Network Security Engineer

The Smart
Reading, PA, United States
1 day ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

IEEE 802.1X Application Firewall Automation of Tests Microsoft Azure Border Gateway Protocol Cisco PIX Cloud Computing Cloud Computing Security Profiling Complex Networks Cyber Security System Configuration
+29 more
Network Address Translation Domain Name System (DNS) Enhanced Interior Gateway Routing Protocol Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language) Network Security Routing Network Segmentation PCI Data Security Standards Ansible Zero Trust Network Access Runbook Data Streaming TCP/IP Wide Area Networks Cisco Anyconnect Identity Services Engine Network Access Control Computer Network Technologies Firewalls (Computer Science) Web Filtering Palo Alto Networks Firepower TACACS+ Protocol Firewall Services Module Cisco Switches Cisco

Job description

Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution., Firewall Engineering & Perimeter Defense * Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. * Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. * Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity * Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. * Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. * Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. * Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management * Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. * Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. * Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs).

Requirements

Required Qualifications * 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). * 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. * Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. * Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. * Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). * Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). * Experience working within an ITIL-based change management framework. * Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications * Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. * Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). * Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). * Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes * Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. * High accountability and attention to detail when executing production changes and maintaining documentation. * Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. * Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all