Overview
Serve as a Senior Staff Network Security Engineer supporting enterprise network security across traditional, virtualized, and cloud environments, with a focus on SaaS and AI access security. Design, deploy, operate, and optimize security architectures and controls that protect SaaS application traffic, organizational data, and AI platform usage.
What you'll do
- Design, implement, operate, and support enterprise network security solutions including routing, switching, segmentation, and traffic filtering technologies.
- Serve as a subject matter expert for firewalls, remote access solutions, IPSec VPNs, IDS/IPS, web application firewalls, proxies, DLP, CASB, NAC, micro-segmentation, wired and wireless security, SIEM, and next-generation breach detection platforms.
- Design, deploy, and operate Palo Alto Networks SaaS Inline Security capabilities for real-time inspection, threat prevention, and data protection.
- Implement and manage Palo Alto Networks AI Access Security controls for AI-driven and generative AI platforms, including policy enforcement, data loss prevention, and visibility into application usage and risk.
- Integrate SaaS Inline Security and AI Access Security with Palo Alto Networks firewalls, CASB, DLP, and SIEM solutions.
- Define and enforce security policies for SaaS and AI application access aligned with corporate risk tolerance, data protection requirements, and industry best practices.
- Monitor, analyze, and respond to security events and alerts related to SaaS and AI application traffic, including investigation, tuning, and continuous optimization.
- Evaluate emerging SaaS and AI security features within the Palo Alto Networks ecosystem and advise on adoption, roadmap alignment, and operationalization.
- Lead and contribute to network security initiatives from concept and architecture through implementation, testing, and production rollout.
- Provide day-to-day operational support, including monitoring, troubleshooting, break-fix remediation, ticket handling, and change management in accordance with established processes and SLAs.
- Perform expert-level protocol troubleshooting across TCP/UDP, IP, ARP, DNS, and HTTP/S, identify root causes, and implement sustainable corrective actions.
- Design, deploy, and maintain site-to-site and remote-access IPSec VPN solutions.
- Administer, design, and support Palo Alto Networks firewalls in on-premises, virtualized, and cloud-based environments, including policy optimization, threat prevention tuning, upgrades, and lifecycle management.
- Support and integrate F5 WAF and McAfee CASB within the broader cybersecurity ecosystem.
- Develop and maintain technical documentation, network diagrams, security standards, and operational runbooks.
- Apply NIST, Cybersecurity Kill Chain, and other security control frameworks and methodologies to architecture decisions, threat modeling, and remediation strategies.
- Evaluate cybersecurity technologies and vendors and recommend solutions that provide measurable value and integrate with existing systems.
- Collaborate with IT operations, cloud engineering, application teams, and security leadership on secure-by-design network architectures.
- Use Python scripting and automation to improve operational efficiency, enhance visibility, and reduce manual effort.
- Provide technical leadership, mentorship, and oversight for assigned projects or junior team members.
- Stay current with evolving threat landscapes, attack vectors, and next-generation security platforms.
- Participate in on-call rotations and provide after-hours support as required.
What you'll need
- Strong understanding of enterprise-level network operations, including routing, switching, segmentation, and filtering technologies in traditional, virtualized, and cloud environments.
- Proven track record of successful IT project contribution from concept to completion.
- 6+ years of specialization in network security technologies, including firewalls, remote access, and IPSec VPN.
- 6+ years of successful network-level troubleshooting and break-fix implementations.
- 6+ years of experience with day-to-day network support, ticketing, and change management.
- Experience in network security solution design, documentation, and best practices.
- Proven engineering experience supporting firewalls, intrusion detection and prevention systems, proxies, DLP, network deception, micro-segmentation, NAC, wired and wireless security, SIEM, next-generation breach detection systems, and CASB.
- Expert-level understanding of network protocols, including TCP/UDP, IP, ARP, DNS, and HTTP(S).
- Detailed understanding of attack vectors, current threats, and remediation strategies.
- Strong time management skills for planning, organizing, and leading architecture development efforts.
- Strong interpersonal and communication skills to build and maintain ongoing business relationships.
- Ability to work as a self-starter with minimal supervision, multitask effectively, and provide oversight and coaching for assigned projects or tasks.
- Detailed understanding of control frameworks and reference architectures such as NIST and Cybersecurity Kill Chain.
- Ability to stay current with cybersecurity developments and next-generation platforms.
- Availability for on-call, after-hours support as required.
- Demonstrable experience with IPSec VPN design, implementation, and troubleshooting.
- Expert-level knowledge of Palo Alto Networks firewalls, including administration, operations, design, deployment, and troubleshooting.
- Demonstrable experience with Palo Alto Networks firewalls in virtual and cloud environments.
- Demonstrable experience with Palo Alto Networks SaaS Inline Security and AI Access Security capabilities.
- Ability to work with suppliers and vendors to assess cybersecurity capabilities, integrations with the existing cybersecurity ecosystem, and operationalization.
- Python is required.
Nice to have
- Hands-on experience with Palo Alto Networks firewalls, F5 WAF, and CASB is highly desired.
- Perl and Java are a plus.
Details
- Location: Bangalore.
- Participate in on-call rotations and provide after-hours support as required.
Read the full description and apply on the company’s own careers page.