> Markdown version of [/jobs/ext/2185570-network-security-engineer](https://www.wearedevelopers.com/jobs/ext/2185570-network-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Engineer - **Company:** Customers Bank - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** IEEE 802.1X, Application Firewall, Microsoft Azure, Border Gateway Protocol, Cisco PIX, Software as a Service, Cloud Computing, Cloud Computing Security, Profiling, Cyber Security, Network Address Translation, Domain Name System (DNS), Enhanced Interior Gateway Routing Protocol, Identity and Access Management, Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Microsoft Office, Network Segmentation, PCI Data Security Standards, Performance Tuning, Remote Access Technology, Migration Manager, Ansible, Zero Trust Network Access, Runbook, Data Streaming, TCP/IP, Wide Area Networks, Cisco Anyconnect, Scripting, Identity Services Engine, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cisco Firewalls, Palo Alto Networks, Firepower, Firewall Services Module, Cisco Switches, Cisco - **Published:** August 22, 2026 - **Apply:** https://www.dice.com/job-detail/1cda1460-f551-47ce-aa6c-13f125450fe0 ## About the Role Proven reliability: We always ground our innovation in our deep experience and strong financial foundation, so we're a partner you can trust., * 5+ years of hands-on experience in network security engineering, with demonstrated expertise in enterprise firewall administration and network perimeter security (CCNP Security-level or equivalent experience). * 3+ years of hands-on experience with Palo Alto Networks NGFWs, including Panorama management, security policy design, and advanced threat prevention features (App-ID, User-ID, WildFire). * Solid hands-on experience with Cisco ASA and/or Firepower (FTD/FMC) - access control policies, IPS tuning, platform upgrades, and migration planning. * Strong working knowledge of Cisco ISE for NAC, 802.1X, RADITACACS+, device profiling, and guest access management. * Experience with VPN technologies including Cisco AnyConnect/Secure Access and IPSec site-to-site tunnels; understanding of certificate-based authentication and split tunneling design. * Solid understanding of core network security protocols and concepts including TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, and network segmentation/micro-segmentation. * Familiarity with Cisco Catalyst SD-WAN security capabilities, including application-aware policy enforcement, encrypted transport, and security service chain integration. * Experience with Cisco Umbrella/Secure Access or similar DNS-layer security and cloud-delivered security platforms; working knowledge of URL filtering, threat intelligence, and SaaS policy management. * Experience working within an ITIL-based change management process; comfortable authoring change requests, presenting to CAB, and performing post-implementation and after-action reviews. * Ability to work with the Microsoft Suite and Customers Bank's internal collaboration and ticketing applications; familiarity with scripting (e.g., Python, Ansible) for firewall automation and policy management is a plus., * Familiarity with security and compliance frameworks relevant to a regulated financial institution (e.g., PCI-DSS, SOX, NIST CSF, FFIEC); ability to translate regulatory requirements into technical security controls. * Palo Alto Networks certifications (PCNSE or equivalent) are preferred; Cisco security certifications (CCNP Security, CCIE Security) are also highly valued. A demonstrated track record carries equal weight to certifications. * ITIL Foundation certification or equivalent experience with change and incident management practices. * Experience with Microsoft Azure networking and cloud security, including Azure Firewall, NSGs, Virtual WAN, ExpressRoute, and integration with on-premises security infrastructure. ## Description As a Network Security Engineer at Customers Bank, you will be a key member of our IT Network team, responsible for designing, implementing, administering, and supporting our enterprise network security infrastructure. You will play a hands-on role in protecting the bank's network perimeter, securing data flows, and enforcing security policies across our multi-site environment. This role requires deep hands-on expertise with Palo Alto Networks and Cisco firewall platforms, along with strong knowledge of network security principles, zero-trust architecture, VPN technologies, Cisco ISE, and SD-WAN security. * Design, deploy, and manage Palo Alto Networks next-generation firewalls (NGFWs), including security policies, NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire across the enterprise and branch locations. * Administer and maintain Cisco ASA and Firepower (FTD) firewalls, managing access control policies, intrusion prevention, and platform lifecycle including upgrades and patching. * Manage and maintain VPN infrastructure, including Cisco AnyConnect/Secure Access remote access, as well as site-to-site IPSec tunnels, ensuring secure and reliable connectivity for remote users and branch offices. * Support and secure the Cisco Catalyst SD-WAN environment, including applying security policies, traffic segmentation, and ensuring encrypted transport across WAN fabrics. * Administer Cisco Umbrella/Secure Access DNS-layer security and web filtering policies, managing category-based controls, threat intelligence integrations, and reporting across the enterprise. * Able to lead investigation and response to network-layer security incidents, anomalies, and policy violations. * Participate in and lead change management activities in accordance with ITIL best practices, ensuring proper documentation, approvals, post-implementation reviews, and compliance with regulatory requirements. * Collaborate with the Information Security, Cloud, and Infrastructure teams to design and implement network segmentation, zero-trust controls, and security architecture improvements aligned to PCI-DSS, SOX, and NIST frameworks. * Work both independently and collaboratively across IT teams, vendors, and business stakeholders to deliver security projects, resolve incidents, and drive continuous improvement of the network security posture. * Maintain thorough documentation of firewall policies, network security architecture, runbooks, and standard operating procedures. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)