Senior Network / Firewall Engineer - Houston, TX

Zedcor Security Solutions (USA), LLC
Houston, TX, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$110,000.0 - $135,000.0
Working hours
Regular working hours
Job source

Tech stack

Audit Trail Microsoft Azure Border Gateway Protocol Cloud Computing Cyber Security Dynamic Host Configuration Protocol Network Address Translation Disaster Recovery Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Network Security Uptime
+23 more
Network Planning and Design Routing Public Key Infrastructure Remote Access Technology Runbook Data Streaming Software Vulnerability Management Wi-Fi Technology Data Logging Network Routers Dynamic Routing Transport Layer Security Load Balancing System Availability Firewalls (Computer Science) Microsoft InTune Palo Alto Networks Microsoft Sentinel Fortinet Firewall Services Module Big Ip Cisco SSL VPN

Job description

  • Design, build, maintain, and troubleshoot IPsec and SSL VPN networks.· Manage and support a Cradlepoint environment of 20,000+ devices.· Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform.
  • Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls.· Patch, monitor, log, audit, and secure network infrastructure.
  • Ensure network links, management access, VPNs, and sensitive data flows are encrypted.· Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks.
  • Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness.
  • Use Zedcor’s internal PKI solution for device identity, certificates, authentication, encryption, and secure management.
  • Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting.
  • Ensure firewalls are used as security enforcement points, not as core infrastructure service providers.
  • Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door.
  • Configure and troubleshoot dynamic routing, including internal BGP.
  • Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms., * Design, build, maintain, and troubleshoot IPsec and SSL VPN networks.· Manage and support a Cradlepoint environment of 20,000+ devices.
  • Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform.
  • Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls.
  • Patch, monitor, log, audit, and secure network infrastructure.
  • Ensure network links, management access, VPNs, and sensitive data flows are encrypted.
  • Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks.
  • Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness.
  • Use Zedcor’s internal PKI solution for device identity, certificates, authentication, encryption, and secure management.
  • Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting.
  • Ensure firewalls are used as security enforcement points, not as core infrastructure service providers.
  • Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door.
  • Configure and troubleshoot dynamic routing, including internal BGP.
  • Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms.

Requirements

The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI., * 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience.

  • Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking.
  • Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access.
  • Solid understanding of DNS and DHCP design, troubleshooting, and security best practices.
  • Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices.
  • Ability to work full-time on-site in Houston, Texas.
  • Ability to troubleshoot complex production issues under pressure.
  • Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks.
  • Hands-on experience with BGP and dynamic routing.
  • Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point.
  • Local Houston-area candidate able to work in office 5 days per week.

Preferred Qualifications

  • Sophos firewall experience.
  • F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience.
  • Enterprise PKI and certificate lifecycle experience.
  • Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience.
  • Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience.
  • Cradlepoint or large-scale cellular router experience.

About the company

Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida., At Zedcor, you won’t just maintain systems, you’ll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you’re looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity.

Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver’s license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements.

The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:22 min

Leveraging unique cultural backgrounds in engineering design

Ixchel Ruiz · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

4:35 min

Defining service-level indicators based on user behavior

Maxim Schepelin Maxim Schepelin · World Congress 2026 Europe

Videos

See all

Related articles

See all