Senior Cybersecurity Engineer (Network Security)
Brak informacji o wynagrodzeniu
SeniorFull-time
#393627·Dodano 3 dni temu·2
Źródło: TTMSTech Stack / Keywords
CybersecurityNetworkSecurityArchitectureCiscoProfilingIoTAPI
Wymagania
Education / Experience:
- Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related field.
- 5+ years experience designing, implementing, and managing enterprise-grade NAC with Cisco ISE.
- Experience deploying and maintaining Palo Alto Next-Generation Firewalls (NGFW), including SSL decryption and threat prevention.
- Experience with automation tools like Ansible, Terraform, and Python for managing network security.
- Experience managing security in complex global environments with diverse devices (IoT, Medical, Corporate).
- Experience in regulated industries (Pharmaceuticals, Healthcare, Finance) is a plus.
Technical Skills:
- Expert in Cisco ISE, including TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, enterprise policies, EAP-TLS, EAP-TEAP.
- Strong understanding of RADIUS, TACACS+, identity-based access control, Enterprise PKI, certificate lifecycle.
- Proficiency in segmentation technologies: TrustSec, SGTs, VRFs.
- Proven deployment and troubleshooting of Palo Alto Firewalls in HA environments.
- Ability to design "Defense in Depth" flows linking device identity to network permissions.
Nice to have:
- Proficiency in Terraform and GitHub for IaC and version-controlled network security.
- Experience building CI/CD pipelines with GitLab/GitHub for security automation.
- Scripting skills in Python, PowerShell, or Bash for API integrations and custom tools.
- Strong foundation in enterprise networking (L2/L3), routing protocols (BGP, OSPF), switching (VLANs, VXLAN).
- Excellent communication, stakeholder management, and mentoring skills.
- Passion for researching emerging network security trends and automated enforcement.
- Ability to translate high-level security requirements into functional network policies.
- Proven self-starter managing technical workstreams end-to-end.
- Expertise mentoring junior cybersecurity engineers on network security best practices.
Additional Qualifications:
- Strong facilitation, communication, conflict resolution, collaboration, and commitment to operational excellence.
Obowiązki
Product Ownership and Technical Leadership:
- Act as the primary SME for Secure Access technologies, evaluate and select emerging security tools.
- Drive the technical roadmap for network access aligned with Zero Trust security architecture.
- Partner with business units to translate security requirements into technical initiatives and policies.
- Provide mentorship and technical leadership to junior engineers.
Identity-Based Access and Authentication:
- Design, deploy, and maintain authentication solutions using protocols like 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA.
- Integrate security platforms with enterprise Identity Providers (IdPs) for secure authentication.
- Architect and manage highly available authentication services globally.
Network Access Control (NAC) and Segmentation:
- Lead lifecycle management of Cisco ISE including upgrades, capacity, and optimization.
- Develop endpoint profiling techniques for corporate, medical, and IoT devices.
- Implement access control via Dot1x, MAC Authentication Bypass (MAB), Guest Access, posture-based authorization.
- Design and oversee Cisco TrustSec and Scalable Group Tag (SGT) micro-segmentation.
Operational Excellence and Automation:
- Serve as escalation point for complex technical incidents with root-cause analysis.
- Develop observability, monitoring, and reporting dashboards for platform health.
- Implement Infrastructure-as-Code (IaC) and security automation.
- Build API-driven integrations and self-service capabilities for IT teams.
Global Operations:
- Ensure secure, reliable connectivity for tens of thousands of endpoints worldwide.
- Collaborate with global product squads and stakeholders to deliver integrated security solutions.
Benefity
- Participation in interesting and demanding projects.
- Flexible working hours.
- Possibility to work remote or hybrid (2 days per week from the office).
- Opportunities for development and promotion.
- Attractive package of benefits.
Elastyczne godziny
Inne informacje
We reserve the right to contact the selected candidates.
TTMS
21 aktywnych ofert