Senior Network Security Engineer (Remote)

Kohl’s, Inc.
Menomonee Falls, WI, United States
17 days ago
Apply on careers.kohls.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Access Amazon Web Services Application Performance Management User Authentication Border Gateway Protocol Cloud Computing Computer Networks Data Centers Dynamic Host Configuration Protocol Domain Name System Security Extensions Domain Name System (DNS) Enhanced Interior Gateway Routing Protocol
+32 more
Data-Flow Analysis Monitoring of Systems Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Network Security Routing Network Segmentation Network Service Packet Analyzer Cisco Nexus Switches Open Shortest Path First (OSPF) PCI Data Security Standards Remote Access Technology Zero Trust Network Access TCP/IP User Environment Management Virtual Local Area Networks Wide Area Networks Enterprise Data Management Data Logging Network Switches Network Routers Cloud-native Network Functions (CNF) Transport Layer Security Google Cloud Load Balancing Cloud Platform System Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Palo Alto Networks Firewall Services Module Cisco

Job description

About the Role

The Senior Network Engineer, Network Security is a hands-on technical leader responsible for designing, implementing, and operating secure, reliable, and scalable network services across locations, data centers, cloud environments, partner connectivity, and remote-user access.

This role requires strong network engineering fundamentals with deep experience in network security, including Cloud Networking (GCP/AWS), Palo Alto Networks firewalls, GlobalProtect VPN and Prisma Access. The engineer will lead technical delivery for firewalls, remote access, SASE, network segmentation, cloud network security, DNS security, and automation.

What You’ll Do

  • Design, implement, and support Google Cloud Platform or similar Cloud network-security solutions, including VPC architecture, Cloud NGFW, Palo Alto VM-Series firewalls, routing, segmentation, ingress and egress controls, NAT, and centralized logging.
  • Design, deploy, configure, and support next-generation firewalls across data centers, retail locations, internet edge, B2B partner connectivity, remote access, and cloud environments.
  • Own the firewall-policy lifecycle, including intake, design review, implementation, validation, documentation, periodic rule recertification, and decommissioning of obsolete rules.
  • Lead hardware refreshes, software upgrades, migrations, and platform consolidations with minimal business impact.
  • Troubleshoot complex firewall, connectivity, routing, NAT, application, and performance issues using logs, packet captures, traffic-flow analysis, and monitoring tools.
  • Design, implement, and support GlobalProtect VPN and Prisma Access services for secure remote-user connectivity.
  • Drive the transition toward Zero Trust access controls, SSL decryption, consistent security policy enforcement, and secure direct internet access.
  • Troubleshoot remote-user connectivity, application performance, authentication, voice and video quality, routing, and security-policy issues across GlobalProtect and Prisma Access.
  • Lead lifecycle management, upgrades, capacity planning, resiliency testing, and operational improvements for remote-access and SASE platforms.
  • Serve as an escalation resource for major network incidents, participate in the on-call rotation, support front-line operations teams with complex issues, lead root-cause analysis, and implement corrective actions to prevent recurrence.

What Skills You Have

Required

  • 5+ years of network security experience in large-scale, complex enterprise, or high-traffic global environments.
  • Strong understanding of networking concepts and protocols (e.g., TCP/IP, BGP, EIGRP, OSPF, VLANs, DNS/DHCP)
  • Hands-on experience with Palo Alto Networks firewalls, Panorama, GlobalProtect VPN, and Prisma Access.
  • Strong understanding of remote-access VPN, SASE, Zero Trust Network Access, IPsec VPN, identity integration, and security-policy design.
  • Strong experience with Google Cloud Platform or similar cloud networking and security, including VPCs, firewall policies, Cloud NGFW or third-party cloud firewalls, Cloud VPN, Cloud Interconnect, Cloud Router, BGP, Cloud DNS, and load balancing.
  • Experience troubleshooting GlobalProtect and Prisma Access issues using firewall logs, Prisma Access logs, packet captures, routing data, and end-user experience metrics.
  • Experience designing secure connectivity for remote users, retail locations, cloud environments, data centers, and third-party partners.

Preferred

  • Palo Alto Networks certifications such as PCNSA, PCNSE, or Prisma Access certification.
  • Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, or CCIE Security.
  • CISSP or equivalent security certification.
  • Experience with Cisco routing, switching, Cisco ACI, SD-WAN, and enterprise data-center networking.
  • Experience with Prisma Access, SASE, ZTNA, ADEM, and identity-based access controls.
  • Experience with FireMon or similar firewall policy-management and compliance platforms.
  • Experience supporting PCI DSS or another regulated environment.

Requirements

  • 5+ years of network security experience in large-scale, complex enterprise, or high-traffic global environments.
  • Strong understanding of networking concepts and protocols (e.g., TCP/IP, BGP, EIGRP, OSPF, VLANs, DNS/DHCP)
  • Hands-on experience with Palo Alto Networks firewalls, Panorama, GlobalProtect VPN, and Prisma Access.
  • Strong understanding of remote-access VPN, SASE, Zero Trust Network Access, IPsec VPN, identity integration, and security-policy design.
  • Strong experience with Google Cloud Platform or similar cloud networking and security, including VPCs, firewall policies, Cloud NGFW or third-party cloud firewalls, Cloud VPN, Cloud Interconnect, Cloud Router, BGP, Cloud DNS, and load balancing.
  • Experience troubleshooting GlobalProtect and Prisma Access issues using firewall logs, Prisma Access logs, packet captures, routing data, and end-user experience metrics.
  • Experience designing secure connectivity for remote users, retail locations, cloud environments, data centers, and third-party partners.

Preferred

  • Palo Alto Networks certifications such as PCNSA, PCNSE, or Prisma Access certification.
  • Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, or CCIE Security.
  • CISSP or equivalent security certification.
  • Experience with Cisco routing, switching, Cisco ACI, SD-WAN, and enterprise data-center networking.
  • Experience with Prisma Access, SASE, ZTNA, ADEM, and identity-based access controls.
  • Experience with FireMon or similar firewall policy-management and compliance platforms.
  • Experience supporting PCI DSS or another regulated environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careers.kohls.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:32 min

Ensuring secure and reliable connectivity for remote employees

Kyle Daigle · Coffee With Developers

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

Videos

See all

Related articles

See all