Job ID: 18359
Alternate Locations:
Job Summary:
The Senior Network Security Engineer provides dedicated engineering capacity to accelerate Newell Brands network segmentation buildout and materially reduce lateral movement risk across the enterprise. This role is the hands-on technical lead for network segmentation architecture and enforcement of network security controls across IT, OT, and cloud environments within Newell's global multi-site footprint. The engineer does not just design; they design, validate, and partner across infrastructure and business stakeholders to drive adoption of controls that reduce real-world attack surface.
Key Responsibilities:
• Own and drive execution of the network segmentation roadmap, translating architecture designs into firewall rule requirements, validated post-implementation with the network team
• Architect and support network zone boundaries, trust relationships, and inter-zone communication rules aligned to Zero Trust principles
• Drive the strategic shift from port/protocol-based to App-ID and User-ID driven segmentation, integrating identity-based access controls across sites
• Lead microsegmentation design for high-risk environments including manufacturing OT, data center, cloud connected, and retail POS segments
• Architect and specify cloud network security controls - network segmentation, cloud firewall policy, and secure cloud-to-on-prem connectivity
• Partner with the OT Security Specialist to design and support IT/OT demilitarized zone architecture and manage converged traffic flow design safely
• Conduct and document network architecture reviews to identify trust boundary gaps, flat network zones, and legacy segment exposure
• Specify and validate firewall rules against segmentation design and security baselines across IT and OT environments
• Drive firewall rule lifecycle reviews: review and tune rule sets, identify unused or overly permissive rules, and coordinate remediation with the network team
• Review and approve firewall change requests for security impact, and verify post-implementation rule accuracy
• Build and maintain network security engineering runbooks and configuration baselines for the Security Engineering team
• Leverage AI-assisted tools and automation to accelerate firewall policy analysis, segmentation validation, and engineering documentation
Required Qualifications:
• 5+ years of hands-on network security engineering experience: firewall policy, segmentation design, and enterprise network architecture • Demonstrated experience designing and validating network segmentation in a complex, multi-site environment
• Working knowledge of Zero Trust Network Access (ZTNA) concepts and practical application to enterprise segmentation
• Working knowledge of cloud network security controls and architecture in at least one major cloud platform (Azure, AWS, or GCP) • Familiarity with enterprise firewall policy management and rule lifecycle tooling (e.g., policy orchestration and change management platforms)
• Understanding of OT/ICS network environments and IT/OT segmentation best practices (Purdue Model, IEC 62443)
• Strong documentation skills: ability to produce architecture diagrams, configuration runbooks, and network design documentation
• Bachelor's degree in Computer Science, Network Engineering, Information Security, or equivalent practical experience
Preferred Qualifications:
• Experience with SASE or cloud-delivered network security platforms
• Demonstrated experience securing hybrid cloud environments, including cloud-to-on-prem network segmentation and enforcement (Azure, AWS, or GCP)
• Cloud security certifications (e.g., AZ-500, AWS Security Specialty, CCSP)
• Experience in a manufacturing, consumer goods, or retail environment with distributed site and OT/IT network challenges
• Experience with SD-WAN architecture and security policy enforcement across distributed sites
• Industry certifications in network security (e.g., PCNSE, CCNP Security, GIAC GAWN, or equivalent)
Date Posted: Sep 30, 2026