Senior Network Security Engineer

Gordon Food Service

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in enterprise-scale security architecture design and implementation.
  • Bachelor's degree in Information Security, Computer Science, Engineering, IT, or related field; equivalent education/experience considered.
  • Expertise in Next-Generation Firewalls, SASE, ZTNA, and micro-segmentation.
  • Deep understanding of identity-centric security models and IAM integration.
  • Experience with multi-cloud environments like AWS, Azure, and GCP.
  • Strong project leadership skills for large-scale infrastructure and security initiatives.

Responsibilities

  • Lead the design and improvement of enterprise security infrastructure.
  • Oversee the migration to modern SASE and ZTNA platforms.
  • Develop network security reference architectures and standards supporting Zero Trust.
  • Collaborate on secure design for infrastructure, routing, and SD-WAN services.
  • Integrate IAM attributes into dynamic network access control decisions.
  • Contribute to enterprise security transit layer architecture for consistent policy enforcement.
  • Design global segmentation strategies utilizing NGFWs and cloud-native security controls.

Benefits

  • Flexible work schedule: 4 days in-office, 1 day remote each week.
  • Participation in a rotating 24/7 on-call schedule for critical support.
  • Engagement in a collaborative and strategic IT environment.
Full Job Description
Position Summary:

The Senior Network Security Engineer responsible for the design, architecture, implementation, and continuous improvement of the organization's network security strategy across hybrid, cloud, and operational technology (OT) environments. Acting as a strategic collaborator between Security, Cloud, Infrastructure, and Network teams, the Senior Engineer transforms the network into an identity-aware enforcement fabric that enables Zero Trust principles across the enterprise.

This role focuses on advancing the organization from traditional IP-based security models toward identity-driven access controls based on user identity, device posture, risk signals, and least-privilege principles. The Senior Engineer serves as the technical authority for network security architecture standards, engineering patterns, and strategic technology direction, creating a unified and scalable security framework across all environments. This position is responsible for driving modernization initiatives, eliminating operational silos, and establishing a single source of truth for network security policy enforcement across on-premises, cloud, and third-party platforms.

What you will do:

  • Lead the design, implementation, and continuous improvement of the enterprise security infrastructure while maintaining an engineering focus on governance, scalability, resiliency, and secure architecture principles in collaboration with other GTS team.
  • Serve as the primary technical engineering lead for the migration from legacy proxy and remote access technologies to modern Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) platforms.
  • Develop and maintain network security reference architectures, engineering standards, design patterns, and implementation roadmaps supporting Zero Trust, cloud adoption, regulatory compliance, and business objectives.
  • Collaborate closely with Cloud and On-Premise Network teams to ensure infrastructure, routing, SD-WAN, and connectivity services are designed and deployed with security-by-design principles while maintaining performance and reliability.
  • Partner with Identity and Access Management (IAM) teams to integrate identity attributes, device posture, risk signals, SAML, OIDC, and directory services into dynamic network access control and policy enforcement decisions.
  • Contribute to the architecture, engineering, and operational management of the enterprise security transit layer to ensure consistent policy enforcement across cloud providers, on-premises infrastructure, partner networks, and vendor-hosted environments.
  • Design and oversee the implementation of a global unified segmentation strategy utilizing Next-Generation Firewalls (NGFWs), micro-segmentation technologies, and cloud-native security controls across data centers and cloud environments.
  • Design and maintain secure segmentation architectures protecting Operational Technology (OT) and Industrial Control System (ICS) environments from enterprise network threats while supporting operational requirements and business continuity.
  • Act as the primary technical stakeholder for Network Detection and Response (NDR) platforms, ensuring comprehensive visibility, telemetry collection, threat detection capabilities, and integration with enterprise security monitoring solutions.
  • Lead the engineering and security posture for enterprise infrastructure services including DNS security, Web Application Firewalls (WAF), DDoS protection, load balancing technologies, and secure application delivery platforms.
  • Manage the security of data-in-transit by establishing encryption standards, certificate lifecycle automation, secure communication protocols, and cryptographic best practices.
  • Design and implement Infrastructure as Code (IaC), automation, and policy-as-code solutions to deploy, maintain, validate, and audit network security controls across hybrid environments.
  • Provide senior-level technical leadership during cybersecurity incidents involving network infrastructure, cloud connectivity, segmentation boundaries, access control systems, and network-based threat activity.
  • Define and monitor key security engineering metrics related to network visibility, segmentation effectiveness, policy compliance, and Zero Trust maturity.
  • Evaluate emerging network security technologies, industry trends, and architectural approaches, providing recommendations that support strategic modernization and roadmap initiatives.
  • Participate in the Cross-Functional Architecture Group to provide technical security expertise and influence the secure design of enterprise technology initiatives.
  • Mentor engineers and provide technical guidance to Security, Cloud, Infrastructure, and Network teams regarding architecture, engineering standards, operational best practices, and technology adoption.
  • Other duties and responsibilities as assigned.


