Senior Network Security Engineer

Covenant LLC
Cambridge, MA, United States
2 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Application Firewall Cloud Computing Cyber Security Dynamic Host Configuration Protocol Network Address Translation Domain Name System Security Extensions Domain Name System (DNS) Firmware Hypertext Transfer Protocols (HTTP) Intrusion Detection and Prevention Subnetting
+13 more
Virtual Private Networks (VPN) Network Security Routing Remote Access Technology Security Information and Event Management TCP/IP Traffic Analysis Data Logging Transport Layer Security Firewalls (Computer Science) Palo Alto Networks Fortinet Firewall Services Module

Job description

  • Administer, maintain, troubleshoot, and continuously improve enterprise Next-Gen firewall infrastructure and associated security controls.
  • Manage firewall policies, NAT, security profiles, zones, interfaces, objects, routing configurations, management portals, and rule-base hygiene.
  • Configure and tune threat prevention, vulnerability protection, URL filtering, DNS security, sandboxing, decryption, and logging profiles.
  • Support secure remote connectivity and VPN operations, including authentication, client connectivity, configuration, and user-impacting incidents.
  • Troubleshoot complex Layer 3-7 network security issues using packet captures, traffic analysis, CLI/vendor tools, logs, and other diagnostic utilities.
  • Leverage SIEM and AI/AIOps capabilities to identify threats, analyze network and firewall activity, prioritize incidents, and identify opportunities to improve security controls.
  • Participate in firewall rule reviews, segmentation initiatives, access evaluations, control validation, and security cleanup activities.
  • Plan and execute firewall maintenance, firmware upgrades, content updates, high-availability validation, license checks, and capacity monitoring.
  • Partner closely with network engineering, infrastructure, cloud, identity, endpoint, application, and security teams.
  • Maintain clear operational documentation, diagrams, procedures, runbooks, change records, and audit/control evidence.
  • Take independent ownership of issues from initial investigation through escalation, resolution, and follow-up.
  • Participate in incident response and scheduled after-hours maintenance when required.

Requirements

  • 5-10 years of hands-on experience in network security, firewall administration, security operations engineering, network engineering, or a closely related role.
  • Deep hands-on Next-Gen Firewall experience, ideally with Palo Alto Networks, Check Point, and/or Fortinet, including firewall policies, NAT, security profiles, VPN, URL filtering, threat prevention, logging, and lifecycle management.
  • Strong enterprise networking fundamentals across TCP/IP, subnetting, routing, switching, DNS, DHCP, NAT, VPN, TLS, and HTTP/S, with the ability to troubleshoot Layer 3-7 issues.
  • Proven ability to independently own production network security issues through investigation and resolution, including firewall changes/upgrades, incident response, and scheduled after-hours maintenance.
  • Strong problem-solving skills with an adaptable mindset and willingness to learn new technologies.

About the company

Company - Our client is a Boston-based investment management firm specializing in systematic, data-driven global equity strategies for institutional investors. The organization combines sophisticated technology and quantitative research with a collaborative, innovation-focused environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann Chris Heilmann +1 · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all