Network Security Engineer
About this role
We're looking for a Network Security Engineer to manage and evolve our firewall and network security estate, primarily built on Check Point and Cisco platforms. This role sits at the intersection of network engineering and security. You'll be hands-on with policy management, troubleshooting, and architecture, while working closely with our Infosec Manager on broader security initiatives. This is not a strict Information Security role - we're prioritizing strong technical depth in firewalling and networking over formal InfoSec credentials. If you're a network engineer with serious firewall chops, we want to hear from you.
Responsibilities
Manage, configure, and troubleshoot Check Point firewalls (policy, NAT, VPN, SmartConsole)
Administer Cisco network infrastructure (switches, routers, ASA where applicable)
Design and implement firewall rule changes following change management processes
Monitor firewall/network performance and proactively resolve issues
Support network segmentation, VPN (site-to-site and remote access), and routing configurations
Participate in security incident response from a network/firewall perspective
Document network topology, firewall rulesets, and standard operating procedures
Collaborate with the Infosec team on vulnerability remediation and hardening initiatives
Assist with audits and compliance requirements relating to network security controls
Solid hands-on experience with Check Point firewall management (CCSA/CCSE certification a plus)
Strong working knowledge of Cisco networking (routing, switching, VPN); CCNA/CCNP a plus
Understanding of core networking concepts: TCP/IP, VLANs, routing protocols (OSPF/BGP), NAT
Experience troubleshooting complex network/security issues under pressure
Familiarity with VPN technologies (IPsec, SSL VPN)
Basic understanding of security principles (least privilege, segmentation, logging)
Good documentation habits and clear communication skills
Comfortable working in a fast-paced, hands-on environment
Nice to Have
Exposure to other firewall/security vendors (Fortinet, Palo Alto)
Scripting/automation experience (Python, Ansible) for network tasks
Experience with SIEM tools or log analysis
Cloud networking exposure (AWS/GCP)