Your Work Schedule:
  • Hours: Monday through Friday, 8:00 AM - 5:00 PM (Standard Business Hours).
  • Modern Hybrid Model: Enjoy the best of both worlds with a flexible schedule: 4 days in the office, 1 day working from home.
  • On-Call Responsibilities: Participation in a rotating 24/7 on-call schedule (approximately one week every three weeks) to support critical system issues and incidents.

What you bring to the table:

  • Five or more years of experience designing, implementing, and supporting enterprise-scale security architectures.
  • Bachelor Degree in Information Security, Computer Science, Engineering, Information Technology, or a related field; equivalent combination of education and experience may be considered.
  • Strong technical acumen and a passion for continuous learning with expertise in Network Security, Zero Trust Architecture, Cloud Security, and Enterprise Infrastructure.
  • Expert-level knowledge of Next-Generation Firewalls (physical and virtual), SASE, ZTNA, micro-segmentation, and modern network security architectures.
  • Deep understanding of identity-centric security models and the integration of IAM attributes, device posture, contextual signals, and risk-based access controls into network policy enforcement.
  • Experience designing and securing multi-cloud environments including AWS, Azure, and GCP, with knowledge of cloud-native networking, security services, transit architectures, and application delivery frameworks.
  • Strong knowledge of cloud transit architectures, security service edge technologies, software-defined networking, and hybrid connectivity solutions.
  • Deep understanding of Network Detection and Response (NDR), network telemetry, traffic analytics, and threat detection methodologies.
  • Experience with Infrastructure as Code (IaC), automation frameworks, and policy-as-code solutions utilizing technologies such as Terraform, Ansible, Python, GitOps, or equivalent platforms.
  • Strong understanding of enterprise PKI, certificate lifecycle management, encryption technologies, and secure communications protocols.
  • Knowledge of Operational Technology (OT) and Industrial Control System (ICS) security principles, segmentation strategies, and risk mitigation approaches.
  • Demonstrated ability to analyze and troubleshoot complex cross-domain networking, security, cloud, and identity-related challenges.
  • Strategic thinking skills with the ability to eliminate operational silos, establish standards, and drive long-term architectural improvements.
  • Strong project leadership skills with experience managing large-scale infrastructure transformations, security modernization initiatives, and cross-functional programs.
  • Excellent communication, presentation, and interpersonal skills with the ability to communicate technical concepts effectively to technical and non-technical audiences.
  • Ability to influence architectural decisions and build consensus among diverse stakeholder groups.
  • Ability to manage multiple priorities, work independently, and deliver high-quality outcomes in a fast-paced environment.
  • Ability to develop innovative solutions to complex technical problems while leveraging industry best practices, established standards, and organizational objectives.

Similar Jobs

More Jobs at Gordon Food Service

More Information Technology Jobs

Find similar Senior Network Security Engineer jobs: