Cyber Security Network Engineer

Robert Walters plc
United States
2 days ago
Apply on computerjobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Firewall Software System Penetration Testing Border Gateway Protocol Complex Networks Cyber Security System Configuration Linux DevOps Online Banking Cryptographic Protocols Enhanced Interior Gateway Routing Protocol Information Technology Operations
+31 more
Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Network Security Windows Servers Network Segmentation Citrix Systems Open Shortest Path First (OSPF) Oracle (Applications) Open Web Application Security Zero Trust Network Access Session Management Security Information and Event Management Software Deployment TCP/IP Transport Layer Security Network Access Control Load Balancing Computer Network Technologies Oracle Flexcube System Availability Software Security Firewalls (Computer Science) Information Technology Cybercrime CIS Benchmarks Firepower Cisco Web Api Citrix Netscaler

Job description

My client are seeking a motivated, hands-on and experienced Cyber Security Network Engineer with experience in the banking industry ideally with Oracle Flexcube and Oracle Banking Digital Experience (OBDX). This role is to own the bank’s technical security posture, protect systems from cyber threats, and manage perimeter and application security platforms. This role bridges the gap between infrastructure engineering and threat management, ensuring high availability, robust defence-in-depth, and strict regulatory compliance across all banking networks.

Main responsibilities:

1.Vulnerability Management:

  • Scanning & Triage: Run regular vulnerability scans across networks applications, and endpoints; triage findings based on business risk and CVSS scores, and coordinate rapid remediation with IT operations teams.

  • KPI Reporting: Track, analyze, and report on vulnerability life cycle metrics and KPIs for senior leadership and regulatory oversight bodies.

  • Patch Verification: Validate the effectiveness of deployed patches and configuration changes via targeted follow-up scans.

  1. Security Infrastructure Ownership:
  • Next-Generation Firewalls (NGFW): Manage and maintain Cisco Firepower Firewalls, including complex rule set architecture, IPS/IDS signature tuning, URL filtering, and malware protection policies.

  • Web Application Firewalls (WAF): Administer F5 WAF (Advanced WAF/ASM) to protect online banking portals, API endpoints, and mobile banking backends against OWASP Top 10, credential stuffing, and advanced bot attacks.

  • Application Delivery Controllers (ADC): Manage Citrix ADC/NetScaler load balancers, ensuring secure traffic distribution, robust TLS/SSL cipher suite configuration, and secure session management.

  • Zero Trust & Access Control: Maintain secure Remote Access VPNs, site-to-site IPsec tunnels, and network access control (NAC) policies to enforce micro-segmentation.

  1. Threat Detection & Response:
  • SIEM Monitoring: Monitor, analyze, and triage alerts from the Security Information and Event Management (SIEM) platform, acting as a technical escalation point for the SOC.

  • Use Case Development: Develop, test, and tune custom detection use cases, correlation rules, and alert logic to improve detection quality and reduce false positives.

  • Incident Response: Support incident response phases (containment, eradication, recovery) during active network-level cyber security incidents.

  1. Security Hardening & Architecture:
  • Baseline Configurations: Establish, update, and enforce secure configuration baselines (eg, CIS Benchmarks) for Windows Servers, Linux/Unix environments, and core network devices.

  • Network Segmentation: Design and audit zone-based network segmentation to isolate critical banking environments (eg, SWIFT, card processing, core banking) from untrusted networks.

  1. Change Management Governance & Discipline:
  • Structured Planning: Author comprehensive change requests detailing exact technical steps, complete documentation, precise impact assessments, and zero-downtime execution windows.

  • Rigorous Testing: Mandate and execute thorough pre-implementation testing in non production environments to validate security policies, rules, and configurations before live deployment.

  • Fail-Safe Rollbacks: Design, document, and test explicit, step-by-step rollback procedures for every infrastructure change to guarantee immediate service restoration in the event of failure.

  • Peer Review: Lead and participate in peer-review cycles for complex network and security modifications to maintain institutional standards and eliminate single points of failure.

  1. Project Security & Compliance:
  • Risk Reviews: Perform technical security reviews and threat modelling for new infrastructure projects, cloud migrations, and standard change requests.

  • Penetration Testing: Coordinate annual penetration testing cycles with external vendors, validate findings, and track the remediation of identified flaws.

  • Regulatory Alignment: Ensure all network security controls comply with industry standards and best practice

Requirements

Required Experience.

  • 5+ years of experience in network engineering with a heavy focus on cyber security, ideally within a regulated financial institution or enterprise environment.

  • Proven hands-on experience configuring and troubleshooting Cisco Firepower, F5 ASM/WAF, and Citrix NetScaler.

  • Strong understanding of core networking protocols (BGP, OSPF, EIGRP), the TCP/IP stack, and advanced cryptographic protocols (TLS 1.3, SSH, IPsec).

Desired Certifications (One or more)

  • General Security: CISSP, CISM, or CEH.

  • Network/Vendor Specific: CCNP Security, Cisco Certified Specialist - Network Security Firepower, F5-CA/F5-CTS, or Citrix Certified Professional - Networking (CCP-N).

  • Soft Skills

  • Strong collaborative skills to work effectively alongside standard IT Infrastructure and DevOps teams.

  • Excellent technical writing skills for creating clear, compliant security documentation and architecture diagrams

Benefits & conditions

My client, an International Bank, is looking for a Cyber Security Network Engineer to join them on a Fixed - Term - Contract for 2 years. This role does not offer sponsorship and you will need to be in the office 5 days per week (in London). However, there is a chance you can work one day per week from home (either Monday or Friday).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on computerjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all