This position will be on-site reporting to our Bangalore office, M-F
This team provides 24/7 support. This role requires shift flexibility, including the ability to rotate between days, mids, and nights.
The Perimeter Security Engineer is responsible for designing, implementing, administering, monitoring, and supporting enterprise perimeter security controls across on-premises, cloud, and remote-access environments. The role provides deep operational expertise in next-generation firewalls and secure web proxy technologies, partners with infrastructure and application teams to resolve connectivity and policy issues, and strengthens security through disciplined change, compliance, lifecycle, and incident-management practices.
How you’ll make an impact
- Administer enterprise firewalls, including security policies, NAT, routing, VPN, application control, URL filtering, threat prevention, software upgrades, high availability, monitoring, auditing, and rule-base hygiene.
- Configure, operate, and troubleshoot secure web proxy and cloud-delivered security services, including explicit and transparent proxy, PAC files, authentication, SSL/TLS inspection, URL categorization, malware controls, and policy enforcement.
- Plan, design, implement, and validate improvements, migrations, replacements, and standardization of perimeter security components.
- Perform in-depth troubleshooting using firewall and proxy logs, packet captures, flow analysis, threat logs, and monitoring tools to determine root cause and restore services.
- Investigate security events and indicators involving internet ingress and egress, remote access, web traffic, command-and-control activity, malicious downloads, and policy violations.
- Assess and implement firewall and proxy requests with appropriate business justification, least-privilege access, application awareness, risk review, testing, and rollback planning.
- Monitor platform availability, capacity, performance, license health, certificate validity, and high-availability status; support uptime and service-level commitments.
- Maintain technical standards, ruleset documentation, object inventories, network diagrams, runbooks, software-release plans, hardware lifecycle records, and operational procedures.
- Support security compliance and audit activities by producing evidence, reviewing access, remediating findings, and reporting adherence to approved policies and standards.
- Collaborate with network, cloud, endpoint, SOC, IAM, application, and vendor teams; provide technical guidance and mentor junior engineers during incidents and changes.
Technical Expertise
- Next-Generation Firewalls: (Fortinet or Palo Alto Networks) NGFW and Panorama; Prisma Access; App-ID, User-ID, Content-ID; GlobalProtect; security profiles; NAT; IPsec and SSL VPN; routing; HA; decryption; log analysis.
- Secure Web Proxy / SSE: Zscaler Internet Access, Broadcom Symantec ProxySG, Netskope, Forcepoint, or equivalent; proxy policy, PAC files, authentication, SSL inspection, URL filtering, sandboxing, DLP integration, and troubleshooting
- Cloud Security: AWS and Microsoft Azure networking and security controls; cloud firewalls, security groups, route tables, load balancers, private connectivity, and hybrid traffic flows. GCP exposure is advantageous.
- Network & Security Foundations: TCP/IP, DNS, DHCP, HTTP/S, TLS, BGP, OSPF, VLANs, routing and switching, load balancers, certificates/PKI, packet capture, and network traffic analysis.
- Operations & Tooling: ITSM and change management; SIEM and monitoring tools; configuration backup; vulnerability and compliance review; scripting or automation with Python, PowerShell, APIs, or infrastructure-as-code is desirable.
What we're looking for
- Minimum 5 years of relevant hands-on experience in perimeter security, with strong operational expertise in enterprise firewall and secure web proxy technologies.
- Proven experience implementing and supporting Palo Alto Networks firewalls and Panorama in enterprise environments; Prisma Access experience is strongly preferred.
- Hands-on experience with at least one enterprise secure web proxy or Security Service Edge platform such as Zscaler, Symantec ProxySG, Netskope, or Forcepoint.
- Professional experience in information security, network security, consulting, managed services, or an enterprise security operations role.
- Demonstrated ability to handle complex incidents, analyze traffic, communicate root cause, and define corrective and preventive actions.
- Experience working within formal incident, problems, change, vulnerability, and configuration-management processes.
- Strong written and verbal communication skills, including the ability to explain technical risks and solutions to technical and non-technical stakeholders.
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience.
- This role demands the availability of 24/5.
- This role is Work from Office.
Certifications
- Palo Alto Networks Certified Network Security Engineer (PCNSE)/ Fortinet Certified Professional NSE4 & NSE5 or current equivalent.
- Zscaler, Netskope, Broadcom/Symantec, Forcepoint, or other proxy/SSE platform certification.
- CCNP Security, CISSP, or a relevant cloud security certification from Microsoft Azure or AWS.
#LI-SK2
What you can expect from Optiv
A company committed to our inclusive value through our Employee Resource Groups
Work/life balance
Professional training resources
Creative problem-solving and the ability to tackle unique, complex projects
Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.