Working knowledge of Windows Server, Active Directory, Group Policy, and Microsoft 365 / Azure administration
- Familiarity with Linux administration and scripting (PowerShell, Bash, or Python) for automation and rapid response
- Experience with SIEM/EDR platforms (e.g., Microsoft Sentinel, Defender, CrowdStrike, Splunk), including rapid deployment in IR scenarios
- Exposure to incident response frameworks such as NIST SP 800-61 and SANS PICERL is a strong asset
- Solid grasp of cybersecurity fundamentals: identity, encryption, logging, hardening, and zero-trust principles
- Comfort working across multiple client environments, tooling stacks, and change-management processes simultaneously
- Certifications such as CompTIA Security+, Network+, CCNA, CCNP Security, NSE, PCNSA, MS-102, AZ-104, or equivalent strongly preferred; CISSP Associate, SSCP, GCIH, or GCFA an asset
- Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued
- Bilingualism (English/French) considered a strong asset
Why Malleum- Work shoulder-to-shoulder with marquee clients on programs and incidents with genuine national and allied security impact
- Join a rapidly scaling firm with a flat, high-trust culture and direct access to senior IR and technical leaders
- Exposure to a wide variety of advanced security tooling, sectors, and cleared environments
- Competitive compensation, on-call and IR premiums, performance incentives, and comprehensive benefits
- Continuous learning budget, certification sponsorship, and clear paths into senior engineering, IR, architecture, or security specializations